SafeWA API
Security overview

SafeWA Security

How SafeWA protects sessions, keys, and automation workflows.

Session-scoped access

API keys are scoped to individual WhatsApp sessions. This limits blast radius and lets operators revoke automation access without disabling the full workspace.

Secret handling

Raw API key secrets are only displayed immediately after creation. Existing keys show only their prefix and can be revoked from the dashboard.

Account protection engine

Every outbound text message is evaluated before sending. SafeWA can allow, delay, or block risky sends based on session health, warm-up, contact status, and message risk.

Webhook safety

Use HTTPS webhook endpoints only. Keep webhook URLs private, rotate exposed endpoints, and avoid sending sensitive customer data to untrusted automation tools.

Operational access

Manual plan activation and admin actions require an admin token. Store admin credentials outside browser screenshots, chats, and public documents.

Responsible automation

Do not send spam or unsolicited bulk messages. Respect opt-out contacts and local messaging rules. SafeWA is designed for legitimate customer conversations and support workflows.