WhatsAppDev API
Send WhatsApp messages from your applications, manage connected sessions, track message delivery and receive real-time webhook notifications.
https://whatsappdev.top/v1
Authentication
Every API request must include your API key using the Bearer authentication scheme.
Authorization: Bearer wapi_live_YOUR_API_KEY
wapi_live_... value immediately: it is shown only once.
The key prefix and key_... ID in the table cannot
authenticate API requests. If you lost the full key, create a new
one and revoke the old one. Replace wapi_live_YOUR_API_KEY
in these examples with your complete key.
Keep API keys on your server and never expose
them in browser JavaScript.
List WhatsApp Sessions
GET /v1/sessions
Returns the WhatsApp accounts connected to your account.
curl -X GET \
'https://whatsappdev.top/v1/sessions' \
-H 'Authorization: Bearer wapi_live_YOUR_API_KEY' \
-H 'Accept: application/json'
Response
{
"success": true,
"data": [
{
"session": "ses_8bf81995f22c197daec42138",
"name": "My WhatsApp",
"phone": "+254771367662",
"status": "WORKING",
"connected": true,
"last_active_at": "2026-10-08 12:20:00"
}
]
}
Get WhatsApp Session
GET /v1/sessions/{session}
Replace {session} with the Public Key
from your Sessions table,
for example ses_8bf81995f22c197daec42138.
You can also get it from the session field in
GET /v1/sessions. It is a public identifier, not your
secret API key. Use a session owned by the same account as your API key.
curl -X GET \
'https://whatsappdev.top/v1/sessions/ses_8bf81995f22c197daec42138' \
-H 'Authorization: Bearer wapi_live_YOUR_API_KEY'
Send Text Message
POST /v1/messages/text
| Field | Required | Description |
|---|---|---|
session
|
Yes |
Copy the Public Key (ses_...)
from Sessions,
or use the session value from
GET /v1/sessions. Connect the session by
scanning its QR code first; its status must be
WORKING. Use the public key, not the internal
session name, phone number, or numeric database ID.
|
to
|
Yes |
The recipient's WhatsApp phone number, supplied by
your application. International numbers should include
the country code, for example 254771367662.
Kenyan local numbers such as 0771367662
or 771367662 are converted to
254771367662. Other countries should use
international format (10 to 15 digits). A leading
+, spaces, and punctuation are removed.
|
message
|
Yes |
Your message content as a non-empty JSON string
of at most 4,096 characters.
Supply the text from your application; no portal ID
is needed for this field. Send the request with
Content-Type: application/json.
|
curl -X POST \
'https://whatsappdev.top/v1/messages/text' \
-H 'Authorization: Bearer wapi_live_YOUR_API_KEY' \
-H 'Content-Type: application/json' \
-d '{
"session": "ses_8bf81995f22c197daec42138",
"to": "0771367662",
"message": "Your verification code is 482193"
}'
Response
{
"success": true,
"data": {
"message_id": "msg_e8992052937f46dc8c4fb730",
"status": "QUEUED",
"session": "ses_8bf81995f22c197daec42138",
"to": "254771367662"
}
}
Get Message Status
GET /v1/messages/{message_id}
curl -X GET \
'https://whatsappdev.top/v1/messages/msg_e8992052937f46dc8c4fb730' \
-H 'Authorization: Bearer wapi_live_YOUR_API_KEY'
Replace {message_id} with the data.message_id
returned when you send a message (the msg_... value).
Save it in your application to track delivery. You can also find
it in Messages and its
details page. Use an API key from the account that sent the message.
{
"success": true,
"data": {
"message_id": "msg_e8992052937f46dc8c4fb730",
"type": "text",
"to": "254771367662",
"status": "DELIVERED",
"session": {
"id": 42,
"name": "My WhatsApp",
"phone": "+254771367662"
},
"attempts": {
"current": 1,
"maximum": 4
},
"error": null
}
}
Webhooks
Instead of repeatedly requesting message status, you can register a webhook endpoint in your developer dashboard.
| Event | Description |
|---|---|
message.sent
|
Message accepted for WhatsApp delivery. |
message.delivered
|
Message reached the recipient device. |
message.read
|
Recipient read the message. |
message.failed
|
Message delivery permanently failed. |
message.received
|
An incoming WhatsApp message was received. |
Example webhook
{
"id": "evt_07124ad9f9ef71f97bc0b325",
"event": "message.delivered",
"created_at": "2026-10-08T09:12:30Z",
"data": {
"message_id": "msg_e8992052937f46dc8c4fb730",
"session": "ses_8bf81995f22c197daec42138",
"to": "254771367662",
"status": "DELIVERED"
}
}
Verify Webhook Signatures
WhatsAppDev signs webhook requests using your webhook signing secret.
The following headers are sent:
X-Webhook-Id: evt_07124ad9f9ef71f97bc0b325
X-Webhook-Event: message.delivered
X-Webhook-Timestamp: 1791444300
X-Webhook-Signature: sha256=...
PHP verification example
Create an endpoint in Webhooks
and copy the signing secret shown after creation. Use that
whsec_... secret below, not your API key or session
public key. Keep it on your server and verify the signature
against the unmodified request body.
$secret = 'whsec_YOUR_WEBHOOK_SECRET';
$timestamp =
$_SERVER['HTTP_X_WEBHOOK_TIMESTAMP'] ?? '';
$signature =
$_SERVER['HTTP_X_WEBHOOK_SIGNATURE'] ?? '';
$body =
file_get_contents('php://input');
$expected =
'sha256=' . hash_hmac(
'sha256',
$timestamp . '.' . $body,
$secret
);
if (!hash_equals($expected, $signature)) {
http_response_code(401);
exit('Invalid signature');
}
$data = json_decode($body, true);
http_response_code(200);
echo 'OK';
Message Statuses
| Status | Meaning |
|---|---|
| QUEUED | Accepted and waiting for a delivery worker. |
| PROCESSING | A delivery worker is processing the message. |
| RETRY | Temporary failure. Delivery will be retried. |
| SENT | Message was sent to WhatsApp. |
| DELIVERED | Message reached the recipient device. |
| READ | Message was read by the recipient. |
| FAILED | Message could not be delivered after retries. |
Error Responses
401 Unauthorized
{
"success": false,
"error": {
"code": "UNAUTHORIZED",
"message": "Invalid or missing API key."
}
}
404 Session Not Found
{
"success": false,
"error": {
"code": "SESSION_NOT_FOUND",
"message": "WhatsApp session not found."
}
}
409 Session Not Connected
{
"success": false,
"error": {
"code": "SESSION_NOT_CONNECTED",
"message": "The WhatsApp session is not connected."
}
}
422 Validation Error
{
"success": false,
"error": {
"code": "VALIDATION_ERROR",
"message": "The request contains invalid data.",
"fields": {
"to": "A valid phone number is required."
}
}
}