Bucket URLs are bearer capabilities
There is no account login around a bucket. Anyone with the bucket ID can view captured requests, change the configured response, clear captures, or delete the bucket. Treat both the dashboard URL and webhook endpoint as secrets.
Do not put bucket URLs in public tickets, screenshots, analytics, or source control. Create a new bucket if a URL was shared outside the intended test group.