The plugin must never send a BeatAPI API key through a model prompt or MCP tool
argument. Credentials belong in Cursor/Grok Bot's plugin Configure store, the
supported local credential store, or the BEATAPI_API_KEY process environment.
Webhook creation returns a signing secret only once. The MCP server writes that
secret to a new local file with permission mode 0600, returns only the file
path, and rolls back the webhook if secure storage fails.
Secret files use BEATAPI_DATA_HOME when configured, Codex's data directory
when available, or ~/.beatapi-agent-plugin on other hosts.
Paid task creation, shot editing, and composition are described as paid mutations in MCP metadata. The plugin never retries authentication, validation, insufficient-credit, or concurrency failures unchanged.
Use GitHub's private vulnerability reporting feature for security reports. If a credential may have been exposed, revoke it immediately in the BeatAPI dashboard.
The latest minor release is the supported release line.