Please report security issues privately by email to service@powertokens.ai. Do not open a public issue, pull request or Discord post for them.
Helpful details:
- The affected version (window title, e.g.
v1.11) and whether you use the EXE, the source, the CLI or the MCP server. - What an attacker could do and the steps to reproduce it.
- Any proof of concept, with real keys removed.
We will acknowledge your report, keep you updated while we work on a fix and credit you in the release notes if you wish.
- Never post an API key in issues, discussions, pull requests, screenshots or logs. Blur or remove keys and Task IDs before sharing anything.
- If a key may have been exposed, delete it in your PowerTokens dashboard and create a new one right away.
- The CLI config (
cli-config.json) stores keys in plain text. Prefer thePOWERTOKENS_API_KEY/POWERTOKENS_API_KEYSenvironment variables and never commit that file.
Security fixes go into the latest release. Please update to the newest version from the Releases page before reporting.
For how the app handles keys and download links, see Security notes in the README.