Billing
Security
Last updated: August 4, 2026
This page summarizes security expectations for Autlantic Billing merchants and integrators. For settlement and custody positioning, see Non-custodial overview.
API keys and secrets
- Store API keys and webhook secrets in environment variables, not source control.
- Use Test keys (
abk_test_…) in staging and Live keys (abk_live_…) in production. Do not mix modes. - Rotate keys and webhook endpoint secrets if they may have leaked.
Webhooks
Verify the x-autlantic-signature header against the raw request body and the signing secret for that endpoint before trusting an event.
Settlement
Customer USDC settles on Base to the merchant payoutAddressEvm. Autlantic does not custody customer subscription revenue.
Relayers
Autlantic may operate relayers to sponsor gas and submit billing transactions. Relayers are not used to custody customer or merchant subscription balances. See Non-custodial overview.
Incident reporting
Report suspected security issues privately to support@autlantic.com. Include enough detail to reproduce the issue without sharing production secrets in public channels.
Related
Developer docs: Security guide · Terms · Community Guidelines

