Skip to documentation
Beacon Docs
Agent API and webhooks

Security guidance

Protect Beacon credentials, limit access, validate input, and preserve safe publication behavior.

Open Markdown

Protect credentials

Store agent keys and access tokens in a secret manager. Never put them in browser storage or client source code.

Do not put credentials in logs, chat, links, analytics, or error reports.

Use HTTPS for every Beacon request.

Limit access

Create one key for one service. Grant only the permissions that service needs.

Revoke a key or connected application when you no longer need it.

Do not accept a workspace ID from a browser as proof of access. Beacon selects the workspace from the authenticated credential.

Protect writes

An idempotency key identifies one write request. Use a stable key for each supported repeatable write.

Do not automatically repeat image generation. Do not repeat an uncertain provider publication.

Keep immediate-publication approval separate from application confirmation. Never approve a request on the user's behalf.

Protect user content

Send only the content required for the requested task. Validate user input before you call Beacon.

Do not expose internal records, raw provider responses, or credential fields through your application.

Handle support data

Record the Beacon request ID for diagnosis. Do not record request authorization headers.

Show safe error details and a clear recovery action. Remove secrets before you send any support message.