BERTokenScope includes baseline production security controls.
Protected API endpoints require:
X-API-Key: <key>
Roles:
vieweranalystadmin
The API applies:
X-Content-Type-Options: nosniffX-Frame-Options: DENYReferrer-Policy: no-referrer- restrictive permissions policy
- baseline content security policy
Configure allowed origins:
BERTSCOPE_ALLOWED_ORIGINS=http://localhost:8501
Configure max request size:
BERTSCOPE_MAX_REQUEST_BYTES=1000000
Configure per-client request limits:
BERTSCOPE_RATE_LIMIT_REQUESTS=120
BERTSCOPE_RATE_LIMIT_WINDOW_SECONDS=60
Unhandled exceptions return a generic 500 response while details are logged server-side.