简体中文
Versions and support

Support and security disclosure

Report integration issues and suspected vulnerabilities without disclosing credentials or personal data.

Support and security disclosure

For integration support, provide the request correlation ID, UTC time, route template, app/installation ID, environment, and safe error code. Never send access or refresh tokens, authorization codes, PKCE verifiers, Cookies, Webhook secrets/signatures, full URLs with queries, request bodies containing PII, payment data, or private evidence attachments.

Suspected vulnerabilities should follow /.well-known/security.txt. Do not test against another tenant, production customer, or destructive endpoint. Preserve a minimal reproducible case in sandbox and wait for authorization before expanding scope.

No documentation channel can approve an app, restore a revoked token, override tenant policy, or mark an unknown Provider result successful.

Copyright © 2026