Security and data handling

API Docket is built on Atlassian Forge and has no servers of its own.

Architecture

All of API Docket's code runs on Atlassian Forge: the user interface runs in a sandboxed frame inside Confluence, and the backend runs as Forge functions in Atlassian's cloud. We do not operate any servers, databases or analytics services, and API Docket never sends your data to us.

What is stored, and where

DataPurposeLocation
Copies of API specificationsFast page loads and the changelogForge storage (your site)
Version history and computed changesChangelog tab; last 50 versions per sourceForge storage (your site)
Connection tokensReading private filesForge encrypted secret storage (your site)
Macro settings (source, display options)Rendering the macroThe Confluence page itself

API Docket stores no personal data. Uninstalling the app causes Atlassian to delete its Forge storage for your site according to Atlassian's data retention policy.

Network requests

API Docket contacts systems outside Atlassian only in two situations, both initiated by your users:

  • Fetching a specification from the URL or repository configured in a macro (GitHub, GitLab, Bitbucket or any URL).
  • Try it out: when a reader sends a request and the macro uses the API Docket relay, the request goes to the API server declared in the specification. The relay refuses any host not listed in the specification, strips cookies and does not follow redirects. Admins can disable the relay for the whole site.

Permissions

  • Attachments are read as the viewing user, so Confluence page and space permissions apply.
  • Only users who can edit a page can change its API Docket macro or test sources.
  • Connections can only be created, changed or deleted by Confluence administrators. This is verified on the server for every request.
  • Each connection is limited to the locations an administrator allows, so page editors cannot use a token to read other repositories.
  • Tokens are never sent to the browser.

Requested Confluence scopes

API Docket requests read-only access to pages, blog posts and attachments, read access to the current user's permissions (to check admin rights), and app storage. It cannot modify or delete Confluence content.

Reporting a vulnerability

Please email security@apidocket.com. We acknowledge reports within two business days.