The developer API and webhooks

7 min read

The API lets your own systems send WhatsApp messages and read what is happening in your workspace. Webhooks are the other direction: Pingly calls you when something changes.

The Developer API screen in Pingly settings, showing API key management and a link to the API documentation.
Settings, Developer API: where keys are created.

Getting a key

  1. Open Settings and then Developer API
    Admins only.
  2. Create a key and copy it immediately
    It is shown once. If you lose it, revoke it and make another — that is safer than any way of recovering it would be.
  3. Store it where secrets go
    An environment variable or a secret manager. Not in your source code, and not in a shared document.

Using it

The screen calls this the WhatsApp Direct API, and that is the honest description: it is for sending and receiving messages through numbers connected by QR code. The Quick Start on the page gives you working curl commands with your own base URL already filled in. What it covers:

EndpointWhat it does
POST /api/v1/messagesSend a text message, or one with an image or document.
GET /api/v1/accountsList your connected numbers and their state.
POST /api/v1/validateCheck whether a number is on WhatsApp before you send.
POST /api/v1/connectConnect a number, with a QR endpoint to scan.
/api/v1/webhooksCreate, list, update and delete webhooks.

The full reference, with every parameter, is at /api/v1/docs on your Pingly domain, generated from the running API — so it is accurate for the version you are calling.

Webhooks

Under Settings → Webhooks, give a URL and choose which events should reach it. Pingly posts JSON to that URL when they happen.

Do thisBecause
Answer 200 quickly, then do the workA slow endpoint causes retries, and you will process the same event twice.
Handle duplicatesRetries are normal. Make your handler safe to run twice on the same event.
Verify it came from PinglyThe endpoint is public. Check the signature before trusting the payload.
Keep one webhook per purposeSeveral webhooks pointing at the same URL deliver the same event several times — an easy thing to add by accident and a confusing one to debug.

More in Administration