---
title: Web Application Firewall (WAF) for Exotel APIs
slug: security
docTags: 
createdAt: 2026-04-09T05:52:17.432Z
---

## Overview

Exotel has implemented a **Web Application Firewall (WAF)** for the **majority of its public APIs** as part of an ongoing platform security hardening initiative.

The WAF inspects inbound API traffic and helps block malicious or malformed requests before they reach Exotel’s core services. This is part of a **defense-in-depth** approach to security and is intended to help mitigate common web attack patterns, including categories broadly covered under the [OWASP Top 10](https://owasp.org/Top10/2025/).

This is a platform-level enhancement and does not require any change to existing customer integrations.

## Scope

The WAF currently protects the **majority of Exotel’s public internet-facing APIs** served through:

- api.exotel.com&#x20;
- api.in.exotel.com&#x20;

For the list of supported APIs and endpoint details, refer to the Exotel API documentation.

This protection layer complements existing application-level controls such as authentication, authorization, and request validation. Coverage may expand over time as part of Exotel’s broader platform hardening efforts.

## What this means for customers

For most customers, no action is required.

Existing integrations will continue to work as usual, provided requests follow Exotel’s documented API specifications and standard HTTP practices.

If a request is blocked by the WAF, the API returns an HTTP **403 Forbidden** response.

## Threats this helps mitigate

The WAF is intended to help protect against common exploit patterns such as:

- SQL injection attempts&#x20;
- Cross-site scripting (XSS) patterns&#x20;
- Remote code execution signatures&#x20;
- File inclusion exploit attempts&#x20;
- Known exploit payloads&#x20;

Some protections may operate in **monitoring mode** during phased rollout or tuning, while the rest are enforced in **blocking mode**.

## Best practices

To reduce the likelihood of legitimate requests being flagged:

- Follow Exotel’s documented request formats&#x20;
- Send well-formed headers, parameters, and payloads&#x20;
- Validate and sanitize inputs before sending requests&#x20;
- Use standard retry logic for transient failures&#x20;

## Reporting availability

If needed for infosec, audit, or compliance requirements, Exotel can provide a report covering the last 7 days.

## Troubleshooting

If you believe a legitimate request was blocked, please share the following with Exotel Support:

- Tenant ID / Account identifier&#x20;
- API endpoint&#x20;
- Approximate timestamp&#x20;
- Source IP, if available&#x20;
- HTTP method&#x20;
- Response code&#x20;
- Request ID / correlation ID, if available&#x20;
- Sample request details with sensitive values masked&#x20;

## FAQ

### Do I need to change my integration?

No. Existing integrations should continue to work without modification if they follow documented API behavior.

### Does this apply to all Exotel APIs?

No. The WAF currently protects the **majority of Exotel’s public APIs**, not all APIs.

### Which API domains are currently covered?

The current WAF coverage applies to APIs served through:

- api.exotel.com&#x20;
- api.in.exotel.com&#x20;

Please refer to the API documentation for endpoint-level details.

### Does this help with OWASP Top 10 risks?

Yes. The WAF is intended to add protection against several common web attack categories broadly covered under the OWASP Top 10. It works alongside application-level controls and does not replace them.

### What happens when a request is blocked?

The API returns an HTTP **403 Forbidden** response.

## Change summary

**Change type:** Platform security enhancement
**Customer action required:** None
&#x20;**Backward compatibility:** Yes, for standards-compliant API usage
