This policy covers every public repository in the DivineAPI GitHub account: the SDKs (divineapi-python, divineapi-node, divineapi-php), the MCP server repos and the API example repos.
Please do not open a public GitHub issue, discussion or pull request for a security problem. A public report can expose other users before a fix is in place.
Report it privately through the DivineAPI help centre: support.divineapi.com.
Please include:
- what is affected (repository and version, or the API host and endpoint path)
- the steps to reproduce, and what you expected to happen
- the impact as you understand it
- how we can reach you for follow-up questions
Never include a live API key or auth token in a report. If a credential was exposed, say so and rotate it from your DivineAPI dashboard.
- Code in these repositories (SDKs, MCP server configuration, example scripts)
- The DivineAPI API hosts and the hosted MCP servers that these repositories call
Questions about using the API, billing or your account are not security reports; send them to support.divineapi.com as a normal request.
If you see what looks like a real DivineAPI API key or auth token committed to any public repository, report it privately through support.divineapi.com instead of posting it anywhere.