WhatsApp API

Features

A messaging platform with the operational parts already built.

Isolation by design

Every customer is a tenant with its own WhatsApp sessions, API token, message history, webhook configuration and usage counters. Isolation is enforced in the data layer with query filters rather than in individual queries, so a missing condition cannot leak another customer's data.

Queue based delivery

The API accepts a message, writes it to a durable queue and returns. A background worker leases each WhatsApp session, drains its queue at a controlled pace, and retries failures with exponential backoff. Restarting the API or the worker never loses a queued message.

Real-time dashboard

QR codes, connection state and message status arrive over a websocket, so the panel reflects reality without a refresh button.

Credentials you can rotate

API tokens are cryptographically random, stored only as a hash, shown once, and can be regenerated or revoked instantly. The dashboard session and the messaging token are separate credentials with separate lifetimes.

Pluggable WhatsApp connector

The platform talks to WhatsApp through a single interface. A built-in simulator, a self-hosted QR connector and an official Business Platform integration can be swapped by configuration without changing the application.

Production deployments should use an authorised integration and follow WhatsApp and Meta messaging policies, including consent requirements.