Security acknowledgements

Thanking the people who help make AffixIO safer.

Responsible security reports deserve a clear response, a fixed issue, and credit when the researcher wants to be named. This page records remediated findings and the people who helped us improve.

Security report log

We only publish enough detail to acknowledge the issue and the remediation. Researcher names and links are added with permission.

Fixed

OAuth Dynamic Client Registration hardening

A researcher reported that the API exposed unauthenticated OAuth 2.0 Dynamic Client Registration with arbitrary redirect URI registration.

Date8 Oct 2026
Areaapi.affix-io.com
StatusRemediated

AffixIO removed public DCR advertising from OAuth metadata, made client registration require an initial access token, tightened redirect URI acceptance, removed the verification probe client, restarted the API service and verified unauthenticated registration now fails closed.

Researcher credit is pending permission. If the reporter would like to be named, we can add their preferred name, company, website, GitHub, LinkedIn, X, Bluesky or other social profile.

1

Receive

We read the report, reproduce where possible, and avoid asking for unnecessary personal data.

2

Fix

We prioritise issues that affect account access, API authorization, proof integrity, payment flows or customer data.

3

Credit

When the reporter agrees, we add a shoutout after the fix is live and the public wording is safe.

Found something?

Email a clear report with affected URL, steps to reproduce, expected result and actual result.

Send a report

Free proof allocations

Agents get 150 free proofs. Humans get 100. No card required.

AI agents receive 150 free AffixIO SDK proofs on BoundProof Agent provision. Eligible new Hub account holders (humans) can claim one allocation of 100 free SDK proofs to test AffixIO verification, agentic payment checks, transaction intent proof and signed yes, no or review outcomes.

Terms: one allocation per account holder, per person or business owner. No card is required. Proofs expire after 30 days. Duplicate, shared, automated or abusive signups may be refused or removed. Agents: /boundproof/agent/. Humans: Hub onboarding with offer params.

See free proofs split