Authentication
Everything viaAuthorization: Bearer <token>. There are two tokens, each with
its own scope:
Account token
Prefix
zpfy_acct_. Manages instances and webhooks (create, list, edit, delete).Instance token
Prefix
zpfy_inst_. Sends messages for a specific number.Getting the account token
In the dashboard, open API & Tokens → Account token and click generate new.Each endpoint shows which token to use in the Authorization selector of the
playground on the right. Messages use the instance token; instances and webhooks,
the account token.
Identifiers
Zapfy uses two identifiers:phoneis just the number. Use it to write to someone for the first time and to match people with the numbers in your system.idis the exact value Zapfy returns:chat.idandsender.idin webhooks, and theidfromGET /groups,GET /communitiesandGET /newsletters. It’s opaque — it may look like...@s.whatsapp.netor...@lid(a person),...@g.us(group/community) or...@newsletter(channel). Use it as received; don’t rebuild it or derive it from a phone.
When sending, the recipient goes in the
to field, which accepts a phone
or an id. To reply to an event, send to its chat.id. A send answers 202 with
{ messageId } and happens right after; the outcome arrives by webhook. Keep the
messageId to reuse in follow-up actions on the message (status, reaction, delete,
edit).