Support

One inbox, read by the people who built it: [email protected]. We aim to reply within one business day.

Go straight to the right place

Licence keys

Your key is in your account. Switch it on once per machine:

npx tashan-cli login
npx tashan-cli doctor

Same command as the free one; the rows with an answer now show it. If you would rather query the history yourself, the key is also a bearer token:

curl -H "Authorization: Bearer <key>" \
  "https://tashan.sh/api/history?id=pkg:tavily-mcp"

A 403 means the key isn't valid or the subscription lapsed; a 503 means validation is temporarily unavailable — retry rather than re-issuing your key.

Treat the key like a password: anyone holding it can use your subscription. If it leaks, revoke it in your account and a new one is issued.

Corrections and disputes

Every number here is derived from public evidence, which means every number can be wrong in a way you can point at.

If a score, a grade, a security finding or a label is wrong about your capability — or about one you rely on — say so and we will fix the data or explain why it stands.

Email [email protected] with CORRECTION in the subject, or use the something wrong here? link at the foot of any capability page — it carries the capability's id for you.

Tell us what the page says, what you believe is true, and where that can be checked publicly.

Security

Found a vulnerability in tashan itself? Email [email protected] with SECURITY in the subject and we'll respond before anything else in the queue. Please don't file it publicly first.

Note that we do not audit the capabilities we measure — a tashan score is not a security review. If you find a malicious capability, report it to its registry and tell us so we can flag it in the data.