# Réglages (vault) `VERIFIED IN CODE` · `#settings` / `page=alya-hs-settings` · **Screenshot of full keys: forbidden** ## 1. Purpose Sandbox/prod keys (`ApiKeyVault`), environment, margin, currency, webhooks, HMAC, min-rates, chatbot public key, invoice legal fields. ## 2. Screenshot `SCREENSHOT REQUIRED` with **hints only** (never full `sand_` / `prod_` / HMAC). ## 3. Navigation `#settings` · WP `page=alya-hs-settings` ## 4. Fields Environment, vaulted keys, margin, currency, nationality, payment default, branding color, webhooks, HMAC, min-rates, chatbot `sand_public_` / `prod_public_`, invoice SIRET/address. Exact live values except margin 10% (seen on Pricing): not dumped here. ## 5. Buttons Save settings. Do not capture after revealing secrets. ## 6. Filters N/A ## 7. Actions Save. HMAC inbound default **OFF**. Min-rates default **OFF**. ## 8. Workflow Administrator only → vault → save. Agency Admin: **no vault**. ## 9. REST/API Settings via admin pages / staff REST where registered. Public `GET /alya/v1/config` returns no secrets. ## 10. Database Encrypted options / vault storage. Not listed as plaintext in this pack. ## 11. Permissions `alya_manage_settings` / `manage_options`. ## 12. Business meaning Supplier connectivity and commercial defaults. Wrong env key = wrong inventory/charges. ## 13. Limitations Vault screen not captured. HMAC OFF on live cockpit (webhooks module). Stripe pk may still be CONFIGURATION REQUIRED. ## 14. Evidence status `VERIFIED IN CODE` · visual `REQUIRES ACCESS` (hints-only) ## Related [security-audit.md](../technical/security-audit.md)