Do not open a public issue for vulnerabilities, exposed API keys, authentication problems, webhook bypasses, credit issues, or customer data.
Report security concerns through GitHub private vulnerability reporting or by emailing support@beatapi.io. Include the affected endpoint, impact, reproduction steps, and relevant request IDs. Remove API keys, webhook secrets, personal data, and private media URLs from the report.
If a BeatAPI key is committed, pasted into an issue, or otherwise exposed:
- revoke or rotate it immediately in the BeatAPI dashboard;
- remove it from the current file;
- clean it from repository history before making the repository public;
- do not rely on deleting only the latest commit.
All examples in this repository use environment variables and placeholder credentials.