API documentation

Base URL: https://whatsapbox.com

Authentication

Send your personal API token in the HTTP Authorization header. Tokens can be created after signing in under account API tokens.

Authorization: Bearer YOUR_API_TOKEN
Accept: application/json
Content-Type: application/json

The legacy token request field is supported for compatibility, but Bearer authentication is recommended because it avoids credentials appearing in URLs and application logs.

Errors and limits

Public API routes are limited to 60 requests per minute. Messaging requests can also return 402 when a messaging subscription is required, 422 for consent or customer-service-window restrictions, and 429 for plan limits.

{
  "status": "error",
  "message": "Contact has not opted in or has opted out of WhatsApp messaging."
}

Outbound order webhooks

Configure an HTTPS order webhook URL and signing secret in the authenticated Integrations area. Events contain event, order, customer, and items. Verify the hexadecimal X-Wpbox-Signature header using HMAC-SHA256 over the raw request body.

<?php
$expected = hash_hmac('sha256', $rawRequestBody, $webhookSecret);
$valid = hash_equals($expected, $_SERVER['HTTP_X_WPBOX_SIGNATURE'] ?? '');

Messages

POSTSend a text message

/api/wpbox/sendmessage

Send a free-form message inside the open 24-hour customer-service window.

curl -X POST 'https://whatsapbox.com/api/wpbox/sendmessage' \
  -H 'Authorization: Bearer YOUR_API_TOKEN' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  --data '{"phone":"+254700000000","message":"Hello from WhatsAppBox"}'
Example response
{
    "status": "success",
    "message_id": 123,
    "message_wamid": "wamid.example"
}

POSTSend a template message

/api/wpbox/sendtemplatemessage

Send an approved template to an opted-in contact.

curl -X POST 'https://whatsapbox.com/api/wpbox/sendtemplatemessage' \
  -H 'Authorization: Bearer YOUR_API_TOKEN' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  --data '{"phone":"+254700000000","template_name":"order_update","template_language":"en","components":[]}'
Example response
{
    "status": "success",
    "message_id": 124,
    "message_wamid": "wamid.example"
}

Commerce

POSTSend a catalogue product

/api/wpbox/sendcatalogproduct

Send one active catalogue product by internal product ID or retailer ID.

curl -X POST 'https://whatsapbox.com/api/wpbox/sendcatalogproduct' \
  -H 'Authorization: Bearer YOUR_API_TOKEN' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  --data '{"phone":"+254700000000","retailer_id":"SKU-100","body":"View this product","footer":"Reply for help"}'
Example response
{
    "status": "success",
    "message_id": 125,
    "message_wamid": "wamid.example"
}

POSTSend a product list

/api/wpbox/sendcatalogproducts

Send up to 30 active catalogue products.

curl -X POST 'https://whatsapbox.com/api/wpbox/sendcatalogproducts' \
  -H 'Authorization: Bearer YOUR_API_TOKEN' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  --data '{"phone":"+254700000000","retailer_ids":["SKU-100","SKU-101"],"body":"Choose a product"}'
Example response
{
    "status": "success",
    "message_id": 126,
    "message_wamid": "wamid.example"
}

GETList catalogue products

/api/wpbox/getCatalogProducts

Return the authenticated company’s catalogue products.

curl -X GET 'https://whatsapbox.com/api/wpbox/getCatalogProducts' \
  -H 'Authorization: Bearer YOUR_API_TOKEN' \
  -H 'Accept: application/json'
Example response
{
    "status": "success",
    "data": []
}

POSTCreate an order

/api/wpbox/createOrder

Create an order from active products identified by product IDs or retailer IDs.

curl -X POST 'https://whatsapbox.com/api/wpbox/createOrder' \
  -H 'Authorization: Bearer YOUR_API_TOKEN' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  --data '{"phone":"+254700000000","retailer_ids":["SKU-100"],"delivery_address":"Nairobi","notes":"Call on arrival","send_confirmation":false}'
Example response
{
    "status": "success",
    "order": {
        "id": 88,
        "order_number": "ORD-EXAMPLE"
    }
}

GETList orders

/api/wpbox/getOrders

Return up to 100 recent orders. Optionally filter by status.

curl -X GET 'https://whatsapbox.com/api/wpbox/getOrders?status=pending' \
  -H 'Authorization: Bearer YOUR_API_TOKEN' \
  -H 'Accept: application/json'
Example response
{
    "status": "success",
    "data": []
}

Resources

GETList templates

/api/wpbox/getTemplates

Return templates belonging to the authenticated company.

curl -X GET 'https://whatsapbox.com/api/wpbox/getTemplates' \
  -H 'Authorization: Bearer YOUR_API_TOKEN' \
  -H 'Accept: application/json'
Example response
{
    "status": "success",
    "templates": []
}

GETList contact groups

/api/wpbox/getGroups

Return contact groups. Add showContacts=yes to include group contacts.

curl -X GET 'https://whatsapbox.com/api/wpbox/getGroups?showContacts=yes' \
  -H 'Authorization: Bearer YOUR_API_TOKEN' \
  -H 'Accept: application/json'
Example response
{
    "status": "success",
    "groups": []
}

GETList contacts

/api/wpbox/getContacts

Return contacts belonging to the authenticated company.

curl -X GET 'https://whatsapbox.com/api/wpbox/getContacts' \
  -H 'Authorization: Bearer YOUR_API_TOKEN' \
  -H 'Accept: application/json'
Example response
{
    "status": "success",
    "contacts": []
}

Contacts

POSTCreate or update a contact

/api/wpbox/makeContact

Create a contact when the phone number is new and optionally attach groups or custom fields.

curl -X POST 'https://whatsapbox.com/api/wpbox/makeContact' \
  -H 'Authorization: Bearer YOUR_API_TOKEN' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  --data '{"phone":"+254700000000","groups":[1],"custom":{"2":"Nairobi"}}'
Example response
{
    "status": "success",
    "contact": {
        "id": 42,
        "phone": "+254700000000"
    }
}