Safe automation

Use the public API, CLI, and MCP in a way that keeps each workspace isolated and keeps billing clear. Related: MCP tools and gates, CLI security.

Workspace isolation

The API key or the app session selects the workspace. Tools must not accept a workspace id from the user. The only exception is a product that explicitly supports a change between workspaces.

Credit-spending actions

Generation and analysis creation can spend credits. Agent tools must make those actions explicit. Agent tools must also keep read-only operations separate.

On hosted MCP, the best choice for read-only exploration is OAuth mcp:read. Before you use paid tools such as generate_image / avatars_create, grant mcp:write (or use an API key). Write calls and paid calls must send idempotency_key. The legacy allow_write / allow_paid arguments are optional.

Logging

Safe logs include:

  • request ids,
  • job ids when necessary,
  • high-level status,
  • sanitized media metadata.

Unsafe logs include:

  • API keys,
  • signed URLs,
  • raw private media URLs,
  • too much user content or too many transcripts.