Include useful diagnostics
- Account email and organization name.
- Target URL, or a safe description if the URL contains private information.
- Request, job, schedule, or capture ID and a UTC timestamp.
- HTTP status, error code, and exact non-secret error message.
- Capture options, expected outcome, and actual outcome.
- A redacted example or screenshots when they can be shared safely.
Remove secrets first
Remove API keys, passwords, session cookies, authorization headers, webhook secrets, one-time codes, signed links, and payment-card details. Check screenshots and logs as well as the request body. Use key names or short identifiers to identify credentials without exposing their values.
If a secret was exposed
Revoke or rotate the credential in the service that issued it, then update affected integrations. Tell support what type of credential was exposed without repeating its value. For privacy or deletion requests, email from the account address and describe the data and organization involved.
Documentation
Related support articles
Need help with this issue?
Email support with this article, your request or capture ID, and the result you expected. Remove credentials and private information first.
Email [email protected]