Security
Built for explicit, auditable automation.
The API keeps rendering deterministic and requires explicit confirmation for store upload and billing actions.
Agents should never log API keys, store credentials, or result URLs. Integrations use idempotency keys and scoped API tokens, with live and test key prefixes that keep automated runs auditable. Signed callbacks and direct App Store Connect or Google Play publishing flows should require explicit approval steps before uploads or billing changes.
Report security issues to [email protected].