Terms of use
Effective
Wamen is a free, experimental work in progress operated by Prasetya. It provides a short-lived WhatsApp identity proof. The application using Wamen owns its users, authorization rules, account records, and durable sessions.
No service-level agreement
Wamen is provided as available, without an uptime commitment or warranty. It uses one unofficial WhatsApp connection during this experimental stage. WhatsApp, infrastructure, policy, or capacity changes may interrupt or end the service without notice. Check the public status page before relying on it.
Acceptable use
You may use Wamen only for lawful, user-initiated identity proof. Do not use it to send spam, impersonate others, probe or bypass security controls, overload the service, automate abusive transaction creation, harvest phone numbers or identifiers, or violate WhatsApp terms or applicable law. Wamen may rate-limit, suspend, or block abusive origins and traffic.
Integrator responsibilities
- Show users why you request a phone number and request it only when necessary.
- Verify Wamen identity tokens on your backend, including signature, issuer, audience, and expiry.
- Do not trust claims merely decoded in browser JavaScript. Create and protect your own application session.
- Protect your application against cross-site scripting because the short-lived Wamen token is stored in browser local storage for this release.
- Provide your own privacy notice, account deletion process, support, and authorization controls.
Identity and deletion
Wamen identity is pairwise to each application origin. Verified deletion causes future sign-ins to receive a new Wamen principal and new application-specific subject. An application keyed only by the old subject may no longer find the old account. Deleting Wamen data does not delete data held by an integrating application.
Support and security
Service support: andhika@prasetya.devSecurity reports: andhika@prasetya.dev