XChat launches X Numbers, private codes that bypass closed inboxes

The optional, refreshable codes let people reach a user's main Chat inbox and place calls without a mutual follow.

By · Published

Primary source: XChat on X

Why it matters

X Numbers give XChat a revocable contact layer that can travel beyond the social graph, supporting direct business and personal outreach without exposing a phone number or opening an inbox to everyone.

A hand holds a smartphone displaying a glowing, abstract interface, suggesting direct digital contact.

X launched X Numbers on September 22nd, giving XChat users a private code they can share with people who need to message or call them without first establishing a mutual follow.

https://x.com/chat/status/2102442240354165057

poster=/api/storage/public-objects/tweet-videos/xchat-launches-x-numbers-private-codes-closed-inboxes-poster-3ac3d7a5.jpg|Video from @chat on X

XChat announced the feature in a two-post thread, describing it as an optional contact method that removes the need to accept a message request or follow the sender. Despite the name, an X Number is a private code rather than a telephone number. It also differs from the safety numbers used to verify identities in encrypted conversations.

The feature gives XChat a second address layer. A public X username identifies an account, while an X Number grants direct access to its Chat inbox. Someone who enters an enabled code can message its owner even when the account has a closed inbox. The conversation lands in the main inbox instead of message requests. The sender may also place a call if the recipient's call settings permit it.

That makes the code function like a revocable contact credential. A founder could share one with prospective customers, a creator could give one to collaborators, or a recruiter could use one for candidates without opening an inbox to every X account.

A code that can be replaced

Users create and manage an X Number from the Number option in Chat's inbox menu, according to X's documentation for the feature. They can enable the code, share it, disable it or refresh it. Refreshing produces a replacement code and prevents someone holding only the previous one from using it to begin a new conversation.

The code does not disturb established routes into an inbox. Accounts a user follows, existing Chat contacts and members of the same Premium Business or Premium Organization can continue reaching that user without entering an X Number.

X Numbers also carry the usual risk of any shareable access credential: recipients can pass them along. X says people who have already exchanged direct messages with a user can see that user's code unless the owner enables the "Hide from others" setting. Anyone who obtains the current code can use it while it remains enabled, regardless of whether the owner follows them.

X says Chat identifies conversations initiated with an X Number, allowing the recipient to disable or refresh the code after unwanted contact. Blocking an account remains a separate control for stopping an existing contact.

XChat separates identity from access

XChat has pitched its dedicated messaging app around an advantage inherited from X: users already have an account and a network of contacts, so they do not need to exchange telephone numbers or persuade people to join another service. X Numbers extend that pitch to people outside a user's existing network while preserving control over who can cross a closed inbox.

The design also gives X a way to support off-platform contact sharing without making a user's telephone number the identifier. A person can put an X Number on a business card, send it privately or replace it after a project ends. Their X account remains unchanged.

The number changes who can initiate contact. It does not change XChat's underlying security model. Chat creates a public-private key pair for registered users and encrypts conversation content with per-conversation keys. X says it stores recoverable private-key shares through the open-source Juicebox protocol, with a PIN that remains on the user's device. X has also published its Chat encryption SDK.

X's own documentation lists material limits. Associated metadata, including recipients and creation times, is not encrypted. The current system lacks forward secrecy, meaning a compromised private key could expose messages handled by the affected device. Adding Grok to a conversation removes end-to-end encryption while Grok is present, and messages sent during that period do not become encrypted after it leaves.

Calls introduce another privacy setting. X's calling documentation says peer-to-peer calls can expose participants' IP addresses when both sides have enhanced call privacy disabled. Enabling that control routes the call through X infrastructure to mask the protected participant's address. Users sharing an X Number broadly will need to manage that setting alongside the code itself.

X Numbers turn a closed inbox from an absolute barrier into a selective one. XChat users can now issue, revoke and replace access without changing their public identity or exposing a telephone number. Whether the code stays selective depends on where its owner shares it and how quickly they rotate it when it travels further than intended.

Reader comments

Conversation for this story loads after sign-in.