HMAC-signed webhooks
Every webhook delivery includes an HMAC-SHA256 signature. Verify the payload came from Polymorfa, not a spoofed source. Configure your secret key per webhook endpoint.
Check out our Launch week free trial and the Polymorfa Builders Program! 15 Pro numbers + add-ons for 30 days.
Ends in ––d : ––h : ––m : ––sSearch for a command to run...
security · compliance
Built for regulated industries. Encryption passthrough, HMAC-signed webhooks, and compliance modes for healthcare, finance, and legal.
Every webhook delivery includes an HMAC-SHA256 signature. Verify the payload came from Polymorfa, not a spoofed source. Configure your secret key per webhook endpoint.
WhatsApp's end-to-end encryption stays intact. Polymorfa never decrypts message content at rest. What passes through the wire is what your webhook receives. Nothing is stored or exposed.
Media files are streamed directly from WhatsApp to your endpoint without being stored on Polymorfa's servers. Zero media retention. Configure per session or globally.
Two modes for regulated industries. Compliance mode enables full message archival for legal discovery and audit trails. No-logs mode ensures zero message retention. Nothing is stored.
Built with international privacy regulations in mind. Data minimization by default, configurable retention policies, and the ability to purge all session data on demand.
Scope API keys by permission level. Create read-only keys for monitoring, write keys for messaging, and admin keys for session management. Least privilege by default.
Detailed guides on HMAC verification, compliance setup, and privacy configuration.