Missing User Warnings
Medium
- Confidence
- 86% confidence
- Finding
- The documentation instructs users to place both an API key and API secret directly in request headers, but provides no warning about secure handling, storage, redaction, or avoiding exposure in logs, client-side code, or shared examples. This increases the risk that integrators will embed long-lived secrets in unsafe locations or accidentally leak them through screenshots, repos, telemetry, or browser-based requests.
