Security at PostWire

PostWire holds the keys to your social accounts, so this page says exactly how they are kept, read from the code that runs in production — not a list of badges. Last reviewed .

Your social accounts' tokens

When you connect a network, you sign in on the network's own page (TikTok, Instagram, Facebook, YouTube, LinkedIn) and PostWire receives an access token from it. PostWire never sees your password for those networks. Bluesky works with an app password you create for PostWire, Telegram with your bot's token and Discord with a channel webhook; they are kept the same way.

WhatHow it is kept
Platform tokens and credentialsEncrypted at rest with AES-256-GCM (authenticated encryption: a changed byte fails to decrypt) and a fresh random 96-bit IV for every write. The 256-bit key lives in the server's environment, not in the database, so a copy of the database alone cannot be decrypted. Stored in PostWire's Postgres database (Supabase).
Listing your accountsThe handle, name and picture each network reports are kept in separate plain columns, so showing your connected accounts never decrypts a token.
Your PostWire API keysShown once when created. PostWire stores only their SHA-256 hash and a short prefix to tell them apart. Revoke any key from the dashboard.
Sign-in for Claude, ChatGPT and other MCP clientsOAuth 2.1 with PKCE (S256). Access tokens last 1 hour, refresh tokens 60 days and rotate on use; PostWire stores only their SHA-256 hashes. A connected app can be revoked through the API (DELETE /api/connected-apps/{id}), or by removing the connector in the AI app.
Webhook signing secretsEncrypted with the same AES-256-GCM scheme.
Your PostWire loginAn email code or link, or Continue with Google: PostWire has no account passwords to leak.
Continue with GoogleOpenID Connect with PKCE, a one-time state and nonce. PostWire asks Google only for openid, email and profile: no access to your Gmail, Drive, contacts or calendar, and no Google token is kept. The ID token's signature, issuer, audience, expiry and nonce are checked, and the address must be verified by Google.
PaymentsStripe Checkout and Stripe's billing portal. Card numbers go to Stripe and never reach PostWire.
In transitHTTPS only, with HSTS. Pages send a Content-Security-Policy, X-Frame-Options: DENY and nosniff. Media links you give PostWire are fetched only from public https hosts, re-checked at every redirect, so they cannot reach internal addresses.

The AI agent never sees your platform tokens

When Claude, ChatGPT, Cursor or any agent uses PostWire, this is what happens:

  1. The agent calls a PostWire tool, such as post_to_social, with the text and the networks.
  2. PostWire checks the agent's PostWire token (its expiry, revocation, audience and scopes) and runs the same code path as the API, with every plan limit and duplicate guard.
  3. On PostWire's server, the network's token is decrypted only to make that one call to the network.
  4. The agent gets back the result: the network, the post's link, the handle it went to, or the network's error. No tool returns a platform token, and no tool can.

The same holds through an MCP gateway such as CoreSpeed or Composio: it keeps only the PostWire token it uses to call PostWire. When PostWire writes drafts, the idea you give it is sent to its AI model provider (Anthropic) to write the text, as the Privacy Policy says; tokens are never part of that.

Publishing needs your approval in the conversation: PostWire's publishing tools are annotated as destructive and open-world in MCP, so assistants such as Claude ask before running them, and the agent setup skill tells any agent to show every draft and wait for a yes.

Reviewed by the platforms

You connect your accounts to PostWire's own apps, which each platform reviewed before letting them publish for other people:

  • TikTok: Content Posting API, Direct Post audit approved . What that review involved.
  • Meta: App Review for Instagram and Facebook Pages approved . Details.
  • Google: verification of YouTube uploads (the youtube.upload scope) approved . Details.

These are the platforms' own reviews of how PostWire uses their APIs and your data. PostWire has no SOC 2 or ISO 27001 certification, and does not claim one.

Deleting your data

  • One network: disconnect it in the dashboard and its stored token is deleted at once.
  • Your whole account: follow the data deletion instructions; every encrypted token, API key, post record and usage record goes with it.
  • Uploaded media: photos and videos uploaded through PostWire are kept 30 days, then removed.
  • From the network's side: you can also remove PostWire from the network's own settings (for example Facebook → Apps and Websites); PostWire can no longer use that token.

Status and changes

Whether the API, the MCP server and the scheduler are working, and how many posts each network accepted over the last 30 days, is on the status page, live from production. Every change a customer would notice is dated in the changelog.

Report a vulnerability

Email support@postwire.io with Security in the subject: what you found, the steps to reproduce it, and the URLs or requests involved. The same address is in /.well-known/security.txt.

  • Test only against your own PostWire account and your own social accounts. Do not access, change or delete anyone else's data.
  • No denial-of-service, spam or social engineering of users or of the platforms PostWire publishes to.
  • Give us a reasonable time to fix it before you publish anything about it.

PostWire is operated by PMJ LIFE STORE LLC, 7901 4th St N, Suite 4707, St. Petersburg, FL 33702, USA. About PostWire.