Developers

An API, signed webhooks, and code that runs where the inbox is.

Three surfaces, documented, with the plan each one starts on stated rather than implied.

REST API

From Starter

Keys you issue and revoke yourself, sent as an X-API-Key header. The same endpoints the app uses — contacts, messages, templates, campaigns, flows, teams, analytics.

API reference →

Outbound webhooks

From Starter

Seven event types, delivered to your endpoint with an HMAC signature in X-Webhook-Signature so you can verify the payload came from us. Failed deliveries retry three times with exponential backoff.

Webhook reference →

Custom actions

From Growth

Buttons in the inbox that call your webhook, open a URL, or run JavaScript you wrote — server-side, in a sandbox with a two-second execution ceiling and no filesystem or network of its own.

What it is for →

Seven events, signed and retried

Point an endpoint at us, pick the events you want, set a secret. Every payload arrives with an HMAC signature you can check against the raw body.

message.incoming

A customer sent you a message.

message.outgoing

A message went out from the workspace.

message.sent

A message you sent was accepted by Meta.

contact.created

A contact was created.

transfer.created

A conversation entered the transfer queue.

transfer.assigned

A queued conversation was assigned to someone.

transfer.resumed

A transferred conversation was picked back up.

Two things worth designing for

Retries are not exactly-once. A failed delivery is retried three times with exponential backoff, and a retry can land after a delivery your side already processed. Make your handler idempotent on the message ID.

Verify before you trust. The signature is the only thing that proves a payload came from us. An endpoint that acts on unverified webhook bodies is an endpoint anyone who learns its URL can drive.

Code that runs where the conversation is

A custom action is a button in the inbox. Three kinds, and the third is the interesting one.

webhook

Calls your endpoint with the conversation context and shows the agent what comes back.

url

Opens your own tool with the contact already in it — a CRM record, an order screen.

javascript

Runs on our server in a sandbox: a two-second ceiling, no filesystem, no network, no reach into another tenant.

The sandbox is deliberately narrow. Running tenant-authored JavaScript on a shared server is a different risk from posting a webhook, which is also why custom actions start on Growth rather than on the entry plan — and why the script cannot make network calls itself. When it needs to reach your systems, the webhook action type is the right tool.

Questions

Questions from developers

Which plans include API access and webhooks?

Outbound webhooks start on Starter, the ₹1,999 entry plan, with up to five endpoints. API keys and custom actions start on Growth at ₹4,499, which also raises webhooks to twenty-five. The free evaluation tier has none of the three — every one of them makes our server issue outbound HTTP on your behalf, which an unpaid tier has no business doing.

How do I authenticate?

Issue a key in the workspace and send it as an X-API-Key header. Keys are scoped to your organisation, and you can revoke one without touching the others.

How do I verify a webhook actually came from you?

Set a secret on the endpoint and we sign every payload with HMAC, sent as X-Webhook-Signature. Compute the same signature over the raw body and compare — if it does not match, discard the request.

What happens if my endpoint is down?

We retry three times with exponential backoff — roughly one second, two, then four. After that the delivery is given up on and logged. Design your endpoint to be idempotent, since a retry can arrive after a delivery you already processed.

What can custom-action JavaScript do?

Transform data and decide what to show the agent. It runs on our server in a sandbox with a two-second ceiling and no filesystem, no network and no access to other tenants. If you need to reach your own systems, use the webhook action type rather than trying to make a request from the script.

Is there a sandbox environment?

Not a separate one. What we would suggest instead is a second WhatsApp number on your workspace — every paid plan includes unlimited numbers, so a test number costs you nothing beyond the messages it sends.

Talk to a person

Tell us what your team is dealing with.

We will walk your own use case through the product on a call. Pick a plan and your workspace is live as soon as payment clears, or book a demo and we will pick it up from there.