API Setup
Configure API tokens and integrate with Whatify API
Set up and manage API tokens to integrate Whatify with your applications.
Overview
The API Settings page allows you to:
- Create and manage API tokens
- Link tokens to specific WhatsApp devices
- Set token expiration dates
- Monitor token usage
- Revoke tokens when needed
Accessing API Settings
- Navigate to Settings → API
- View your API tokens and create new ones
Creating API Tokens
Create Your First Token
- Click Create New Token
- Fill in token details:
- Token Name: Descriptive name (e.g., "Production App", "Mobile App")
- Description: Optional description of token usage
- Linked Device: Optional - select a specific WhatsApp device
- Expiration: Optional - set an expiration date
- Click Create Token
- Important: Copy the token immediately - it won't be shown again!
Token Information
Each token has:
- Name: Your chosen name
- Token: The actual API key (shown only once)
- Created: Creation date
- Last Used: Last time the token was used
- Expires: Expiration date (if set)
- Status: Active or Revoked
- Linked Device: Associated WhatsApp device (if any)
Device Linking
Link tokens to specific WhatsApp devices for better control.
Why Link Devices?
- Security: Restrict token to specific device
- Organization: Separate tokens for different devices
- Tracking: Know which device handles which requests
- Control: Better management of multiple devices
Linking a Token to Device
When Creating Token:
- Select device from dropdown during token creation
- Token will only work with that device
After Creation:
- Find the token in the list
- Click Edit
- Select device from dropdown
- Click Save
Unlinking a Device
- Edit the token
- Select "No Device" or remove device selection
- Save changes
Token will now use default or available devices.
Token Security
Best Practices
- Keep Tokens Secret: Never share tokens publicly
- Use Environment Variables: Store tokens securely
- Rotate Tokens: Regularly create new tokens and revoke old ones
- Set Expiration: Use expiration dates for temporary access
- Monitor Usage: Check "Last Used" to detect unauthorized use
Storing Tokens Securely
In Application Code:
# .env file
WHATIFY_API_TOKEN=your_token_here
WHATIFY_BASE_URL=https://whatify.dev// In your code
const apiToken = process.env.WHATIFY_API_TOKEN;Never commit tokens to git:
# .gitignore
.env
.env.local
.env.productionToken Permissions
All tokens have access to:
- Connect/disconnect WhatsApp
- Check connection status
- Send messages
- View message history
Tokens inherit organization permissions.
Managing Tokens
Viewing Token Details
Click on any token to view:
- Full token details
- Usage statistics
- Associated device
- Creation and expiration dates
- Recent activity
Editing Tokens
Modify token settings:
- Click Edit on the token
- Update:
- Token name
- Description
- Linked device
- Expiration date
- Click Save
Note: You cannot change the actual token string.
Revoking Tokens
Immediately disable a token:
- Find the token in the list
- Click Revoke
- Confirm revocation
Revoked tokens:
- Cannot be reactivated
- Stop working immediately
- Remain in the list for tracking
- Can be permanently deleted
Deleting Tokens
Permanently remove a token:
- Revoke the token first
- Click Delete
- Confirm deletion
Warning: This action cannot be undone.
Using API Tokens
Authentication Methods
Bearer Token (Recommended):
curl -X GET "https://whatify.dev/api/whatsapp/v1/status" \
-H "Authorization: Bearer YOUR_API_TOKEN"Query Parameter:
curl -X GET "https://whatify.dev/api/whatsapp/v1/status?token=YOUR_API_TOKEN"Using the Whatify SDK
Install the SDK:
npm install whatify-whatsapp-clientInitialize with your token:
import { Whatify } from "whatify-whatsapp-client";
const client = new Whatify({
apiToken: process.env.WHATIFY_API_TOKEN!,
});
// Use the client
const status = await client.status();Testing Your Token
Test your token with cURL:
curl -X GET "https://whatify.dev/api/whatsapp/v1/status" \
-H "Authorization: Bearer YOUR_TOKEN"Expected response:
{
"success": true,
"status": "connected",
"phone": "1234567890"
}Token Usage Monitoring
Viewing Usage Statistics
Monitor token usage:
- Go to Settings → API
- Click on a token to view details
- See usage statistics:
- Total requests
- Last used date/time
- Request volume over time
- Endpoint usage breakdown
Usage Alerts
Set up alerts for:
- High request volume
- Unusual activity
- Approaching rate limits
- Token expiration
Rate Limits
API tokens are subject to rate limits:
| Endpoint | Limit | Window |
|---|---|---|
/connect | 15 requests | 1 minute |
/disconnect | 5 requests | 1 minute |
/status | 20 requests | 1 minute |
/send | 30 requests | 1 minute |
Handling Rate Limits
When rate limited, you'll receive:
{
"success": false,
"error": "Rate limit exceeded",
"resetIn": 45
}Wait for resetIn seconds before retrying.
