DEV Community

Armando
Armando

Posted on

How I Built an Encrypted Messaging API

I built Quayat, a privacy-first chat app. Now it has a REST API for developers.

The problem: Every messaging API I tried required bot approval (Telegram), business verification (WhatsApp), or didn't encrypt server-side.

What I built:

REST API with API Key auth (SHA-256 hashed)

Rate limiting: 100/day free, 5,000/day premium

Webhooks with HMAC-SHA256 signatures

AES-256 encryption stays server-side
Enter fullscreen mode Exit fullscreen mode

Docs and keys: https://quayat.me/api/docs/

Happy to answer questions about the architecture.

Top comments (2)

Collapse
 
hascar profile image
Armando •

i don't think is good practice to ask a credit card number to verify an account...... i'm confused