Rotate the webhook signing secret
Issues a new signing secret and invalidates the old one immediately — there is no overlap window. Deploy the new secret to your receiver promptly; the retry policy (3 attempts with exponential backoff) covers a rollout measured in seconds, not hours. Signature scheme (unchanged): every delivery carries `X-WASync-Signature: sha256=<hex>` = HMAC-SHA256 of `${X-WASync-Timestamp}.${rawBody}` keyed with this secret. `X-WASync-Timestamp` is epoch milliseconds; reject anything older than 5 minutes. Verify over the RAW body, before parsing. Full contract: https://developers.wasync.app/docs/webhooks
Issues a new signing secret and invalidates the old one immediately — there is no overlap window. Deploy the new secret to your receiver promptly; the retry policy (3 attempts with exponential backoff) covers a rollout measured in seconds, not hours.
Signature scheme (unchanged): every delivery carries X-WASync-Signature: sha256=<hex> = HMAC-SHA256 of ${X-WASync-Timestamp}.${rawBody} keyed with this secret. X-WASync-Timestamp is epoch milliseconds; reject anything older than 5 minutes. Verify over the RAW body, before parsing. Full contract: https://developers.wasync.app/docs/webhooks
The default way to authenticate. Create a key at https://developers.wasync.app/keys and send it as Authorization: Bearer wsk_live_….
The key is shown once at creation and stored only as a hash — lose it and you revoke it and create another. Each key carries its own scopes (whatsapp.read, whatsapp.send, whatsapp.events, whatsapp.manage) and an optional IP allowlist.
Errors: an unknown or revoked key returns 401 invalid_key; a key whose IP allowlist does not cover the calling address returns 403 ip_not_allowed (a distinct code on purpose — the key is fine, the address is not). Both carry a WWW-Authenticate: Bearer challenge. Scopes and the connection list are resolved live on every request, so revoking a key or narrowing it takes effect on the next call.
In: header
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/webhook/rotate"{ "secret": "whsec_7c21…"}Set the webhook endpoint PUT
Points WASync at your URL and returns the signing secret for it. Idempotent — calling it again with a different URL moves the endpoint. The URL must be HTTPS on a publicly reachable host; http, localhost and private ranges are rejected with 400 `invalid_webhook`. Signature scheme (unchanged): every delivery carries `X-WASync-Signature: sha256=<hex>` = HMAC-SHA256 of `${X-WASync-Timestamp}.${rawBody}` keyed with this secret. `X-WASync-Timestamp` is epoch milliseconds; reject anything older than 5 minutes. Verify over the RAW body, before parsing. Full contract: https://developers.wasync.app/docs/webhooks
Security
How keys are stored, how to pin them to addresses, and how fast a revocation takes effect.