Idempotency
Networks fail. If a POST times out you can’t know whether Waasl received it — and retrying a send could message a customer twice. Send an Idempotency-Key header on every write:
curl -X POST https://api.waasl.io/v1/messages \ -H "Authorization: Bearer $WAASL_API_KEY" \ -H "Idempotency-Key: 6f1c9a2e-8b7d-4f3a-9e21-0c5d8b7a4e10" \ -H "Content-Type: application/json" \ -d '{ "to": "+96550001234", "kind": "template", "template": { "name": "order_ready", "language": "ar", "params": ["سارة", "4821"] } }'- Retrying with the same key and same body returns the original response — no second message.
- Reusing a key with a different body fails with
409 idempotency_conflict. - Keys are remembered for 24 hours. Use a UUID v4, or derive one from your own record (e.g.
order-4821-ready) so a crash-and-restart in your system is also safe. GETandDELETEare naturally idempotent and ignore the header.
For messages the key also becomes the message id lookup — Waasl already applies this inside the platform today.