Security
What we never expose, and what we ask of you.
What the platform does to keep an integration safe, and what it asks of you in return.
What you never receive
- Provider credentials. Your application talks to the platform; the platform talks to WhatsApp, Meta, Telegram and the mail providers with credentials that are encrypted at rest, decrypted only inside the adapter that needs them, and never returned by any endpoint. An integration cannot be the place a Meta token leaks from, because it never has one.
- Other applications' data. Every application belongs to one workspace and is scoped to it in every query; there is no id you can guess your way to another workspace with. Every id is a UUID.
- Secrets twice. An API key, a client secret and a webhook secret are shown once, at creation or rotation, and stored hashed. Lose one and it is re-issued.
What we ask
- Keep credentials out of code and out of browsers. A secret manager or an environment variable on the server that calls us; never a mobile app, never a web page, never a repository.
- Ask for the least. An application that only sends needs
messages.sendand the one channel it sends on. A leaked key can then do only that. - Verify every webhook. The signature, then the timestamp, then dedupe on the event id - in that order, before the body is trusted. See Webhooks.
- Rotate on a schedule and on any doubt. Rotation keeps the old key alive for a grace window so a redeploy has no gap; revocation is immediate.
- Use HTTPS. The API refuses plain HTTP, and so should your webhook endpoint - a delivery to
http://is refused when the endpoint is registered.
Transport and headers
TLS 1.2 or newer. Every response carries X-Request-ID, a strict Content-Security-Policy, X-Content-Type-Options: nosniff, Referrer-Policy and Strict-Transport-Security. The public API sets no cookies and accepts none: an API key can never be promoted into a session.
Rate limits as a control
Per-application limits (Rate limits) mean a bug that loops cannot spend the business's whole messaging budget in a minute, and the send bucket on top of the request bucket means a loop of reads cannot mask a loop of sends.
Audit
Every credential issued, rotated, revoked or suspended, every scope or channel changed, and every webhook endpoint created or disabled is in the workspace's audit log with who, when and from where. Request logs keep every call your application made - method, path, status, duration, request id - for the business to inspect in the developer portal.
Reporting a vulnerability
If you believe you have found a security issue in the API, write to the address on the business's developer portal page and include a request id where you can. Please do not test against a live workspace's customers.
https://communication-api.artofluminaire.com
Every response carries X-Request-ID; quote it when you write to support.