Skip to content
Open dashboard

SIDEMEX / MCP

Security

How Sidemex protects your account when you connect an AI assistant: OAuth, least privilege, human-confirmed payments and auditing.

Read as Markdown
  • OAuth 2.1 + PKCE. You never share your password with the assistant.
  • Tokens bound to Sidemex. A token issued for the MCP server does not work elsewhere, and the server rejects tokens issued for other services.
  • Least privilege. You approve groups of actions and can revoke them any time.
  • No automatic payments. The assistant hands you a link; you are only charged when you confirm on sidemex.net.
  • No passwords in chat. Creating a mailbox or changing its password gives you a single-use link; the password never passes through the assistant.
  • Only your resources. Every operation checks that the domain or mailbox belongs to your account.
  • Auditing. Every action is logged and visible in your dashboard.
  • External data flagged. Third-party data (WHOIS, TXT records) is returned as data, not as instructions.

See /.well-known/security.txt.