Skip to content

Developer overview

Wabot gives you four ways to build on top of your WhatsApp Business account. Choose the one that fits what you’re building:

REST API

Send template and session messages, manage templates, contacts and flows, and read conversations from your backend.

Webhooks

Get notified when a customer messages you, a message is delivered or read, or a template is approved.

Embed chat

Put the Wabot inbox inside your own CRM or admin panel. Your signed-in users don’t need a second login.

MCP server

Let AI agents such as Claude, Cursor or Codex create templates, send messages and read replies.

Service URL
REST API https://api.wabot.shop
MCP server https://api.wabot.shop/mcp
Embed chat https://app.wabot.shop/embed-chat
Inbound workflow webhooks https://wh.wabot.shop
  1. Get your credentials. In Wabot, open Developer → Developer Credentials and copy your Client ID and Client Secret.

  2. Exchange them for a token.

    Terminal window
    curl -X POST https://api.wabot.shop/v1/authenticate \
    -H "clientid: $WABOT_CLIENT_ID" \
    -H "clientsecret: $WABOT_CLIENT_SECRET"

    The response contains a token, valid for 1 hour, and a refreshToken, valid for 7 days.

  3. Call the API. Send the token in the Authorization header without a Bearer prefix:

    Terminal window
    curl https://api.wabot.shop/account/get -H "Authorization: $TOKEN"

    The response lists your connected phone numbers. Note the whatsappPhoneId, because you need it to send messages.

Version What it covers
Unversioned The original endpoints, kept stable: send template messages, templates, contacts, account, campaigns, flows
/v1 Authentication with refresh tokens, session (free-form) messages, creating workflows
/v2 Paginated read endpoints for contacts, conversations and templates, plus template sync

Each new version only adds endpoints, so existing integrations keep working.

Scope Limit
REST API 105 requests per minute
MCP server 60 requests per minute per Client ID
Embed session exchange 30 requests per minute per IP

When you go over a limit you get 429 Too Many Requests. Wait a minute and try again.