API documentation
Base URL: https://whatsapbox.com
Authentication
Send your personal API token in the HTTP Authorization header. Tokens can be created after signing in under account API tokens.
Authorization: Bearer YOUR_API_TOKEN Accept: application/json Content-Type: application/json
The legacy token request field is supported for compatibility, but Bearer authentication is recommended because it avoids credentials appearing in URLs and application logs.
Errors and limits
Public API routes are limited to 60 requests per minute. Messaging requests can also return 402 when a messaging subscription is required, 422 for consent or customer-service-window restrictions, and 429 for plan limits.
{
"status": "error",
"message": "Contact has not opted in or has opted out of WhatsApp messaging."
}Outbound order webhooks
Configure an HTTPS order webhook URL and signing secret in the authenticated Integrations area. Events contain event, order, customer, and items. Verify the hexadecimal X-Wpbox-Signature header using HMAC-SHA256 over the raw request body.
<?php
$expected = hash_hmac('sha256', $rawRequestBody, $webhookSecret);
$valid = hash_equals($expected, $_SERVER['HTTP_X_WPBOX_SIGNATURE'] ?? '');Messages
POSTSend a text message
/api/wpbox/sendmessage
Send a free-form message inside the open 24-hour customer-service window.
curl -X POST 'https://whatsapbox.com/api/wpbox/sendmessage' \
-H 'Authorization: Bearer YOUR_API_TOKEN' \
-H 'Accept: application/json' \
-H 'Content-Type: application/json' \
--data '{"phone":"+254700000000","message":"Hello from WhatsAppBox"}'
Example response{
"status": "success",
"message_id": 123,
"message_wamid": "wamid.example"
}
POSTSend a template message
/api/wpbox/sendtemplatemessage
Send an approved template to an opted-in contact.
curl -X POST 'https://whatsapbox.com/api/wpbox/sendtemplatemessage' \
-H 'Authorization: Bearer YOUR_API_TOKEN' \
-H 'Accept: application/json' \
-H 'Content-Type: application/json' \
--data '{"phone":"+254700000000","template_name":"order_update","template_language":"en","components":[]}'
Example response{
"status": "success",
"message_id": 124,
"message_wamid": "wamid.example"
}
Commerce
POSTSend a catalogue product
/api/wpbox/sendcatalogproduct
Send one active catalogue product by internal product ID or retailer ID.
curl -X POST 'https://whatsapbox.com/api/wpbox/sendcatalogproduct' \
-H 'Authorization: Bearer YOUR_API_TOKEN' \
-H 'Accept: application/json' \
-H 'Content-Type: application/json' \
--data '{"phone":"+254700000000","retailer_id":"SKU-100","body":"View this product","footer":"Reply for help"}'
Example response{
"status": "success",
"message_id": 125,
"message_wamid": "wamid.example"
}
POSTSend a product list
/api/wpbox/sendcatalogproducts
Send up to 30 active catalogue products.
curl -X POST 'https://whatsapbox.com/api/wpbox/sendcatalogproducts' \
-H 'Authorization: Bearer YOUR_API_TOKEN' \
-H 'Accept: application/json' \
-H 'Content-Type: application/json' \
--data '{"phone":"+254700000000","retailer_ids":["SKU-100","SKU-101"],"body":"Choose a product"}'
Example response{
"status": "success",
"message_id": 126,
"message_wamid": "wamid.example"
}
GETList catalogue products
/api/wpbox/getCatalogProducts
Return the authenticated company’s catalogue products.
curl -X GET 'https://whatsapbox.com/api/wpbox/getCatalogProducts' \ -H 'Authorization: Bearer YOUR_API_TOKEN' \ -H 'Accept: application/json'Example response
{
"status": "success",
"data": []
}
POSTCreate an order
/api/wpbox/createOrder
Create an order from active products identified by product IDs or retailer IDs.
curl -X POST 'https://whatsapbox.com/api/wpbox/createOrder' \
-H 'Authorization: Bearer YOUR_API_TOKEN' \
-H 'Accept: application/json' \
-H 'Content-Type: application/json' \
--data '{"phone":"+254700000000","retailer_ids":["SKU-100"],"delivery_address":"Nairobi","notes":"Call on arrival","send_confirmation":false}'
Example response{
"status": "success",
"order": {
"id": 88,
"order_number": "ORD-EXAMPLE"
}
}
GETList orders
/api/wpbox/getOrders
Return up to 100 recent orders. Optionally filter by status.
curl -X GET 'https://whatsapbox.com/api/wpbox/getOrders?status=pending' \ -H 'Authorization: Bearer YOUR_API_TOKEN' \ -H 'Accept: application/json'Example response
{
"status": "success",
"data": []
}
Resources
GETList templates
/api/wpbox/getTemplates
Return templates belonging to the authenticated company.
curl -X GET 'https://whatsapbox.com/api/wpbox/getTemplates' \ -H 'Authorization: Bearer YOUR_API_TOKEN' \ -H 'Accept: application/json'Example response
{
"status": "success",
"templates": []
}
GETList contact groups
/api/wpbox/getGroups
Return contact groups. Add showContacts=yes to include group contacts.
curl -X GET 'https://whatsapbox.com/api/wpbox/getGroups?showContacts=yes' \ -H 'Authorization: Bearer YOUR_API_TOKEN' \ -H 'Accept: application/json'Example response
{
"status": "success",
"groups": []
}
GETList contacts
/api/wpbox/getContacts
Return contacts belonging to the authenticated company.
curl -X GET 'https://whatsapbox.com/api/wpbox/getContacts' \ -H 'Authorization: Bearer YOUR_API_TOKEN' \ -H 'Accept: application/json'Example response
{
"status": "success",
"contacts": []
}
Contacts
POSTCreate or update a contact
/api/wpbox/makeContact
Create a contact when the phone number is new and optionally attach groups or custom fields.
curl -X POST 'https://whatsapbox.com/api/wpbox/makeContact' \
-H 'Authorization: Bearer YOUR_API_TOKEN' \
-H 'Accept: application/json' \
-H 'Content-Type: application/json' \
--data '{"phone":"+254700000000","groups":[1],"custom":{"2":"Nairobi"}}'
Example response{
"status": "success",
"contact": {
"id": 42,
"phone": "+254700000000"
}
}