Developer documentation

Security and operational guidance

Keep authority narrow, credentials isolated, and recovery behavior explicit.

Excluded actions

REST and MCP do not expose account authentication settings, API-key lifecycle, billing, organization ownership or membership administration, organization deletion, or internal support operations.

Sensitive scopes

Evidence reveal, export, recipient deletion, Live publication, and audit access recheck the current dashboard role permission in addition to OAuth scope.

Compatibility policy

Veltor supports the published API version and standards-compliant MCP clients. Additive fields and actions follow the compatibility policy; breaking contract changes require a versioned migration path and changelog entry.