TRUST / SECURITY

Security

How to keep your account and API keys safe, and how to report a problem.

Passwords and API keys

Log in only at api.headcountlabs.com/data/login. Create and manage API keys at api.headcountlabs.com/data/keys. Never send a password or API key by email, including to Headcount Labs support.

Keep API keys on your server or in a protected environment variable. Do not put them in browser code, mobile apps, URLs or source control.

MCP sign-in

The MCP server at https://api.headcountlabs.com/mcp uses OAuth sign-in in your browser. Setup steps are on the MCP page.

Report a security problem

Email support@headcountlabs.com. Describe the problem without including passwords or API keys.