Security guidance
Protect Beacon credentials, limit access, validate input, and preserve safe publication behavior.
Protect credentials
Store agent keys and access tokens in a secret manager. Never put them in browser storage or client source code.
Do not put credentials in logs, chat, links, analytics, or error reports.
Use HTTPS for every Beacon request.
Limit access
Create one key for one service. Grant only the permissions that service needs.
Revoke a key or connected application when you no longer need it.
Do not accept a workspace ID from a browser as proof of access. Beacon selects the workspace from the authenticated credential.
Protect writes
An idempotency key identifies one write request. Use a stable key for each supported repeatable write.
Do not automatically repeat image generation. Do not repeat an uncertain provider publication.
Keep immediate-publication approval separate from application confirmation. Never approve a request on the user's behalf.
Protect user content
Send only the content required for the requested task. Validate user input before you call Beacon.
Do not expose internal records, raw provider responses, or credential fields through your application.
Handle support data
Record the Beacon request ID for diagnosis. Do not record request authorization headers.
Show safe error details and a clear recovery action. Remove secrets before you send any support message.