Baileys WhatsApp Privacy Settings: Complete Configuration Guide

Baileys provides ten privacy categories including last-seen, profile photo, read receipts, and call/group permissions, all configurable via fetchPrivacySettings() and updatePrivacySetting() methods in the socket instance.

The Baileys library exposes WhatsApp Web's full privacy stanza hierarchy through a clean TypeScript API. Whether you need to hide your online status, restrict who can add you to groups, or manage the privacy token system for 1-to-1 messages, all controls are available through the socket's helper methods implemented in src/Socket/chats.ts.

Available Privacy Categories in Baileys

Baileys mirrors WhatsApp's native privacy model with ten configurable categories. The valid values for each are defined in src/WAM/constants.ts under the privacySettings* entries.

Category Controls Valid Values
last Last-seen timestamp visibility all, contacts, contact_blacklist, none
online Online presence visibility all, contacts, contact_blacklist, none
profile Profile information (name, about) all, contacts, contact_blacklist, none
profile_photo Profile picture visibility all, contacts, contact_blacklist, none
status Status updates visibility all, contacts, contact_blacklist, none
readreceipts Read receipt sending all, none
calladd Who can call you all, contacts, contact_blacklist, none
groupadd Who can add you to groups all, contacts, contact_blacklist, none
messages Message-related privacy all, contacts, contact_blacklist, none
privacy_token Token-based anti-spam for 1-to-1 chats true, false

The contact_blacklist value enables allowlist-style control where you explicitly exclude specific contacts from seeing your information.

Core API Methods for Privacy Management

fetchPrivacySettings() — Retrieve Current Configuration

Located in src/Socket/chats.ts, this method sends a privacy IQ query and returns a typed map of all current values.

import makeWASocket from '@whiskeysockets/baileys';

const sock = makeWASocket({ /* auth configuration */ });

const privacy = await sock.fetchPrivacySettings();
console.log(privacy);
// {
//   last: 'contacts',
//   profile: 'all',
//   status: 'contacts',
//   profile_photo: 'all',
//   readreceipts: 'all',
//   online: 'contacts',
//   calladd: 'all',
//   groupadd: 'all',
//   messages: 'all',
//   privacy_token: 'true'
// }

The return type follows ChatPrivacySetting defined in src/Types/Chat.ts.

updatePrivacySetting(name, value) — Modify Individual Settings

This public method delegates to the internal privacyQuery helper in src/Socket/chats.ts to issue set IQ requests.

// Hide last seen from everyone
await sock.updatePrivacySetting('last', 'none');

// Only allow contacts to view your profile photo
await sock.updatePrivacySetting('profile_photo', 'contacts');

// Restrict group additions to contacts only
await sock.updatePrivacySetting('groupadd', 'contacts');

// Completely disable read receipts
await sock.updatePrivacySetting('readreceipts', 'none');

Privacy Token System for 1-to-1 Messages

The privacy_token setting controls an anti-spam mechanism where Baileys generates cryptographic tokens for 1-to-1 conversations. Token generation utilities reside in src/Utils/tc-token-utils.ts.

Disabling Privacy Tokens

// Stop sending privacy tokens (may increase spam risk)
await sock.updatePrivacySetting('privacy_token', 'false');

Handling Token Validation Failures

Incoming messages lacking valid tokens trigger error code 463 in src/Socket/messages-recv.ts. Monitor for these events to detect potential spam or token synchronization issues.

sock.ev.on('messages.upsert', ({ messages }) => {
  for (const msg of messages) {
    if (msg.message?.error?.code === 463) {
      console.warn('Missing privacy token — possible untrusted sender or token refresh needed');
    }
  }
});

Complete Privacy Configuration Example

import makeWASocket, { useMultiFileAuthState } from '@whiskeysockets/baileys';

async function configurePrivacy() {
  const { state, saveCreds } = await useMultiFileAuthState('./auth');
  
  const sock = makeWASocket({
    auth: state,
    printQRInTerminal: true
  });

  sock.ev.on('creds.update', saveCreds);

  // Wait for connection
  await new Promise<void>((resolve) => {
    sock.ev.on('connection.update', ({ connection }) => {
      if (connection === 'open') resolve();
    });
  });

  // Review current settings
  const current = await sock.fetchPrivacySettings();
  console.log('Before:', current);

  // Apply restrictive configuration
  await sock.updatePrivacySetting('last', 'none');
  await sock.updatePrivacySetting('online', 'contacts');
  await sock.updatePrivacySetting('profile_photo', 'contacts');
  await sock.updatePrivacySetting('groupadd', 'contacts');
  await sock.updatePrivacySetting('calladd', 'contacts');
  await sock.updatePrivacySetting('readreceipts', 'none');

  // Verify changes
  const updated = await sock.fetchPrivacySettings();
  console.log('After:', updated);
}

configurePrivacy().catch(console.error);

Source Code Reference Map

File Purpose Key Export
src/Types/Chat.ts TypeScript definitions for privacy types ChatPrivacySetting
src/Socket/chats.ts Socket methods: fetchPrivacySettings, privacyQuery fetchPrivacySettings()
src/WAM/constants.ts Valid values for all privacy categories privacySettings* constants
src/WABinary/constants.ts Binary protocol tags privacy_token tag
src/Socket/messages-recv.ts Incoming notification parser Error 463 handling
src/Utils/tc-token-utils.ts Token generation and validation generatePrivacyToken()

Summary

  • Ten privacy categories are exposed through Baileys, matching WhatsApp Web's native capabilities.
  • fetchPrivacySettings() in src/Socket/chats.ts retrieves all current values as a typed map.
  • updatePrivacySetting(name, value) modifies individual settings with automatic IQ query generation.
  • The privacy token system (privacy_token: true/false) provides cryptographic verification for 1-to-1 conversations, with error code 463 indicating token validation failures in src/Socket/messages-recv.ts.
  • All valid values are centralized in src/WAM/constants.ts for runtime validation.

Frequently Asked Questions

How do I check my current privacy settings in Baileys?

Call await sock.fetchPrivacySettings() on any connected socket instance. This queries WhatsApp's servers and returns a complete map of all ten privacy categories with their current values.

What is the difference between contacts and contact_blacklist in Baileys privacy settings?

contacts allows all contacts to see your information. contact_blacklist enables inverse control—you explicitly select which contacts cannot see the protected information, effectively creating a blocklist while leaving access open to others.

Why am seeing error code 463 when receiving messages?

Error 463 in src/Socket/messages-recv.ts indicates a missing or invalid privacy token. This occurs when privacy_token is enabled but the sender's token fails validation, or when tokens are out of sync. Consider refreshing credentials or contacting the sender to verify their client supports token exchange.

Can I batch-update multiple privacy settings in one request?

No. Baileys issues individual IQ set requests for each category via privacyQuery in src/Socket/chats.ts. For atomic configuration, make sequential calls to updatePrivacySetting—the WhatsApp protocol does not support multi-category updates in a single stanza.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →