WASync · Developers
API ReferenceWebhook

Rotate the webhook signing secret

Issues a new signing secret and invalidates the old one immediately — there is no overlap window. Deploy the new secret to your receiver promptly; the retry policy (3 attempts with exponential backoff) covers a rollout measured in seconds, not hours. Signature scheme (unchanged): every delivery carries `X-WASync-Signature: sha256=<hex>` = HMAC-SHA256 of `${X-WASync-Timestamp}.${rawBody}` keyed with this secret. `X-WASync-Timestamp` is epoch milliseconds; reject anything older than 5 minutes. Verify over the RAW body, before parsing. Full contract: https://developers.wasync.app/docs/webhooks

POST
/webhook/rotate

Issues a new signing secret and invalidates the old one immediately — there is no overlap window. Deploy the new secret to your receiver promptly; the retry policy (3 attempts with exponential backoff) covers a rollout measured in seconds, not hours.

Signature scheme (unchanged): every delivery carries X-WASync-Signature: sha256=<hex> = HMAC-SHA256 of ${X-WASync-Timestamp}.${rawBody} keyed with this secret. X-WASync-Timestamp is epoch milliseconds; reject anything older than 5 minutes. Verify over the RAW body, before parsing. Full contract: https://developers.wasync.app/docs/webhooks

AuthorizationBearer <token>

The default way to authenticate. Create a key at https://developers.wasync.app/keys and send it as Authorization: Bearer wsk_live_….

The key is shown once at creation and stored only as a hash — lose it and you revoke it and create another. Each key carries its own scopes (whatsapp.read, whatsapp.send, whatsapp.events, whatsapp.manage) and an optional IP allowlist.

Errors: an unknown or revoked key returns 401 invalid_key; a key whose IP allowlist does not cover the calling address returns 403 ip_not_allowed (a distinct code on purpose — the key is fine, the address is not). Both carry a WWW-Authenticate: Bearer challenge. Scopes and the connection list are resolved live on every request, so revoking a key or narrowing it takes effect on the next call.

In: header

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/webhook/rotate"
{  "secret": "whsec_7c21…"}