Please do not open a public issue for a suspected vulnerability. Contact GetBirthChart through the private security contact published at getbirthchart.com/developers, including a concise description, affected version, reproduction steps, and impact. Never include a real API key or private birth data.
- Configure credentials with
GETBIRTHCHART_API_KEY. - Do not pass credentials as command-line arguments or MCP tool input.
- The server never logs the key or sends it anywhere except the configured API base URL as an Authorization header managed by
@getbirthchart/sdk. - Keep host configuration files containing keys outside source control.
The server exposes only explicit calculation methods and fixed resources. Tool input cannot select an endpoint, URL, host, method, header, shell command, or proxy target. Birth inputs are not persisted or cached.
The latest published version is supported. Security fixes are released as new patch or minor versions under semantic versioning where possible. Runtime support is Node.js 20+.