Securing 2M+ accounts & $15B+ in assets, protected & secure·B5 Secure™ — per data-element authorization for .NET platforms

Start Here

Step 1

Start Here

Start with identity and ownership, not a secret copied into a configuration file. Every B5 integration should be anchored to an enterprise, project, application, environment, audience, scope set, owner, and callback policy.

Create the integration record

Continue

Implementation steps

Name the enterprise tenant and designate business, technical, and security owners.
Create one project per bounded product or workload rather than one project for the entire company.
Create separate applications for server, mobile, browser, automation, and partner identities.
Create isolated development, test, staging, and production environments.
Define exact audiences, scopes, redirect URIs, webhook targets, and rotation contacts.

Control details

Enterprise Tenant

The enterprise tenant is the root customer identity used for policy, licensing, entitlement, audit, and evidence partitioning.

Project

A project groups applications and environments around one bounded product, service, or integration objective.

Application

An application receives its own identity, credential lifecycle, callback rules, and evidence trail.

Environment

Credentials and data never cross environment boundaries. Test Mode must have no production reach.

Audience Scopes

Audience limits where a credential is accepted. Scopes limit what it can request. Both are enforced independently.

Owners Callbacks

Every integration needs accountable owners, approved redirect and webhook destinations, and a documented incident contact.

Integration record

Record these values before a credential is issued

ObjectRequired valuesWhy it matters
EnterpriseTenant ID, legal customer, ownersRoot identity, commercial boundary, and evidence partition.
ProjectProject ID, product/workload, security ownerBounds applications, policy, and deployment ownership.
ApplicationApplication ID, type, audience, scopesCreates a distinct software identity and credential lifecycle.
EnvironmentDevelopment, test, staging, productionPrevents credential and data crossover.
CallbacksExact redirect URIs and webhook targetsPrevents open redirects and unapproved event delivery.
Credential rule: server secrets belong in an approved secret store. Native mobile applications and browser extensions must use user-bound OAuth, device proof, and short-lived authority instead of an embedded tenant secret.
Build & integrate

Continue to a real implementation page

Every destination below is a published B5 page with additional guidance or a concrete implementation surface.

Developer Relations

Talk to a human.

Get architecture guidance, Test Mode access, integration review, or help choosing the right B5 identity and authorization pattern.

Scroll to Top