Account & security

Manage the credential used by external automations and review the security model of your gateway account.

U

—

—

Account role

Access level stored on your gateway account.

user
Session cookie

Dashboard authentication uses a Secure, HttpOnly, SameSite=Strict cookie.

Enabled
Transport

Keep the production subdomain on HTTPS.

HTTPS

Public API key

Used by n8n, backend services and other trusted integrations.

Treat this like a password. Anyone with this key can call the public API as your account. Regeneration invalidates the previous key immediately.

Production security checklist

Do not place the API key in public frontend code

Use server-side systems such as n8n, backend services or protected environments.

Recommended
Rotate exposed keys

If a key appears in screenshots, chat logs or public repositories, regenerate it.

Important
Avoid exposing legacy backend endpoints

The new /api/* layer checks bearer authorization and sender ownership. Legacy MPWA routes should not be offered to untrusted clients.

Important
Use authorized recipients

Only message recipients you are permitted to contact and follow WhatsApp rules and applicable law.

Required