Build your next conversation.
The API reference and integration guide for your WhatsApp workspace.
DEVELOPER DOCUMENTATION
From zero to your first request.
Create an account, open API keys, and generate a sandbox key. Create a sandbox session and use its ID to send a test request. No phone connection or paid plan is required for sandbox tests.
curl -X POST "http://localhost:3000/api/v1/sessions" \ -H "Authorization: Bearer YOUR_SANDBOX_KEY" \ -H "Content-Type: application/json" \ -d '{"name":"Development","mode":"sandbox"}'
simulated: true.
They do not send messages to WhatsApp.
Authenticate with a secret API key.
Keep keys in server environment variables. Never place them in HTML, client JavaScript, public repositories, or URLs. Revoke and replace a key from the dashboard if it is exposed.
curl "http://localhost:3000/api/v1/me" -H "Authorization: Bearer YOUR_API_KEY"
Manage sessions and QR connections.
| Method | Endpoint | Behavior |
|---|---|---|
| GET | /sessions | List sessions matching your API key environment. |
| POST | /sessions | Create with {name, mode}. |
| GET | /sessions/id | Read status; qr.image is a data URL when available. |
| POST | /sessions/id/connect | Start a live QR connection or mark sandbox ready. |
| POST | /sessions/id/disconnect | Stop the connection while retaining credentials. |
| DELETE | /sessions/id | Log out and remove this session. |
Send messages from your server.
Use an international phone number with 8–15 digits, country code first, and no + or spaces. A message body may contain up to 4,000 characters.
const response = await fetch("http://localhost:3000/api/v1/messages", { method: "POST", headers: { "Authorization": "Bearer " + process.env.WA_API_KEY, "Content-Type": "application/json", "Idempotency-Key": crypto.randomUUID() }, body: JSON.stringify({ session_id: "YOUR_SESSION_ID", to: "923001234567", body: "Hello from my application!" }) }); const data = await response.json(); if (!response.ok) throw new Error(data.error); console.log(data);
Reuse the same Idempotency-Key when retrying an uncertain request. The same key and payload return the stored result; a different payload with that key returns 409. If a live send has status unknown, check WhatsApp before creating a new request.
{ "session_id": "YOUR_SESSION_ID", "to": "923001234567", "body": "Your invoice is attached.", "media": { "mimetype": "application/pdf", "filename": "invoice.pdf", "data": "BASE64_ENCODED_FILE" } }
Receive and verify events.
Add WhatsApp to your website.
In Website widget, choose your business name, WhatsApp number, message, color, and position. Save and copy the generated code into your website before the closing body tag.
<script src="http://localhost:3000/embed.js" data-widget="YOUR_WIDGET_ID" defer></script>
Plans and NayaPay payments.
Limits and errors.
| Status | Meaning |
|---|---|
| 400 | Invalid fields. Read the error property. |
| 401 | Missing, invalid, revoked key or expired sign-in. |
| 402 | A paid plan is required or access has expired. |
| 403 | Access denied, domain restriction, or session limit. |
| 404 | Resource not found in this account/environment. |
| 409 | Conflicting request, disconnected session, or duplicate reference. |
| 429 | Message quota or request rate limit reached. |
| 502 | Provider result uncertain. Check history before resending. |
| 503 | Required server integration is not configured. |