Agreed on both counts! The danger is inherent to any unofficial Robinhood integration since they don't provide OAuth. We've tried to be upfront about the tradeoffs in our security model docs.
1 karma · joined December 30, 2025
The "temporary access" framing is accurate: Robinhood returns tokens that expire, we hold them in memory (not disk), and they're wiped on logout or server restart.
We're transparent about this tradeoff. If you're not comfortable with it, don't use it. For those who are, tokens are memory-only and wiped on logout/restart.