Skip to content

Changelog

API changelog

Changes to the whatsappx.si API and these docs, newest first. If you built against the earlier in-app API docs, check the corrections below.

2026-10-03: public developer docs and corrections

The developer docs moved to whatsappx.si/docs. They were checked line by line against the API, and several statements in the earlier in-app docs turned out to be wrong. Most items below are documentation corrections; the one access change is marked Changed.

Live events (SSE)

  • Event names are message.created, conversation.updated and sync.progress (not message, conversation and sync_progress).
  • Each data: line is an envelope {type, workspace_id, payload, at}, not the raw payload. See Live events.

Webhooks

  • A webhook’s events value is messages, not *, and it is not a filter: every enabled webhook receives every delivery.
  • Generated shared tokens look like whtok_… (48 hex characters after the prefix).
  • The retry policy is now documented: 3 attempts, 5-second timeout, no delivery log or replay.
  • The scan.whatsapp payload for QR-linked numbers is now documented. See Webhook events.

Message status

  • Delivered and read receipts are not tracked. A message’s status is only received or sent.

Errors and authentication

  • The error Workspace access denied does not exist. The real messages are forbidden, workspace required (X-Tenant-ID) and API key belongs to a different workspace.
  • The status list now includes 413 and 503, and 429 applies only to the sign-in and email endpoints. See Errors and limits.
  • Changed: POST /api/whatsapp/connect and POST /api/whatsapp/disconnect (linking or unlinking the QR-linked number) are now Console only: an owner or admin signed in to the app. API keys get 403 with API keys cannot administer workspaces.
  • POST /api/v1/knowledge-ai/answer and POST /api/v1/assistant need a write key (or a session); a read key gets API key is read-only.

Responses

  • GET /api/whatsapp/qr returns {code, image, pending}, not {qr, qr_pending, connected}.
  • POST /api/conversations/{id}/read returns the conversation object, not {id, unread_count}.
  • Members include user_id. Use user_id (not the membership id) as assignee_id.
  • GET /api/health returns a services map and 503 with status: "degraded" when a dependency is down.

Newly documented

  • Limits: conversation list capped at 30; contacts, templates and knowledge lists capped at 500; message limit above 100 falls back to 50; at most 10 webhooks; template sync imports Meta’s first page only.
  • Message media download paths (media_url). See List messages.
  • Sign-in endpoints and their rate limits are listed in Authentication and Errors and limits.