Blog · Security and integrations

Security and integrations: 2FA, API keys, webhooks, blocked senders and your data

Protect the account with two-step login, connect other apps through API keys and webhooks, block unwanted senders and export your data.

All of this lives in Settings, on your user page.

Two-step login (2FA)

  1. Under Security: two-step login press Enable 2FA.
  2. You get a 6-digit code by email; confirm it. From now on every sign-in asks for a fresh code.

API keys

  1. Under API keys, name the key (e.g. "Our CRM") and press Create key.
  2. Copy the key immediately, you will not see it again. Use it as a Bearer token in API requests.
  3. Revoke a key any time; integrations using it lose access on the spot.

Webhooks

Under Webhooks add an https URL and pick the events (new conversation, new message, status changed, etc.). You receive a POST signed with the X-Syncon-Signature header (HMAC SHA-256) and see failed deliveries next to each webhook.

Blocked senders, spam and antivirus

  • When you mark an email as spam you can also block the sender (the address or the whole domain). The list is in Settings → Blocked senders; blocked messages stay, marked as spam, nothing is deleted.
  • On plans with the spam filter, the AI triages suspicious messages automatically; on plans with antivirus, attachments are scanned before download.

Your data (GDPR)

Under Your data you export your personal data as JSON or delete your account (a teammate deletes their user; the owner deletes the whole company account, with password confirmation).

All your companies. One inbox.

Email, website chat, WhatsApp, Messenger and Instagram in a single inbox shared with your team. The first domain is free.

Start free