Skip to content
76 changes: 76 additions & 0 deletions app/en/resources/security-research-program/page.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,8 @@ We're interested in reports about:
- Logic flaws affecting agent behavior
- Issues that could compromise user data or agent integrity

A finding that shows one tenant reading or changing another tenant's tokens, secrets, or data is in scope. Send that.
Comment thread
evantahler marked this conversation as resolved.
Outdated

## Reporting process

Please email <ContactEmail domain="arcade.dev" user="security">our security team</ContactEmail> with:
Expand All @@ -51,3 +53,77 @@ We'll acknowledge receipt within 72 hours and aim to provide an initial assessme
While we're a small team with limited resources, we appreciate the effort researchers put into improving our security. We'll credit researchers (with permission) in our security updates and may provide modest rewards for significant findings on a case-by-case basis.

For questions about this program, please <ContactEmail domain="arcade.dev" user="security">contact our security team</ContactEmail>.

## Common questions

Researchers most often ask about mail authentication, DNS, and OAuth reports that describe the Arcade Cloud data model.
Comment thread
evantahler marked this conversation as resolved.
Outdated

### Arcade's DNS settings are intentional

Arcade manages email authentication with SPF, DKIM, and DMARC. The SPF record ends in `~all` (SoftFail), while DMARC uses `p=reject`. Receivers reject unaligned mail that claims to come from `arcade.dev`. Valimail manages this configuration.

Reports that only recommend `-all`, DNSSEC, RRSIG, or CAA describe hardening choices, not vulnerabilities. Include a demonstrated security impact if you believe the configuration is exploitable.

### Auth error pages come from the identity vendor

Ory serves the error page on `auth.arcade.dev`. Arcade uses Ory for account login. Send reports about reflected content on this page through [Ory's security process](https://www.ory.com/docs/ecosystem/security).
Comment thread
cursor[bot] marked this conversation as resolved.
Outdated

### Public discovery documents are public

`auth.arcade.dev/.well-known/openid-configuration` publishes standard OpenID metadata for clients. Its contents are not sensitive, and Arcade does not support dynamic client registration.

### A project API key is an administrator credential

Arcade Cloud isolates data by tenant and by [project](/resources/glossary#project). A project is the trust boundary. Everyone with membership in a project, or with one of its API keys, shares that project's users, brokered tokens, and secrets, and can start authorization for those users. Invite people you trust, and join projects you trust.
Comment thread
cursor[bot] marked this conversation as resolved.
Outdated

A project API key authenticates as the administrator of that one project. It can start authorization and read tokens for that project's users. A report that uses a project key to read data from the same project describes expected administrator access.
Comment thread
cursor[bot] marked this conversation as resolved.
Outdated

### Projects scope user IDs

`user_id` is an opaque, caller-supplied string. The same value can appear in many projects, but each project has its own authorization records. Using `ada@example.com` in one project does not grant access to records for `ada@example.com` in another project.
Comment thread
evantahler marked this conversation as resolved.
Outdated

### Completing a flow stays in the project that started it
Comment thread
evantahler marked this conversation as resolved.
Outdated

Authorization completion requires an API key from the project that started the flow and the same `user_id` supplied at the start. The user ID does not travel through the browser redirect.
Comment thread
cursor[bot] marked this conversation as resolved.
Outdated

### A custom auth provider replaces the platform provider for your tenant

You can add an auth provider whose ID matches a platform provider, such as `google`. Your provider then handles authorization for your tenant, and its client ID appears in the authorization URL. The identity provider still validates the client and redirect URI.
Comment thread
evantahler marked this conversation as resolved.
Outdated

A broken provider configuration can disrupt that tenant's tools. This reflects expected administrator access, not a cross-tenant outage.
Comment thread
evantahler marked this conversation as resolved.
Outdated

### Default OAuth apps follow project membership

Arcade's default OAuth apps work with the [Arcade user verifier](/build/user-facing-agents/secure-auth-production#use-the-arcade-user-verifier). The verifier asks the end user to sign in to an Arcade account that is a member of the project. Membership means the project may act for that account on connectors that use the default app.
Comment thread
evantahler marked this conversation as resolved.
Outdated

A default-app token can appear in a second project only when that Arcade account is also a member of the second project. Project membership is a trust relationship.
Comment thread
evantahler marked this conversation as resolved.
Outdated

For a multi-user production app, add your own OAuth client and a [custom user verifier](/build/user-facing-agents/secure-auth-production#build-a-custom-user-verifier). Default apps fit development and single-tenant use.
Comment thread
evantahler marked this conversation as resolved.
Outdated

Read [Confused deputy attacks on OAuth](https://www.arcade.dev/blog/arcade-proactively-addressed-coat-vulnerability-in-agentic-ai/) for a related consent-binding issue and Arcade's control.
Comment thread
evantahler marked this conversation as resolved.
Outdated

### Secret names are public

Platform secret names are public so customers can replace defaults with their own values.

A response that returns secret values, or another tenant's secret material, is a different finding. Send that.
Comment thread
evantahler marked this conversation as resolved.
Outdated

### Health-check tokens authenticate the health check

Worker health checks use a credential limited to that check. Steady-state calls use a secret for the worker deployment.

Include evidence that the token succeeds on a real worker request or reaches another tenant's data.
Comment thread
evantahler marked this conversation as resolved.
Outdated

### Plan limits are billing

Arcade bills premium tool executions against the project's plan. A quota bypass is a metering bug, not an authorization bypass, and is not eligible for a security reward.
Comment thread
cursor[bot] marked this conversation as resolved.
Outdated

### Retired hosts and archived examples

A retired hostname that still permits content changes or exposes customer data is worth a report. Name the host and demonstrate the impact.
Comment thread
cursor[bot] marked this conversation as resolved.
Outdated

Archived example repositories are samples. A static scan of an archived repo, with no impact on Arcade Cloud, is outside this program.

### Files on a developer laptop

The Arcade CLI stores credentials on the machine where it runs. A local file-permission finding must expose another user's data or affect Arcade Cloud to fit this program.
2 changes: 1 addition & 1 deletion public/llms.txt
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
<!-- git-sha: 41f63dddcd733afccdf0ed280d07651b32b7e88d generation-date: 2026-09-26T21:40:41.006Z -->
<!-- git-sha: 80656a60758d5a639b608b244ac08d07df435b25 generation-date: 2026-10-02T04:42:34.687Z -->

# Arcade

Expand Down
6 changes: 6 additions & 0 deletions redirects.ts
Original file line number Diff line number Diff line change
Expand Up @@ -1170,4 +1170,10 @@ export const redirects: Redirect[] = [
destination: "/:locale/build",
permanent: true,
},
// Folded into the security research program page before this path shipped.
{
source: "/:locale/resources/common-security-reports",
destination: "/:locale/resources/security-research-program",
permanent: true,
},
Comment thread
cursor[bot] marked this conversation as resolved.
Outdated
];
Loading