The server side: APIs, databases, queues, and the failures that only show up under load.
initDataUnsafe is attacker-controlled; the signed initData string is the only thing worth parsing. The exact HMAC-SHA256 algorithm, the auth_date freshness question the docs leave open, and what the 10.2 domain lock does not cover.
Sep 16, 2026 · Backend · 3 min