Best Practices

This guide describes the recommended practices for integrating with the Trudenty Consumer Trust Index (CTI) API. Following these recommendations helps improve security, reliability, and application performance.


Secure Your Credentials

Your Client ID and Client Secret uniquely identify your application.

Trudenty recommends that you:

  • Store x-client-id and x-client-secret credentials in a secure secrets management solution.
  • Never expose credentials in source code or client-side applications.
  • Rotate credentials immediately if they are suspected to be compromised.

Always Use HTTPS

All API requests must be sent over HTTPS.

HTTPS encrypts data exchanged between your application and the Trudenty platform, helping protect sensitive consumer information.


Handle Errors Gracefully

Applications should expect and appropriately handle API errors.

Recommended practices include:

  • Validate request data before sending requests.
  • Handle authentication failures separately from server errors.
  • Retry only transient failures such as HTTP 429 and 500.

Respect Rate Limits

Current rate limit:

500 requests per minute per client IP

Monitor your request volume and implement exponential backoff when retrying rate-limited requests.


Log Request Identifiers

Every response includes an X-Request-ID.

Store this identifier in your application logs.

Providing the request identifier when contacting Trudenty Support significantly reduces investigation time.


Data handling

  • Treat consumer_id as a sensitive consumer identifier. Apply your organization's data protection policies.
  • Handle 404 / no_network_record gracefully — it indicates no trust index exists for that consumer, not an API failure.

Performance

  • Cache responses according to your business rules if repeat lookups for the same consumer occur within a short window.
  • Use pagination (page, limit) on history requests rather than requesting large page sizes unnecessarily.

Need Assistance?

If you have questions about onboarding, authentication, or API integration, visit the Contact Support page to explore available support channels and contact our team.



Did this page help you?