API Keys, Credentials & Secrets
Strict guidance for API keys, provider tokens, brokerage credentials, storage, support redaction, and user responsibility.
Page sections
Never send secrets to support
Users should not send API keys, brokerage passwords, provider tokens, private keys, seed phrases, full connection strings, signing secrets, or authentication cookies to support.
If a secret is accidentally shared, revoke or rotate it immediately with the provider. Do not wait for support to confirm deletion.
Local responsibility
Users are responsible for securing their own device, Windows account, local files, credential vault, provider accounts, broker accounts, backups, and exported project files.
OptionForge should avoid storing secrets in plain text where secure platform storage is available, and users should still treat any local configuration as sensitive.
Support boundaries
Support can help troubleshoot connection configuration, provider setup, access checks, and app-side error messages, but support should not ask for or use the user’s private login credentials.
Screenshots of provider dashboards should be cropped or redacted before sending.