Skip to main content
The Zapfy API is REST over HTTPS. You send messages and manage instances and webhooks through a single surface — how it connects to WhatsApp stays abstracted. Base URL

Authentication

Everything via Authorization: Bearer <token>. There are two tokens, each with its own scope:

Account token

Prefix zpfy_acct_. Manages instances and webhooks (create, list, edit, delete).

Instance token

Prefix zpfy_inst_. Sends messages for a specific number.

Getting the account token

In the dashboard, open API & Tokens → Account token and click generate new.
The token is shown only once, at the moment it is generated — copy it and store it in a secret manager or environment variable. Generating a new token revokes the previous one immediately: every integration still using the old token starts receiving 401 until you update it.
Each endpoint shows which token to use in the Authorization selector of the playground on the right. Messages use the instance token; instances and webhooks, the account token.

Identifiers

Zapfy uses two identifiers:
  • phone is just the number. Use it to write to someone for the first time and to match people with the numbers in your system.
  • id is the exact value Zapfy returns: chat.id and sender.id in webhooks, and the id from GET /groups, GET /communities and GET /newsletters. It’s opaque — it may look like ...@s.whatsapp.net or ...@lid (a person), ...@g.us (group/community) or ...@newsletter (channel). Use it as received; don’t rebuild it or derive it from a phone.
When sending, the recipient goes in the to field, which accepts a phone or an id. To reply to an event, send to its chat.id. A send answers 202 with { messageId } and happens right after; the outcome arrives by webhook. Keep the messageId to reuse in follow-up actions on the message (status, reaction, delete, edit).

Webhooks

Inbound events (message received, status, connection) arrive at the webhooks you register — one URL, many events. See Configuration, Events and Handling events.