Support
Quote the server-issued X-Request-Id, UTC time, route and public X-Sx-Key-Id. For uncertain writes, also provide the original Idempotency-Key through the approved secure channel.
Never send an HMAC secret, RSA private key, X-Sx-Signature, raw authorization material, signing token, webhook secret, personal payload, or a copied .env file.
For suspected credential compromise, a human operator should revoke it immediately. Revocation is checked after a signature verifies and is terminal; disabled credentials are reversible. Reconcile any in-flight writes before switching credentials.