TRUST / SECURITY
Security
How to keep your account and API keys safe, and how to report a problem.
Passwords and API keys
Log in only at api.headcountlabs.com/data/login. Create and manage API keys at api.headcountlabs.com/data/keys. Never send a password or API key by email, including to Headcount Labs support.
Keep API keys on your server or in a protected environment variable. Do not put them in browser code, mobile apps, URLs or source control.
MCP sign-in
The MCP server at https://api.headcountlabs.com/mcp uses OAuth sign-in in your browser. Setup steps are on the MCP page.
Report a security problem
Email support@headcountlabs.com. Describe the problem without including passwords or API keys.