Manage credentials and webhooks safely.
Purpose
Put each secret in its owning settings area, test only the connection you changed, and rotate access without exposing the value. In plain language: decide who owns the service, save its credential in the supported place, confirm one harmless connection, and revoke the old access.
Audience and access
For: Gym owners coordinating the change, WordPress administrators, and the technical owner of each provider<br>
Access needed: manage_options for Integrations and GymCore AI settings; gymcore_manage_communications or manage_options for the SMS provider destination; server access only for wp-config.php or environment secrets<br>
Common paths: GymCore Admin > Integrations, GymCore Admin > Communications & Automations > Channels & providers, and GymCore Admin > AI > Settings
Before you start
- Name the credential owner, provider account, affected production connection, maintenance window, and rollback credential.
- Use staging and a harmless provider account or destination where possible.
- Obtain the exact provider fields and, for inbound AI webhooks, the sender’s production network addresses before changing enforcement.
- Keep secrets out of chat, screenshots, browser-console captures, tickets, and command history.
Exact steps
Safe stop: Enter or review new credentials only in the approved admin field, but stop before Save & Connect, Save changes, secret rotation, or enforcement changes until the provider owner and rollback credential are ready.
Connect a registered GymCore integration
-
Open GymCore Admin > Integrations and locate the provider card.
Expected: The card shows Connected or Not Connected and one of Connect, Test Connection, or Disconnect. If the page says no integrations are registered, no customer form exists for that provider.
-
For a new connection, select Connect, complete the provider-labelled fields, and select Save & Connect.
Expected: The card changes to Connected. Password-type fields are determined by the registered provider schema; do not assume every field is a secret.
-
Select Test Connection.
Expected: The card reports Healthy or Unhealthy. Connected means configuration was saved; only Healthy reports the current health response, and neither proves a future delivery or sync.
-
When revoking access, disable or rotate the credential at the provider first, then select Disconnect and confirm Disconnect this integration?
Expected: The card returns to Not Connected. Verify the provider no longer accepts the old credential.
Update Twilio credentials
-
Open GymCore Admin > Communications & Automations > Channels & providers as a site administrator. The current owner renders the Twilio credential form, rate limit, readiness result, and explicit Send test SMS action.
Expected: The page masks the stored token and separates saved configuration, readiness, test acceptance, and carrier delivery.
-
Rotate or enter credentials only through that approval-gated owner workflow. Never edit the old options directly. Use the installed test action at most once with the current administrator’s staff-controlled billing phone.
Expected: GymCore and Twilio show the same message SID and destination. Provider acceptance is not carrier delivery; verify Twilio’s final status.
Configure the AI provider and Slack
-
Configure the approved provider through Settings > Connectors. GymCore AI does not read or copy the provider credential.
Expected: GymCore Admin > AI > Connections & Security > Provider and model lists only configured providers. Refresh the catalog, save the exact model draft, run readiness, and activate it. Do not restore the retired GymCore AI credential option.
-
For approval alerts, enter the restricted URL under Slack incoming webhook URL, choose whether to enable Include action summary in Slack, and select Save Changes.
Expected: Only an HTTPS
hooks.slack.comURL is accepted. This credential sends alerts; it does not authenticate inbound AI actions.
Protect the inbound AI webhook
-
First, tell the external automation owner that you are rotating its shared secret and restricting the network addresses allowed to connect. Agree on the five-minute cutover and rollback owner.
Expected: The owner has the correct production sender addresses and is ready to update the secret immediately.
-
Open GymCore Admin > AI > Settings > Webhook & Security. Enter one sender address per line under IP Allowlist and select Enforce IP allowlist.
Expected: With enforcement on, an empty list blocks all webhook traffic. The screen uses the server-observed source address; a reverse proxy must set that address correctly.
-
Select Generate Secret for a first connection or Rotate Secret for an existing one, then confirm the prompt.
Expected: The new secret is shown once in an admin notice. During rotation, the previous and new secrets are accepted for five minutes.
-
Transfer the new secret through the approved secret channel, update the external sender, and select Save Changes for the allowlist settings.
Expected: A staging request from an allowed address with a current signature succeeds; a stale, altered, or disallowed request is rejected. Do not claim this test unless the installed staging request was actually run.
-
After five minutes, repeat one staging request using only the new secret and verify the intended source record or action status.
Expected: The old secret no longer authenticates after cleanup, and the new request produces the expected local record exactly once.
Expected result
Each service uses one supported credential location, the old access is revoked, a harmless connection check has a recorded result, and the final provider or source record confirms what happened.
Defaults and limits
| Area | Current source behavior |
|---|---|
| Integration cards | Administrator-only; registered provider schema controls fields |
| Twilio token | Legacy option may exist, but the current customer UI does not render a supported replacement field |
| AI provider key | Owned by WordPress and the registered provider plugin under Connectors; Gym Core AI does not read or store it |
| Slack URL | HTTPS hooks.slack.com only; blank disables Slack |
| Inbound webhook secret | 64 hexadecimal characters when generated |
| Secret rotation overlap | 5 minutes |
| IP enforcement | On by default in current validator; on + empty list denies all |
| Client address | Server REMOTE_ADDR; forwarded headers are not trusted by the validator |
Technical handoff
The inbound automation signs the timestamp and raw request body with the shared secret and sends the result in X-HMA-Signature. This HMAC signature expires after five minutes and is separate from a WordPress REST nonce, which protects actions taken by a signed-in administrator. A legacy bearer-token path remains in source but lacks timestamp replay protection and should not be used for new connections. “Egress IP” means the network address the external sender uses when it leaves its service; it belongs in IP Allowlist.
Side effects and privacy
Saving a credential can grant access to messages, accounting, AI prompts, or member records. Connection tests can create provider logs, billable requests, or external messages. Secret rotation can interrupt automation; leaving enforcement off with an empty allowlist accepts any source address that has a valid signature. Provider retention is separate from GymCore retention.
Recover by symptom
Connect saves but Test Connection is Unhealthy
Do not reconnect repeatedly. Confirm the provider account, required fields, network access, clock, and provider status. Capture only the sanitized health error and provider request ID.
A Twilio test succeeds locally but no phone receives it
Check Twilio’s message status, sender selection, destination E.164 value, account restrictions, consent, and carrier rejection. The local response is not delivery proof.
The webhook returns 401 or 403 after rotation
Confirm the external sender uses the new secret, its clock is within five minutes, the raw body is unchanged after signing, and the server-observed source address is allowed. Do not turn off enforcement on production as a diagnostic shortcut.
The new secret was exposed
Rotate again, update the sender within the five-minute overlap, revoke screenshots/logs where possible, and review webhook requests during the exposure window.
A credential field is missing
Use the owning surface above. A provider absent from Integrations has no registered customer form. Do not write options directly or add secrets to an undocumented field.
Related guides
- Configure approval notifications
- Protect AI data and connections
- Troubleshoot integrations and APIs
- Collect diagnostics and contact support
Source review: checked-out gym-core and gym-core-ai PHP/JavaScript on 2026-07-13. Connection outcomes must be recorded from the installed staging environment; none are fabricated here.
Need help?
Describe one problem and the installed versions. Never send passwords, license keys, API keys, payment details, or member records.