Multiple Devices
Manage multiple WhatsApp devices with separate tokens.
Setup Multiple Devices
- Connect multiple WhatsApp devices:
- Go to Settings → WhatsApp
- Connect each device separately
- Create tokens for each device:
- Create token and link to Device 1
- Create another token and link to Device 2
- Use appropriate token in your applications
Use Cases
- Staging vs Production: Different devices for testing
- Department Separation: Sales, Support, Marketing each have own device
- Geographic Distribution: Different regions use different numbers
- Load Balancing: Distribute message load across devices
API Documentation
Access comprehensive API documentation:
- API Reference - Complete endpoint documentation
- Manual Testing - Test endpoints with cURL
- Examples - Code examples and use cases
Troubleshooting
Token Not Working
Check:
- Token is active (not revoked)
- Token hasn't expired
- Token is copied correctly (no extra spaces)
- Using correct authentication method
- API endpoint URL is correct
Unauthorized Errors
{
"success": false,
"error": "Invalid API token"
}Solutions:
- Verify token is correct
- Check if token was revoked
- Ensure token hasn't expired
- Confirm you're using the right token
Device Not Found
{
"success": false,
"error": "No connected WhatsApp device found"
}Solutions:
- Check if linked device is connected
- Remove device link to use any available device
- Connect the specific device
- Check device status in WhatsApp settings
Rate Limit Errors
Solutions:
- Implement exponential backoff
- Reduce request frequency
- Distribute requests across multiple tokens
- Contact support for higher limits
Security Recommendations
Token Hygiene
- Rotate Regularly: Create new tokens every 3-6 months
- Remove Unused: Delete tokens you no longer use
- Monitor Activity: Check "Last Used" regularly
- Set Expiration: Use expiration dates when possible
Access Control
- Least Privilege: Only create tokens when needed
- Separate Concerns: Different tokens for different apps
- Team Management: Track which team member uses which token
- Audit Trail: Review token usage logs
Incident Response
If a token is compromised:
- Revoke Immediately: Disable the compromised token
- Check Usage: Review recent activity
- Create New Token: Generate replacement token
- Update Applications: Deploy new token to apps
- Monitor: Watch for suspicious activity
Integration Examples
Node.js Application
import { Whatify } from "whatify-whatsapp-client";
import express from "express";
const app = express();
const client = new Whatify({
apiToken: process.env.WHATIFY_API_TOKEN!,
});
app.post("/send-message", async (req, res) => {
const { to, text } = req.body;
const result = await client.send({ to, text });
res.json(result);
});
app.listen(3000);Python Application
import requests
import os
API_TOKEN = os.getenv('WHATIFY_API_TOKEN')
BASE_URL = 'https://whatify.dev'
headers = {
'Authorization': f'Bearer {API_TOKEN}',
'Content-Type': 'application/json'
}
response = requests.post(
f'{BASE_URL}/api/whatsapp/v1/send',
headers=headers,
json={'to': '1234567890', 'text': 'Hello!'}
)
print(response.json())Next Steps
- API Reference - Explore all API endpoints
- Manual Testing - Test your tokens
- Examples - See code examples
- WhatsApp Connection - Connect devices