JP Agent Tracking Bridge (docs) - Security
Article Index
- JP Agent Tracking Bridge (docs)
- How JP Agent Tracking Bridge Works
- Requirements
- WordPress Installation
- Joomla Installation
- Basic Configuration
- Connecting Google
- Google Permissions
- Disconnecting Google
- Installing the Agent Tools
- Start Tagging
- Talking to Your AI Agent
- Tracking Overview
- Structured Tracking Rules
- Custom Tracking Scripts
- Successful Form Tracking
- YOOtheme Essentials Forms
- Email Click Tracking
- Phone Click Tracking
- Google Tag Manager
- Existing GTM Tags
- Publishing Google Tag Manager
- Google Analytics Verification
- Tracking Verification
- Recommended Verification Chain
- WooCommerce Tracking
- WooCommerce Ecommerce Data
- WooCommerce Purchase Statuses
- Consent and Cookie Management
- YOOtheme Pro
- Stop Tagging
- Security
- Google OAuth Security
- History
- Reset and Clear Log
- Working With Existing Tracking
- Troubleshooting
- Google Connection Problems
- Events Appear in dataLayer but Not GA4
- Form Tracking Does Not Fire
- WooCommerce Troubleshooting
- Frontend Layout Problems
- Recommended First Tracking Job
- Recommended WooCommerce Setup
- Developer and Agency Notes
- Agent API Concepts
- Google Tools MCP
- Privacy and Google Data
- Before Finishing a Tagging Session
- Quick Start
- Example Agent Request
- All Pages
Page 32 of 51
Security
JP Agent Tracking Bridge separates normal tracking runtime from temporary remote configuration access.
Important security principles include:
- Remote Agent Access is disabled by default.
- Start Tagging generates temporary high-entropy credentials.
- Bootstrap credentials are one-time exchange credentials.
- Connection previews do not consume bootstrap credentials.
- Stop Tagging revokes active remote access.
- Old credentials do not become valid again.
- Google OAuth tokens remain server-side.
- Google refresh tokens are not exposed to the CMS frontend.
- Google credentials are not placed in AI prompts.
- OAuth client secrets are not exposed to the browser.