Account & security
Manage the credential used by external automations and review the security model of your gateway account.
U
—
—
Account role
userAccess level stored on your gateway account.
Session cookie
EnabledDashboard authentication uses a Secure, HttpOnly, SameSite=Strict cookie.
Transport
HTTPSKeep the production subdomain on HTTPS.
Public API key
Used by n8n, backend services and other trusted integrations.
Treat this like a password. Anyone with this key can call the public API as your account. Regeneration invalidates the previous key immediately.
Production security checklist
Do not place the API key in public frontend code
RecommendedUse server-side systems such as n8n, backend services or protected environments.
Rotate exposed keys
ImportantIf a key appears in screenshots, chat logs or public repositories, regenerate it.
Avoid exposing legacy backend endpoints
ImportantThe new /api/* layer checks bearer authorization and sender ownership. Legacy MPWA routes should not be offered to untrusted clients.
Use authorized recipients
RequiredOnly message recipients you are permitted to contact and follow WhatsApp rules and applicable law.