Production Environment
Cybrid bank configuration, API security, and production readiness
Error
Authentication required to view users
Environment: UNKNOWN
Sandbox mode - transactions are simulated. Switch CYBRID_ENV to "production" when ready to go live.
Production Readiness Checklist
Bank Overview
No bank data available
Bank Accounts
No bank accounts found
Fund Trading Account (USD → USDC)
Executes a bank-level trade converting your bank's USD fiat balance to USDC in the trading account. This USDC backs all user crypto withdrawals. Ensure your fiat account is funded first.
Bank Funding Details
No funding details available
API Applications & IP Allowlist
Cybrid recommends configuring an IP allowlist on each production application to restrict API access to your server egress IPs. Customer tokens (POST /api/customer_tokens) are not gated by the allowlist.
No bank applications found
Token Security
- Bank tokens: 30min (prod) / 8hr (sandbox) lifetime
- Customer tokens used for all customer-scoped operations
- Tokens never exposed to client-side code
Webhook Security
- Validate X-Cybrid-Signature on all webhooks (HMAC-SHA256)
- Use constant-time comparison for signature verification
- Configure webhook signing key in Cybrid Partner Portal