Baileys WhatsApp Privacy Settings: Complete Configuration Guide
Baileys provides ten privacy categories including last-seen, profile photo, read receipts, and call/group permissions, all configurable via fetchPrivacySettings() and updatePrivacySetting() methods in the socket instance.
The Baileys library exposes WhatsApp Web's full privacy stanza hierarchy through a clean TypeScript API. Whether you need to hide your online status, restrict who can add you to groups, or manage the privacy token system for 1-to-1 messages, all controls are available through the socket's helper methods implemented in src/Socket/chats.ts.
Available Privacy Categories in Baileys
Baileys mirrors WhatsApp's native privacy model with ten configurable categories. The valid values for each are defined in src/WAM/constants.ts under the privacySettings* entries.
| Category | Controls | Valid Values |
|---|---|---|
last |
Last-seen timestamp visibility | all, contacts, contact_blacklist, none |
online |
Online presence visibility | all, contacts, contact_blacklist, none |
profile |
Profile information (name, about) | all, contacts, contact_blacklist, none |
profile_photo |
Profile picture visibility | all, contacts, contact_blacklist, none |
status |
Status updates visibility | all, contacts, contact_blacklist, none |
readreceipts |
Read receipt sending | all, none |
calladd |
Who can call you | all, contacts, contact_blacklist, none |
groupadd |
Who can add you to groups | all, contacts, contact_blacklist, none |
messages |
Message-related privacy | all, contacts, contact_blacklist, none |
privacy_token |
Token-based anti-spam for 1-to-1 chats | true, false |
The contact_blacklist value enables allowlist-style control where you explicitly exclude specific contacts from seeing your information.
Core API Methods for Privacy Management
fetchPrivacySettings() — Retrieve Current Configuration
Located in src/Socket/chats.ts, this method sends a privacy IQ query and returns a typed map of all current values.
import makeWASocket from '@whiskeysockets/baileys';
const sock = makeWASocket({ /* auth configuration */ });
const privacy = await sock.fetchPrivacySettings();
console.log(privacy);
// {
// last: 'contacts',
// profile: 'all',
// status: 'contacts',
// profile_photo: 'all',
// readreceipts: 'all',
// online: 'contacts',
// calladd: 'all',
// groupadd: 'all',
// messages: 'all',
// privacy_token: 'true'
// }
The return type follows ChatPrivacySetting defined in src/Types/Chat.ts.
updatePrivacySetting(name, value) — Modify Individual Settings
This public method delegates to the internal privacyQuery helper in src/Socket/chats.ts to issue set IQ requests.
// Hide last seen from everyone
await sock.updatePrivacySetting('last', 'none');
// Only allow contacts to view your profile photo
await sock.updatePrivacySetting('profile_photo', 'contacts');
// Restrict group additions to contacts only
await sock.updatePrivacySetting('groupadd', 'contacts');
// Completely disable read receipts
await sock.updatePrivacySetting('readreceipts', 'none');
Privacy Token System for 1-to-1 Messages
The privacy_token setting controls an anti-spam mechanism where Baileys generates cryptographic tokens for 1-to-1 conversations. Token generation utilities reside in src/Utils/tc-token-utils.ts.
Disabling Privacy Tokens
// Stop sending privacy tokens (may increase spam risk)
await sock.updatePrivacySetting('privacy_token', 'false');
Handling Token Validation Failures
Incoming messages lacking valid tokens trigger error code 463 in src/Socket/messages-recv.ts. Monitor for these events to detect potential spam or token synchronization issues.
sock.ev.on('messages.upsert', ({ messages }) => {
for (const msg of messages) {
if (msg.message?.error?.code === 463) {
console.warn('Missing privacy token — possible untrusted sender or token refresh needed');
}
}
});
Complete Privacy Configuration Example
import makeWASocket, { useMultiFileAuthState } from '@whiskeysockets/baileys';
async function configurePrivacy() {
const { state, saveCreds } = await useMultiFileAuthState('./auth');
const sock = makeWASocket({
auth: state,
printQRInTerminal: true
});
sock.ev.on('creds.update', saveCreds);
// Wait for connection
await new Promise<void>((resolve) => {
sock.ev.on('connection.update', ({ connection }) => {
if (connection === 'open') resolve();
});
});
// Review current settings
const current = await sock.fetchPrivacySettings();
console.log('Before:', current);
// Apply restrictive configuration
await sock.updatePrivacySetting('last', 'none');
await sock.updatePrivacySetting('online', 'contacts');
await sock.updatePrivacySetting('profile_photo', 'contacts');
await sock.updatePrivacySetting('groupadd', 'contacts');
await sock.updatePrivacySetting('calladd', 'contacts');
await sock.updatePrivacySetting('readreceipts', 'none');
// Verify changes
const updated = await sock.fetchPrivacySettings();
console.log('After:', updated);
}
configurePrivacy().catch(console.error);
Source Code Reference Map
| File | Purpose | Key Export |
|---|---|---|
src/Types/Chat.ts |
TypeScript definitions for privacy types | ChatPrivacySetting |
src/Socket/chats.ts |
Socket methods: fetchPrivacySettings, privacyQuery |
fetchPrivacySettings() |
src/WAM/constants.ts |
Valid values for all privacy categories | privacySettings* constants |
src/WABinary/constants.ts |
Binary protocol tags | privacy_token tag |
src/Socket/messages-recv.ts |
Incoming notification parser | Error 463 handling |
src/Utils/tc-token-utils.ts |
Token generation and validation | generatePrivacyToken() |
Summary
- Ten privacy categories are exposed through Baileys, matching WhatsApp Web's native capabilities.
fetchPrivacySettings()insrc/Socket/chats.tsretrieves all current values as a typed map.updatePrivacySetting(name, value)modifies individual settings with automatic IQ query generation.- The privacy token system (
privacy_token: true/false) provides cryptographic verification for 1-to-1 conversations, with error code463indicating token validation failures insrc/Socket/messages-recv.ts. - All valid values are centralized in
src/WAM/constants.tsfor runtime validation.
Frequently Asked Questions
How do I check my current privacy settings in Baileys?
Call await sock.fetchPrivacySettings() on any connected socket instance. This queries WhatsApp's servers and returns a complete map of all ten privacy categories with their current values.
What is the difference between contacts and contact_blacklist in Baileys privacy settings?
contacts allows all contacts to see your information. contact_blacklist enables inverse control—you explicitly select which contacts cannot see the protected information, effectively creating a blocklist while leaving access open to others.
Why am seeing error code 463 when receiving messages?
Error 463 in src/Socket/messages-recv.ts indicates a missing or invalid privacy token. This occurs when privacy_token is enabled but the sender's token fails validation, or when tokens are out of sync. Consider refreshing credentials or contacting the sender to verify their client supports token exchange.
Can I batch-update multiple privacy settings in one request?
No. Baileys issues individual IQ set requests for each category via privacyQuery in src/Socket/chats.ts. For atomic configuration, make sequential calls to updatePrivacySetting—the WhatsApp protocol does not support multi-category updates in a single stanza.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →