Security
Report vulnerabilities privately.
Email [email protected]. Do not include access tokens, provider responses, or personal data in the first message.
Scope
MCPainless local releases and the mcpainless.com, app, auth, mcp, and catalog services are in scope. Denial of service, social engineering, and testing against accounts you do not own are out of scope.
Relay privacy
The OAuth relay receives a PKCE challenge and a digest-bound transaction. It never receives the PKCE verifier. Authorization codes are encrypted at rest, retrieved once over HTTPS, and never placed in browser URLs or application logs.
Handling
We acknowledge receipt, validate impact, coordinate remediation, and credit reporters who request it. There is no paid bug bounty.