Webhooks
Create a webhook
Adds a webhook that is enabled right away. The response contains the signing secret (and the token, if you set or generated one) only this once. A workspace can have at most 10 webhooks.
- Console only: owner or admin
- Workspace:
X-Tenant-ID
Headers
CookiestringrequiredThe
whatsappx_sessioncookie the app sets when you sign in. Browsers send it automatically; API keys are not accepted on this endpoint.X-Tenant-IDuuidrequiredWorkspace id. Required for session requests. You can pass
?tenant=<id>instead.
Body
application/jsonurlstringrequiredWhere deliveries are posted.
tokenstringoptionalOptional shared token sent as
X-Whatsappx-Webhook-Tokenon every delivery. Ignored whengenerate_tokenistrue.generate_tokenbooleanoptionalGenerate a random token (
whtok_+ 48 hex characters) instead of passing your own.
Response
201 Createdapplication/json
iduuidWebhook id.
urlstringHTTPS URL that receives deliveries.
eventsstringAlways
messages. It is informational and not a filter: every enabled webhook receives every event.enabledbooleanWhether deliveries are sent.
has_tokenbooleanWhether a shared token is sent in
X-Whatsappx-Webhook-Token.created_atintegerCreation time in Unix seconds.
secretstringmay be absentSigning secret (
whsec_+ 48 hex characters). Returned only in the create response; store it to verifyX-Hub-Signature-256.tokenstringmay be absentThe shared token, returned only in the response that set or generated it. Generated tokens are
whtok_+ 48 hex characters.
Status codes
- 201Created. The new webhook, including
secret(andtokenwhen set). Store them now: they are not shown again. - 400Bad request.
Webhook URL must be at most 2048 characters,Enter a valid https:// URL, for example https://example.com/hooks/whatsapp,webhook URL must use https,localhost webhook URLs are not allowed,webhook token must be 8–256 characters,webhook token contains invalid characters,limit of 10 webhooks per workspace reachedorinvalid body. - 401Unauthorized. No signed-in session (
unauthorized). - 403Forbidden. API keys can never call this endpoint (
API keys cannot administer workspaces). A signed-in user who is not an owner or admin getsadmin required; a user who is not a member of the workspace getsforbidden.
What gets delivered, the headers and how to verify signatures are described in Webhooks and Webhook events.