Web Application Firewall (WAF) for Exotel APIs
Overview
Exotel has implemented a Web Application Firewall (WAF) for the majority of its public APIs as part of an ongoing platform security hardening initiative.
The WAF inspects inbound API traffic and helps block malicious or malformed requests before they reach Exotel’s core services. This is part of a defense-in-depth approach to security and is intended to help mitigate common web attack patterns, including categories broadly covered under the OWASP Top 10.
This is a platform-level enhancement and does not require any change to existing customer integrations.
Scope
The WAF currently protects the majority of Exotel’s public internet-facing APIs served through:
- api.exotel.com
- api.in.exotel.com
For the list of supported APIs and endpoint details, refer to the Exotel API documentation.
This protection layer complements existing application-level controls such as authentication, authorization, and request validation. Coverage may expand over time as part of Exotel’s broader platform hardening efforts.
What this means for customers
For most customers, no action is required.
Existing integrations will continue to work as usual, provided requests follow Exotel’s documented API specifications and standard HTTP practices.
If a request is blocked by the WAF, the API returns an HTTP 403 Forbidden response.
Threats this helps mitigate
The WAF is intended to help protect against common exploit patterns such as:
- SQL injection attempts
- Cross-site scripting (XSS) patterns
- Remote code execution signatures
- File inclusion exploit attempts
- Known exploit payloads
Some protections may operate in monitoring mode during phased rollout or tuning, while the rest are enforced in blocking mode.
Best practices
To reduce the likelihood of legitimate requests being flagged:
- Follow Exotel’s documented request formats
- Send well-formed headers, parameters, and payloads
- Validate and sanitize inputs before sending requests
- Use standard retry logic for transient failures
Reporting availability
If needed for infosec, audit, or compliance requirements, Exotel can provide a report covering the last 7 days.
Troubleshooting
If you believe a legitimate request was blocked, please share the following with Exotel Support:
- Tenant ID / Account identifier
- API endpoint
- Approximate timestamp
- Source IP, if available
- HTTP method
- Response code
- Request ID / correlation ID, if available
- Sample request details with sensitive values masked
FAQ
Do I need to change my integration?
No. Existing integrations should continue to work without modification if they follow documented API behavior.
Does this apply to all Exotel APIs?
No. The WAF currently protects the majority of Exotel’s public APIs, not all APIs.
Which API domains are currently covered?
The current WAF coverage applies to APIs served through:
- api.exotel.com
- api.in.exotel.com
Please refer to the API documentation for endpoint-level details.
Does this help with OWASP Top 10 risks?
Yes. The WAF is intended to add protection against several common web attack categories broadly covered under the OWASP Top 10. It works alongside application-level controls and does not replace them.
What happens when a request is blocked?
The API returns an HTTP 403 Forbidden response.
Change summary
Change type: Platform security enhancement Customer action required: None Backward compatibility: Yes, for standards-compliant API usage