Report a problem
Bugs, documentation errors, and suspected clone sites. You do not need an account to report something, and you will get a reference you can use to follow it up.
Never include a secret in a report
Do not paste a .maFile, a shared secret, an identity secret, a
revocation code, a password or an API key into this form or into any message
to us. Nobody here will ever ask for one. A report that needs to describe a
secret can describe its shape without its value.
Reports containing what looks like a shared secret, an identity secret, a revocation code or a private key are refused and not stored. That is deliberate: the check is in the code, not just in the sentence above.
What to include
- What you did, what you expected, and what happened instead.
- The application version and your operating system.
- Whether it happens every time or occasionally.
- For a suspected clone site: the URL, and where you encountered it.
What happens to a report
-
You get a reference in the form
ODA-7K2M-B9QW. It is the only way to find the report again, so keep it — there is no account to recover it from. - It is read. Reports are triaged rather than queued: anything describing lost access, lost items, or a secret behaving unexpectedly is looked at ahead of everything else.
- It gets an answer. Including "we are not going to change this", with a reason. A tracker where reports quietly expire is a tracker nobody reports to twice.
Reporting a clone site
Fake authenticator downloads are the reason this project exists, and a report takes a minute. Send the URL and where you found it — a search result, an advertisement, a video description, a Discord message. We collect them, warn about the patterns on the scam clones page, and report the worst to the registrars and hosts involved.
You do not need to be sure. A site that turns out to be legitimate costs us five minutes; one that turns out not to be may save somebody their inventory.
Security reports
Do not open a public issue for a security problem. There are two private routes, both live now:
- GitHub private vulnerability reporting — preferred. It is private, it threads, and it does not depend on an address staying monitored.
- [email protected] — read, if you would rather not use GitHub.
What we commit to, in writing: acknowledgement within 72 hours, an initial assessment within 7 days, and a fix or a dated plan within 30 days for a confirmed high or critical. Those are the commitments of a single maintainer, and if one is going to be missed we will say so before the deadline rather than after. The full policy is in SECURITY.md.
Please give us a reasonable window to release a fix before publishing details. We will not use that window to argue you into silence, and we will credit you unless you would rather we did not.