Skip to content

Security

  • Read-only API key — FluidRAG uses a Freshdesk API key over Basic Auth. The integration can search and read tickets but cannot create, update, or delete them.
  • No user login flow — the API key authenticates as itself; no OAuth scopes or user consent are required.
  • Minimal surface — only two credentials are needed: FRESHDESK_DOMAIN and FRESHDESK_API_KEY.
  • No inbound endpoints — FluidRAG only makes outbound API calls to <subdomain>.freshdesk.com. No webhooks or inbound endpoints are required.
  • Private note separation — during extraction, private conversations (internal notes) are split from public conversations and preserved in a separate Internal Notes section. During live search, the agent labels private notes distinctly rather than blending them with customer and agent replies.
  • Hallucination protection — a response validator cross-checks every ticket ID in the agent’s answer against the tickets actually retrieved, and strips unverified IDs automatically.
  • Credentials in etcd — the API key and domain are stored in etcd and never exposed to the client.
  • Rate limit awareness — paginated extraction stops gracefully when Freshdesk returns a 429 rate-limit response, respecting the Retry-After header.