CAKE Security Settings to Protect Your Platform

by | Aug 4 | Blog, How-To

The recent launch of the CAKE Idea Portal has provided our customers with a direct line of communication to share with us the challenges they’re facing and their proposed solutions to overcome those challenges. Based on our community’s recent input, we have moved forward in expanding the CAKE security settings to help further safeguard our customers’ businesses, including Multi-Factor Authentication (MFA), system alerts, and increased API controls.

To help our customers ensure system security, the following is a list of CAKE security features and best practices across system logins and APIs.

 

System login security settings and notifications  

The CAKE platform delivers the following security settings for system login.

First, be sure to use the Multi-Factor Authentication (MFA) functionality within CAKE to log in to your CAKE instance. MFA verifies a user’s identity by requiring multiple credentials and is a critical component of identity and access management. CAKE sends a Time-based One-time Password (TOTP) to an authenticator app (e.g. Google Authenticator or Microsoft Authenticator) on your smartphone to verify credentials and securely access your CAKE platform.

While users do have the option to disable or change security settings within CAKE, we enable our default security settings based on best practices that ensure secure system login. CAKE security settings across admin and partner portals are:

  • Failed Login Attempts: 5 attempts
  • Admin Portal Session Timeout: 60 minutes
  • Password Strength: Strong
  • Password Usage History Restriction:10 passwords
  • Password Expiration Policy: 90 days

New this month, the CAKE platform will now notify users via email if there is a login from a new location or device. The platform tracks logins based on IP address and device ID and indicates when your login has been compromised so you can change your credentials. This functionality is in addition to the existing system alert for when login credentials are modified, e.g. if someone changes the email address or password on a contact record.

 

API security settings

API security is of utmost importance in CAKE.

Our latest platform update encrypts (hides) API keys in the UI, requiring users to click a “show” button to see/grab the API key. This enables the platform to accurately log who accesses the API keys and when in case there’s an issue.

To ensure maximum security of your APIs, follow these four best practices:

  • Give API keys custom names based on where the key is used. For example, if you want to generate a custom key for a third-party webhook integration, you could name the CAKE API key after the third-party system (e.g. Salesforce.)
  • Utilize the role access/permission setting for API key visibility so that only the necessary admin users have access to API keys.
  • If you know the IP address of the server that will be making API calls, you can whitelist the IP and choose to only allow calls from whitelisted IPs. You can do this through CAKE’s IP Whitelisting for API calls feature.
  • Create new API keys often — at least every three months — in case an API key has been compromised.

 

CAKE is committed to safeguarding your performance marketing program, to learn more about CAKE security settings, contact your Account Manager, or visit our Knowledge Base.

 

 

Author

Garth Harris

Garth Harris

As COO of the Affiliate Marketing Group, Garth's focus is to drive growth and adoption through the marketing and product teams while providing excellent customer service within the onboarding and support departments. During his 15 years in the affiliate marketing industry, Garth has held a wide range of roles, from client services manager to senior director of product engineering and, most recently, general manager at CAKE. These experiences have helped him build a deep understanding of his customers and their businesses. Outside of work, Garth is happiest behind a grill or at the beach with his family.

Related Articles

CAKE at Affiliate Summit West 2026
Mar 16 2026

Building Better Connections at Affiliate Summit West 2026

Connection was the word of the week at ASW26, and a constant theme...
new advertisers
Feb 18 2026

5 Best Practices for Onboarding New Advertisers

Onboarding is a critical step in establishing a long-term...
2025 Year in review - CAKE Product Updates
Dec 09 2025

Year in Review: 2025 Product Updates

As we wrap up the year, we want to take a moment to thank our...
Affiliate Referral Program
Nov 27 2025

Turbocharge Revenue and Partnerships With an Affiliate Referral Program

Discover how to boost revenue and partnerships with an affiliate...
Batch Processing
Nov 06 2025

Streamline Link Generation and Data Cleanup with New Batch Actions in CAKE

New in CAKE: Two bulk actions, Batch Link Generation and Batch Data...
Garth Harris at the Sip & Send happy hour at ASE 2025, hosted by CAKE and TUNE
Oct 21 2025

Affiliate Summit in 2025: A Recap and Look Ahead

Garth Harris provides his first write-up of an Affiliate Summit...
Email Marketing - Why It Belongs in Your Affiliate Program
Sep 24 2025

7 Reasons Email Marketing Rocks for Affiliate Programs

Email marketing is a fundamental part of strategic affiliate...
clickless-tracking-voucher-codes
Sep 22 2025

Using CAKE’s Voucher Codes for Clickless Tracking

As an affiliate marketer, the best way to accurately measure...
Saas customer support
Aug 14 2025

Experience Excellence With CAKE’s Top-Tier SaaS Customer Success

Have you ever encountered an issue with a tech provider or software...
Better Together: CAKE and TUNE Align Under One Unified Affiliate Marketing Vision
Jul 29 2025

Better Together: CAKE and TUNE Align Under One Unified Affiliate Marketing Vision

CAKE and TUNE, the most trusted platforms in the industry, have come...