# Security

URL: https://docs.ablyft.com/developers/consent-and-security/security/

> How access to ABlyft is protected, what the snippet sends, and what to keep in mind when integrating.



This page lists the security-relevant behavior of the snippet, the REST API and the MCP server that we can describe from
how they work. It is not a compliance statement. For questions about certifications, data processing or contracts,
contact ABlyft support.

## Access to your account

* **Roles.** Each team member has one role (viewer, member, admin or owner). The role decides what someone can read and
  change, in the app, in the API and through the MCP server. See [Roles & permissions](https://docs.ablyft.com/guides/projects-and-teams/roles-and-permissions/).
* **API tokens** let scripts act on your behalf in the [REST API](https://docs.ablyft.com/developers/reference/rest-api/). You create and revoke them
  in your personal settings under **API Tokens**, see [Authentication](https://docs.ablyft.com/developers/reference/rest-api/#authentication).
* **MCP connections** let AI assistants act on your behalf. They are authorized with a login step (OAuth) and listed under
  **MCP Connections** in your personal settings, where you can revoke them. See [MCP server](https://docs.ablyft.com/developers/reference/mcp-server/).

> **Treat tokens like passwords:** A token has the permissions of your user within your teams. Store it in a secret manager, never in front-end code or
> in a repository. If a token may have leaked, revoke it in the token list and create a new one. Prefer **Read only**
> tokens when write access is not needed.

## What the snippet is

The snippet is a public JavaScript file on the CDN (`https://cdn.ablyft.com/s/<project ID>.js`). Anyone who knows the URL can
read it.

> **Do not put secrets into the snippet:** The snippet contains the configuration of your running experiments, audiences, pages and goals, including the JavaScript
> and CSS of your variations and your project code. Do not put passwords, API keys or private data into experiment code,
> helper code or audience rules.

## What the snippet sends

The snippet sends events to the tracker, by default `https://log.ablyft.com`, with `navigator.sendBeacon()`. A request contains:

| Part                                    | Content                                                                                                                                                        |
| --------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `projectId`, `source`, `snippetVersion` | Your project ID, the fixed value `ablyft-snippet` and the snippet version                                                                                      |
| `user.experimentsBucket`                | The visitor's assignments: experiment ID to variation ID                                                                                                       |
| `user.attributes`                       | The visitor's browser user agent, the page URL, visitor type (`new` or `returning`) and device type (`desktop`, `tablet`, `mobile`)                            |
| `events`                                | The events, each with a type (`bucketing`, `pageview`, `click`, `custom`, `revenue`), a value, a timestamp, an ID, and for goals the goal ID and variation IDs |

The request has no field for a visitor ID, name or email address. Because the URL and user agent are sent, avoid putting personal data into
URLs of pages that run experiments.

The snippet only sends events when the visitor is part of at least one experiment, not for bots, and not when the visitor
opted out or the browser sends Do Not Track while **Adhere to Do Not Track** is on. See [Storage & privacy](https://docs.ablyft.com/developers/consent-and-security/storage-and-privacy/).

## Frames

The snippet does not run inside iFrames by default, see [Requirements](https://docs.ablyft.com/developers/installation/requirements/#iframes) to allow it.

## URL parameters can change what a visitor sees

Some [URL parameters](https://docs.ablyft.com/developers/reference/url-parameters/) change what the visitor's own browser shows, for example
`ablyft_preview` and `ablyft_set_bucketing`. They only affect the browser that opens the URL. Preview mode also turns off goal
tracking in that browser. Experiments in preview status are part of the public snippet, so do not rely on a variation
staying secret before it launches.

## Content Security Policy

If you use a Content Security Policy, see [Requirements](https://docs.ablyft.com/developers/installation/requirements/#network-and-content-security-policy)
for the domains to allow and the use of `eval`.

## Next steps

- [Storage & privacy](https://docs.ablyft.com/developers/consent-and-security/storage-and-privacy/): What is stored in the browser.
- [REST API](https://docs.ablyft.com/developers/reference/rest-api/): Authentication with API tokens.

