| name | brightdata-security-basics |
| description | Apply Bright Data security best practices for secrets and access control.
Use when securing API keys, implementing least privilege access,
or auditing Bright Data security configuration.
Trigger with phrases like "brightdata security", "brightdata secrets",
"secure brightdata", "brightdata API key security".
|
| allowed-tools | Read, Write, Grep |
| version | 1.6.0 |
| license | MIT |
| author | Jeremy Longshore <jeremy@intentsolutions.io> |
| tags | ["saas","scraping","data","brightdata"] |
| compatibility | Designed for Claude Code |
Bright Data Security Basics
Overview
Security best practices for Bright Data zone credentials, API tokens, and webhook delivery. Bright Data credentials include Customer ID, zone passwords, and API tokens — all must be protected.
Prerequisites
- Bright Data zones configured
- Understanding of environment variables
- Access to Bright Data control panel
Instructions
Step 1: Credential Inventory
| Credential | Scope | Rotation | Storage |
|---|
| Customer ID | Account-wide | Never changes | Can be in config |
| Zone Password | Per-zone | Rotate quarterly | Secrets vault only |
| API Token | Account-wide | Rotate quarterly | Secrets vault only |
SSL Cert (brd-ca.crt) | Public | Auto-renewed | Can be in repo |
Step 2: Environment Variable Security
BRIGHTDATA_CUSTOMER_ID=c_abc123
BRIGHTDATA_ZONE=web_unlocker1
BRIGHTDATA_ZONE_PASSWORD=z_pass_xyz
BRIGHTDATA_API_TOKEN=abc123def456
.env
.env.local
.env.*.local
BRIGHTDATA_CUSTOMER_ID=
BRIGHTDATA_ZONE=
BRIGHTDATA_ZONE_PASSWORD=
BRIGHTDATA_API_TOKEN=
Step 3: Zone Isolation by Environment
Create separate zones per environment so staging credentials cannot access production proxy bandwidth:
const ZONE_MAP = {
development: 'web_unlocker_dev',
staging: 'web_unlocker_staging',
production: 'web_unlocker_prod',
} as const;
export function (): {
env = process.. || ;
process.. || [env] || .;
}