
Mintlify, a San Francisco-based code documentation firm, has disclosed a data breach that compromised customer GitHub tokens due to a system vulnerability. The breach, identified on March 1, prompted the company to implement immediate security measures and launch a bug bounty program to address the issue.
The incident, outlined in a notice on Mintlify’s website, revealed that 91 customer tokens were exposed during the breach. Unauthorized requests to sensitive API endpoints raised concerns, indicating that the perpetrator had access to Mintlify’s private admin tokens, thereby gaining unauthorized entry to its systems.
Upon discovery, Mintlify revoked all GitHub token access, rotated administrative access tokens, and enhanced the security of its APIs. Collaboration with GitHub was initiated to determine whether the compromised tokens were used to access private repositories.
In response to the breach, Mintlify engaged with a bug bounty reporter to rectify the underlying vulnerability. Additionally, all access tokens were revoked again on March 2, and the company is collaborating with cybersecurity firms to investigate the incident and fortify its security protocols.
To foster proactive vulnerability reporting, Mintlify has introduced a bug bounty program covering its various platforms, including mintlify.com, dashboard.mintlify.com, leaves.mintlify.com, and the Mintlify GitHub apps. Security researchers are encouraged to submit vulnerability reports to ’security @ mintlify.com,’ providing detailed descriptions, reproduction steps, environment details, and proof-of-concept code if available.
Mintlify assures financial compensation for previously unidentified vulnerabilities with a Common Vulnerability Scoring System (CVSS) score of 4 or higher. Further information regarding responsible disclosure guidelines and compensation details is available on Mintlify’s responsible disclosure page.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543