Trust & Safety

Security overview

Signal is credential-minimal and OAuth-first. It never asks for platform passwords, cookies, 2FA codes, or recovery codes, and stores tokens encrypted.

Last updated June 14, 2026

Signal's security posture is a product decision. It connects to platforms with the narrowest credential each one supports, stores those credentials encrypted at rest, and keeps them revocable from inside the app.

Signal never asks for

  • ·Your platform password.
  • ·Cookies or browser session tokens.
  • ·2FA or recovery codes.
  • ·Proxy or fingerprint configuration.

How accounts connect

  • ·X, Reddit, LinkedIn — official OAuth, scopes requested explicitly.
  • ·Bluesky — an app password (not your main password).
  • ·dev.to, Hashnode — a personal API key/token.
  • ·Tokens are encrypted at rest and revocable from Accounts.