Support

One inbox, read by the people who built it: [email protected]. We aim to reply within one business day.

Go straight to the right place

Licence keys

Your key is in your account. Switch it on once per machine:

npx tashan-cli activate <your key>
npx tashan-cli doctor

Same command as the free one; the rows with an answer now show it. If you would rather query the history yourself, the key is also a bearer token:

curl -H "Authorization: Bearer <key>" \
  "https://tashan.sh/api/history?id=pkg:tavily-mcp"

A 403 means the key isn't valid or the subscription lapsed; a 503 means validation is temporarily unavailable — retry rather than re-issuing your key. Treat the key like a password: anyone holding it can use your subscription. If it leaks, revoke it in your account and a new one is issued.

Security

Found a vulnerability in tashan itself? Email [email protected] with SECURITY in the subject and we'll respond before anything else in the queue. Please don't file it publicly first.

Note that we do not audit the capabilities we measure — a tashan score is not a security review. If you find a malicious capability, report it to its registry and tell us so we can flag it in the data.