Safe automation
Use the public API, CLI, and MCP in a way that keeps each workspace isolated and keeps billing clear. Related: MCP tools and gates, CLI security.
Workspace isolation
The API key or the app session selects the workspace. Tools must not accept a workspace id from the user. The only exception is a product that explicitly supports a change between workspaces.
Credit-spending actions
Generation and analysis creation can spend credits. Agent tools must make those actions explicit. Agent tools must also keep read-only operations separate.
On hosted MCP, the best choice for read-only exploration is OAuth
mcp:read. Before you use paid tools such as generate_image /
avatars_create, grant mcp:write (or use an API key). Write calls and paid
calls must send idempotency_key. The legacy allow_write / allow_paid
arguments are optional.
Logging
Safe logs include:
- request ids,
- job ids when necessary,
- high-level status,
- sanitized media metadata.
Unsafe logs include:
- API keys,
- signed URLs,
- raw private media URLs,
- too much user content or too many transcripts.