Skip to content
SocialHelper
Get API key

Security

Built to be trusted.

What SocialHelper does to keep your keys, your accounts and your data safe. Every point on this page describes how the product works today.

Your API keys

  • Keys are stored only as a SHA-256 hash. The full key is shown once, when you create it.
  • Only workspace owners and admins can create or revoke keys, and revoking one stops it at once.
  • A key reaches only its own workspace. Asking for another workspace’s account, post or media returns 404.
  • 120 requests a minute per key, for REST and MCP together.

Your connected accounts

  • Access tokens, app passwords and bot tokens are encrypted at rest and never returned by the API.
  • Disconnecting an account deletes its credentials, cancels its scheduled posts and, where the platform allows it, revokes SocialHelper’s access.
  • If a platform withdraws access, the account is flagged for reconnection, the workspace owner gets an email, and an account.needs_reconnect webhook is sent.

Webhooks

  • Every delivery is signed with HMAC-SHA256 over the timestamp and body, so you can check it came from SocialHelper.
  • Signing secrets are encrypted at rest, and you can rotate them in the dashboard.
  • Webhook URLs must resolve to public addresses, and in production must use HTTPS. Connections are pinned to the checked address and don’t follow redirects.

Media and URLs

  • When you import media from a URL, every redirect is checked against private networks, with at most 3 redirects.
  • A file’s type is read from its contents, not from its name or the headers you send.

Signing in to the dashboard

  • Email verification is required before you can use the dashboard.
  • Two-factor authentication and passkeys are available for every account.
  • Sign-in attempts are rate limited: 5 a minute per email and address, and 30 an hour per email.

Infrastructure

  • All traffic uses HTTPS, and the socialhelper.app domain is on the browser HSTS preload list (as every .app domain is).
  • Servers are hosted with Hostinger in the United States, behind Cloudflare.

Found a problem?

Please report security issues to [email protected]. For how we handle personal data, see the Privacy Policy.

Build on a solid base.

Create a free account, connect an account and send your first post in a few minutes.