Security and data handling
API Docket is built on Atlassian Forge and has no servers of its own.
Architecture
All of API Docket's code runs on Atlassian Forge: the user interface runs in a sandboxed frame inside Confluence, and the backend runs as Forge functions in Atlassian's cloud. We do not operate any servers, databases or analytics services, and API Docket never sends your data to us.
What is stored, and where
| Data | Purpose | Location |
|---|---|---|
| Copies of API specifications | Fast page loads and the changelog | Forge storage (your site) |
| Version history and computed changes | Changelog tab; last 50 versions per source | Forge storage (your site) |
| Connection tokens | Reading private files | Forge encrypted secret storage (your site) |
| Macro settings (source, display options) | Rendering the macro | The Confluence page itself |
API Docket stores no personal data. Uninstalling the app causes Atlassian to delete its Forge storage for your site according to Atlassian's data retention policy.
Network requests
API Docket contacts systems outside Atlassian only in two situations, both initiated by your users:
- Fetching a specification from the URL or repository configured in a macro (GitHub, GitLab, Bitbucket or any URL).
- Try it out: when a reader sends a request and the macro uses the API Docket relay, the request goes to the API server declared in the specification. The relay refuses any host not listed in the specification, strips cookies and does not follow redirects. Admins can disable the relay for the whole site.
Permissions
- Attachments are read as the viewing user, so Confluence page and space permissions apply.
- Only users who can edit a page can change its API Docket macro or test sources.
- Connections can only be created, changed or deleted by Confluence administrators. This is verified on the server for every request.
- Each connection is limited to the locations an administrator allows, so page editors cannot use a token to read other repositories.
- Tokens are never sent to the browser.
Requested Confluence scopes
API Docket requests read-only access to pages, blog posts and attachments, read access to the current user's permissions (to check admin rights), and app storage. It cannot modify or delete Confluence content.
Reporting a vulnerability
Please email security@apidocket.com. We acknowledge reports within two business days.