Docs/security-best-practices

Docs

Security Best Practices

  • Connect only trusted MCP servers.
  • Treat social_competitors_create as a write action and review the request carefully before approving it.
  • Use least-privilege workspace access in Sociality.io.
  • Reconnect OAuth if authentication becomes stale or suspicious.
  • Check social_workspace_context before large billable queries.
  • Use social_platform_capabilities instead of guessing metric names for a channel.