Explore


Home About Pricing Studio Api Contact

Language

logo

powered by amerencio

Back to overview

Support areas

Security

2FA, verification codes, OAuth warnings, domains, secrets, logs and sensitive actions.

Verification codes protect account access, OAuth provider connections, account unlock, and sensitive account changes. The required method depends on your account security settings.

verification security account

No. For verification flows that use the standard account verification helper, XWMS uses the authenticator code when 2FA is enabled and only sends email codes when 2FA is not enabled.

2fa email verification

Store client secrets only on your backend or server environment. Never expose a client secret in frontend JavaScript, public repositories, screenshots, or browser-readable configuration.

api client-secret security

Yes. XWMS records API request metadata for audit, debugging, usage tracking, and security review. Sensitive values should not be exposed in logs.

api logs audit

Yes. Connected external login accounts can be removed from your account area after account verification when required.

external-login security account

Live support

Start a conversation

Welcome back. Start a ticket or leave your question.