// the find
rmyndharis/OpenWA
Free, Open Source, Self-Hosted WhatsApp API Gateway
OpenWA is a self-hosted gateway that exposes whatsapp-web.js and Baileys through one REST/MCP API, for developers who want programmatic WhatsApp without Meta's Cloud API or vendor lock-in. It's a NestJS/TypeScript service with a bundled React dashboard, multi-session support, and swappable storage/cache/database backends — a reasonable fit for internal tooling, bots, and automation hobbyists, not for anything regulated.
The access-control model is unusually granular for a self-hosted tool: API keys can be scoped to specific sessions and specific chats, with unmarked/future routes defaulting to refusal rather than silent access — the right failure mode for pointing an agent at a shared account. The README is upfront about the category's actual risk: it explains ban mechanics, the Chromium-footprint-vs-fingerprint tradeoff between the two engines, and links known platform-level failure modes (passkey linking gate, silent first-message drops) to tracked GitHub issues instead of glossing over them. Docker hardening is done properly — non-root execution via gosu/dumb-init, and a socket-proxy sidecar instead of mounting the Docker socket into the app container directly. The MCP server defaults to a read-only 25-tool surface and reuses the same per-session/per-chat auth as REST, rather than being a separate unauthenticated door for agents.
The project sits entirely on reverse-engineered clients, and the pile of patch-wwebjs-*.js / patch-baileys-*.js scripts in the repo shows how much ongoing patching is needed just to keep those dependencies functional — that's a recurring maintenance tax on the maintainers, not a one-time integration cost. Send pacing is off by default and there's no per-minute cap at all, only an opt-in daily allowance — a developer who skips the risk-management doc can hot-loop requests straight into a ban with no guardrail stopping them. Media is returned inline to API/webhook consumers but isn't persisted to the configured storage backend, so anyone assuming S3/MinIO gives them a durable media archive is wrong. The Docker socket proxy's own security doc reportedly admits it isn't a real privilege boundary once POST is enabled — a compromised app container is effectively host-root-equivalent, which undercuts the hardening story for anyone relying on the built-in orchestration.