Skip to content

Security: AffixIO/MCP

Security

SECURITY.md

AffixIO MCP

Public install

  • Clients use https://www.affix-io.com/mcp only.
  • Authorisation is OAuth 2.0 PKCE in the browser.
  • Do not put platform credentials in MCP client config, READMEs, or UI copy.

Hosted process

  • Upstream Affix API credentials stay on the server.
  • Never log, return, or document those values in user-facing surfaces.
  • zk_verify_user and HTTP health responses must not include key material.

There aren't any published security advisories