API keys
- Call the API from a backend, CI job, or test runner.
- Give each key only the scopes its integration needs.
- Never include a key or
Authorizationheader in URLs, logs, analytics, or support messages. - Rotate a key if it may have been exposed.
Email content
Treat sender names, addresses, subjects, HTML, filenames, raw source, and attachments as untrusted input. Escape values before inserting them into HTML, SQL, shell commands, or templates. Render HTML in an isolated sandbox and validate or scan attachments according to your application’s risk. The API checks account ownership on every private read. Missing, expired, and non-owned private resources use the same404 response.