Skip to content
Beta — the Waasl API is in private beta. Endpoints marked Coming soon are designed but not live yet. Request early access

Authentication

Every request authenticates with a secret API key sent as a bearer token:

GET /v1/me HTTP/1.1
Host: api.waasl.io
Authorization: Bearer wsl_live_your_key_here

Requests without a valid key fail with 401 unauthorized. All traffic must use HTTPS; plain HTTP is refused.

Prefix Environment Base URL Sends real messages
wsl_live_ Production https://api.waasl.io/v1 Yes
wsl_test_ Sandbox https://stage.api.waasl.io/v1 No — deliveries are simulated

A key only works in its own environment. Test-mode data is kept separate from live data.

Workspace owners and admins create keys in the Waasl app under Settings → Developers → API keys. The full key is shown once; Waasl stores only a hash. Give each integration its own key so you can revoke one without breaking the others.

Restrict a key to what the integration needs. A request outside the key’s scopes fails with 403 insufficient_scope.

Scope Grants
contacts:read / contacts:write Contacts, tags, custom fields, stages
conversations:read / conversations:write List, assign, close, reopen, notes
messages:read / messages:write Read and send messages, upload media
templates:read / templates:write WhatsApp templates
automation:write Publish/pause and trigger workflows
broadcasts:write Create and cancel broadcasts
webhooks:manage Webhook endpoints
analytics:read Analytics and usage
  1. Create a new key with the same scopes.
  2. Deploy it to your integration.
  3. Revoke the old key in Settings → Developers. Revocation is immediate.

Waasl emails workspace owners when a key hasn’t been used for 90 days, and when a key appears to have leaked in a public GitHub repository.

API access is part of the Growth and Enterprise plans. During the beta it can be enabled for any workspace on request.