Authentication
Every request authenticates with a secret API key sent as a bearer token:
GET /v1/me HTTP/1.1Host: api.waasl.ioAuthorization: Bearer wsl_live_your_key_hereRequests without a valid key fail with 401 unauthorized. All traffic must use HTTPS; plain HTTP is refused.
Live and test keys
Section titled “Live and test keys”| Prefix | Environment | Base URL | Sends real messages |
|---|---|---|---|
wsl_live_ |
Production | https://api.waasl.io/v1 |
Yes |
wsl_test_ |
Sandbox | https://stage.api.waasl.io/v1 |
No — deliveries are simulated |
A key only works in its own environment. Test-mode data is kept separate from live data.
Creating keys
Section titled “Creating keys”Workspace owners and admins create keys in the Waasl app under Settings → Developers → API keys. The full key is shown once; Waasl stores only a hash. Give each integration its own key so you can revoke one without breaking the others.
Scopes Beta
Section titled “Scopes ”Restrict a key to what the integration needs. A request outside the key’s scopes fails with 403 insufficient_scope.
| Scope | Grants |
|---|---|
contacts:read / contacts:write |
Contacts, tags, custom fields, stages |
conversations:read / conversations:write |
List, assign, close, reopen, notes |
messages:read / messages:write |
Read and send messages, upload media |
templates:read / templates:write |
WhatsApp templates |
automation:write |
Publish/pause and trigger workflows |
broadcasts:write |
Create and cancel broadcasts |
webhooks:manage |
Webhook endpoints |
analytics:read |
Analytics and usage |
Rotating keys
Section titled “Rotating keys”- Create a new key with the same scopes.
- Deploy it to your integration.
- Revoke the old key in Settings → Developers. Revocation is immediate.
Waasl emails workspace owners when a key hasn’t been used for 90 days, and when a key appears to have leaked in a public GitHub repository.
API access is part of the Growth and Enterprise plans. During the beta it can be enabled for any workspace on request.