Skip to main content
If you suspect a security issue with your app, email security@attio.com as soon as possible. Please don’t use support or the chat widget for security issues, so that your report reaches the right team quickly. You should contact us if, for example:
  • Your app’s client secret or one of its access tokens has leaked.
  • You notice unusual API activity from your app.
  • You find a vulnerability in Attio.

Helping us understand the issue

The more context you share, the faster the Attio team can act. Where possible, include:
  • Your app ID - This is the same as your ‘Client ID’, which you can find in the OAuth section of your app in the Developer console.
  • What happened - What leaked or what you found, and how.
  • When it happened - When the issue started, or when you first noticed it.
  • What you’ve already done - For example, whether you’ve rotated your client secret or revoked any access tokens.

Securing your app

While the Attio team investigates, you can take the following steps to limit the impact.

Rotating your client secret

If your client secret has leaked, head to the Developer console, select your app, and open the OAuth section. Click the refresh button next to ‘Client Secret’, then deploy the new secret to your app. Only admins of your developer account can rotate the client secret.

Revoking access tokens

Rotating your client secret does not revoke access tokens that have already been issued. If you still have the affected tokens, revoke each one with the Revoke endpoint:
To protect your users, the Attio team may also lock your app and revoke its access tokens. We will unlock your app once the issue is resolved. Workspaces will then need to connect your app again.