Skip to content

Security

We never need a login to your database.

TextBind only calls the HTTPS actions you register. Report vulnerabilities to us privately before public disclosure.

security@textbind.com

Secrets
  • AES-256-GCM for Meta tokens, app secrets, and authentications
  • Auth passwords hashed by better-auth; session cookies with CSRF protections
  • Secrets are write-only after save
Boundaries
  • HTTPS-only action URLs; private / metadata IPs rejected
  • 8s timeout and a 10-failure circuit breaker
  • JSON Schema check before any HTTP call
Identity
  • Hashed 6-digit link codes, 10-minute TTL, 5-attempt lockout
  • High-risk actions require WhatsApp Confirm / Cancel buttons
  • 15 turns / 3 minutes / phone; one job per conversation

Your side

  • Least-privilege Meta system-user token. Rotate if leaked.
  • Staging authentications in Playground. It hits real URLs.
  • Payment method on the WABA so Meta does not stop delivery.
  • Honor X-Idempotency-Key on your APIs.

Enterprise may include a 99.9% monthly uptime target for the TextBind API, excluding Meta and your execute URLs. Credits follow the Refund Policy. Processor terms: DPA.

Connect your number in one sitting.

Create a workspace, paste Meta keys, register an action. Meta bills WhatsApp. We bill the software.