Changelog
API changelog
Changes to the whatsappx.si API and these docs, newest first. If you built against the earlier in-app API docs, check the corrections below.
2026-10-03: public developer docs and corrections
The developer docs moved to whatsappx.si/docs. They were checked line by line against the API, and several statements in the earlier in-app docs turned out to be wrong. Most items below are documentation corrections; the one access change is marked Changed.
Live events (SSE)
- Event names are
message.created,conversation.updatedandsync.progress(notmessage,conversationandsync_progress). - Each
data:line is an envelope{type, workspace_id, payload, at}, not the raw payload. See Live events.
Webhooks
- A webhook’s
eventsvalue ismessages, not*, and it is not a filter: every enabled webhook receives every delivery. - Generated shared tokens look like
whtok_…(48 hex characters after the prefix). - The retry policy is now documented: 3 attempts, 5-second timeout, no delivery log or replay.
- The
scan.whatsapppayload for QR-linked numbers is now documented. See Webhook events.
Message status
- Delivered and read receipts are not tracked. A message’s
statusis onlyreceivedorsent.
Errors and authentication
- The error
Workspace access denieddoes not exist. The real messages areforbidden,workspace required (X-Tenant-ID)andAPI key belongs to a different workspace. - The status list now includes
413and503, and429applies only to the sign-in and email endpoints. See Errors and limits. - Changed:
POST /api/whatsapp/connectandPOST /api/whatsapp/disconnect(linking or unlinking the QR-linked number) are now Console only: an owner or admin signed in to the app. API keys get403withAPI keys cannot administer workspaces. POST /api/v1/knowledge-ai/answerandPOST /api/v1/assistantneed a write key (or a session); areadkey getsAPI key is read-only.
Responses
GET /api/whatsapp/qrreturns{code, image, pending}, not{qr, qr_pending, connected}.POST /api/conversations/{id}/readreturns the conversation object, not{id, unread_count}.- Members include
user_id. Useuser_id(not the membershipid) asassignee_id. GET /api/healthreturns aservicesmap and503withstatus: "degraded"when a dependency is down.
Newly documented
- Limits: conversation list capped at 30; contacts, templates and knowledge lists capped at 500; message
limitabove 100 falls back to 50; at most 10 webhooks; template sync imports Meta’s first page only. - Message media download paths (
media_url). See List messages. - Sign-in endpoints and their rate limits are listed in Authentication and Errors and limits.