You are viewing region:DEGermanyGBEUHotline
GBEU
News & StatusContact
Phylex logoPhylex
About
Client AreaCareers
Automation APIs
OverviewAuthenticationAccount APIReseller APIErrors and limitsSecurity
Agent tools
AI SDK and skill
Phylex logoPhylex

Premium cloud hosting solutions with enterprise-grade infrastructure. Trusted by thousands of businesses worldwide for reliable VPS, VDS, and dedicated servers.

Compute

  • Dedicated Servers

Game Hosting

    Storage

    • Storage Boxes
    • S3 Storage

    Network & Security

    • IP Subnets
    • IP Transit
    • BGP SAAR
    • DDoS Protection
    • Looking Glass

    Developer

    • API Documentation
    • Authentication
    • Reseller API
    • API Security

    Support & Info

    • Knowledge Base
    • Support Center
    • News & Status
    • Network Info
    • Careers

    Legal

    • Terms of Service
    • Privacy Policy
    • Data Protection
    • Refund Policy
    • Imprint
    Found a bug or typo?

    Report it and get a small thank-you gift.

    Bug bounty

    Need a hand?

    Find practical setup guidance or open a ticket with our support team.

    Knowledge BaseOpen a ticket

    © 2022-2026 Phylex branding under ISPLABS LIMITED. All Rights Reserved.

    ISPLABS LIMITED | Company number 16958848

    Registered office address 128 City Road, London, United Kingdom, EC1V 2NX

    Listed on WH Top
    GDPR compliance badgeGDPR Compliant
    ICO registration badgeRegistration reference: ZC161318
    Rated on Revuio.de
    0.0/5 (0 reviews)
    View profile
    Follow us:
    Security

    Integration checklist

    An API key is a password for the scopes it carries. Design storage, rotation, logging, and failure handling before issuing production credentials.

    Phylex never needs your raw API key in a support ticket. Revoke and replace a key immediately if it appears in client code, logs, screenshots, or a repository.

    • Store keys in a server-side secret manager, never browser code, mobile bundles, logs, analytics, or Git.
    • Grant the narrowest scopes and restrict production keys to fixed egress CIDRs where possible.
    • Set an expiry, rotate before it, and revoke the old key after consumers move.
    • Keep services:write and services:power on separate, short-lived keys.
    • Grant finance:read only to server-side integrations that need billing history.
    • Persist one Idempotency-Key per logical mutation until the final response is durable.
    • Treat a 404 as opaque; never infer whether another tenant owns the reference.
    • Reseller write scopes are permanently bound to the issuing reseller tenant.
    Manage account keysAccount OpenAPI specification