Volver a la ayuda Back to help
Vantis Uniasser

Documentación de la API REST REST API Documentation

Integra WA Manager con n8n, Zapier, Make o tu propio código Integrate WA Manager with n8n, Zapier, Make or your own code

Base URL:Base URL: https://tudominio.com/wa-api/api/v1
¿Qué puedes hacer con la API? What can you do with the API? Enviar mensajes de WhatsApp, leer conversaciones, consultar contactos y recibir mensajes en tiempo real mediante webhooks — todo desde tu CRM, n8n, Zapier, Make o código propio. Send WhatsApp messages, read conversations, query contacts, and receive messages in real time via webhooks — all from your CRM, n8n, Zapier, Make or custom code.
Paso 1 — Genera tu API Key
Step 1 — Generate your API Key
1

Abre el panel de API Keys en WA Manager

Open the API Keys panel in WA Manager

En la barra lateral de WA Manager, pulsa el icono de llave 🔑 (junto al icono de campana y de cierre de sesión).

In the WA Manager sidebar, click the key icon 🔑 (next to the bell and logout icons).

2

Crea una nueva clave

Create a new key

En la pestaña API Keys, escribe un nombre identificativo (ej: «n8n producción») y opcionalmente selecciona una cuenta de WhatsApp concreta si quieres restringir el acceso. Pulsa Crear API Key.

In the API Keys tab, enter a descriptive name (e.g. «n8n production») and optionally select a specific WhatsApp account to restrict access. Click Create API Key.

3

Guarda la clave — solo se muestra una vez

Save the key — shown only once

La clave completa aparece justo después de crearla. Cópiala y guárdala en un lugar seguro. No se puede recuperar después.

The full key appears right after creation. Copy and save it somewhere safe. It cannot be retrieved later.

wam_a1b2c3d4e5f6789012345678901234567890abcdef1234567890abcdef12345678
Paso 2 — Autenticación
Step 2 — Authentication

Incluye la API key en todas las peticiones con el header Authorization:

Include the API key in every request using the Authorization header:

HTTP Header
Authorization: Bearer wam_a1b2c3d4...
⚠ La clave da acceso a tus mensajes — trátala como una contraseña ⚠ The key grants access to your messages — treat it like a password No la incluyas en el código fuente público ni en repositorios. Usa variables de entorno. Never include it in public source code or repositories. Use environment variables.
Paso 3 — Primera petición
Step 3 — First request

Prueba que funciona obteniendo tus cuentas de WhatsApp:

Test it by fetching your WhatsApp accounts:

cURL
curl -H "Authorization: Bearer wam_TU_API_KEY" \
     "https://tudominio.com/wa-api/api/v1/accounts"
Respuesta ejemplo
Example response
JSON
[
  {
    "id": 1,
    "account_name": "Mi número personal",
    "type": "qr",
    "phone_number": "+34612345678",
    "status": "connected"
  }
]
Tipos de cuenta
Account types
📷 type: "qr"

Número vinculado por QR (personal o Business). Soporta envío de texto, imágenes y documentos.

Number linked via QR (personal or Business). Supports sending text, images and documents.

🌐 type: "meta"

WhatsApp Business API oficial de Meta. Solo permite envío de texto vía API (imágenes requieren ID de Meta).

Official Meta WhatsApp Business API. Only text sending via API (images require a Meta media ID).

GET /api/v1/accounts Lista tus cuentas de WhatsApp List your WhatsApp accounts

Devuelve todas las cuentas accesibles con la API key. Si la clave está restringida a una cuenta, devuelve solo esa.

Returns all accounts accessible with the API key. If the key is restricted to one account, returns only that one.

Respuesta
Response
[{
  "id": 1,
  "account_name": "Soporte",
  "type": "qr",          // "qr" | "meta"
  "phone_number": "+34612345678",
  "status": "connected"    // "connected" | "disconnected"
}]
GET /api/v1/conversations Lista conversaciones List conversations
Parámetros de query
Query parameters
ParámetroParameterTipoTypeDescripciónDescription
limit integer opcional / optional Máximo de resultados (defecto: 30) Maximum results (default: 30)
offset integer opcional / optional Paginación desde el resultado N Pagination from result N
search string opcional / optional Buscar por nombre o número Search by name or number
Respuesta
Response
[{
  "id": 42,
  "account_id": 1,
  "jid": "34612345678@s.whatsapp.net",
  "name": "Juan García",
  "last_message": "Hola, ¿cuándo llegará mi pedido?",
  "last_message_at": 1724177400,
  "unread_count": 2,
  "is_group": false
}]
GET /api/v1/messages Mensajes de una conversación Messages of a conversation
Parámetros de query (obligatorios marcados con *)
Query parameters (required marked with *)
ParámetroParameterTipoTypeDescripciónDescription
account_id * integer requerido / required ID de la cuenta de WhatsApp WhatsApp account ID
jid * string requerido / required JID de la conversación (ej: 34612345678@s.whatsapp.net) Conversation JID (e.g. 34612345678@s.whatsapp.net)
limit integer opcional / optional Máximo de mensajes (defecto: 50) Maximum messages (default: 50)
before integer opcional / optional Paginar: ID interno del último mensaje recibido Paginate: internal ID of the last received message
Respuesta
Response
[{
  "id": 1234,
  "wa_id": "3EB0...",           // ID interno de WhatsApp
  "direction": "in",           // "in" | "out"
  "body": "Hola, ¿me podéis ayudar?",
  "type": "text",             // text | image | document | audio | video
  "status": "read",           // sent | delivered | read | failed
  "timestamp": "2026-08-20T18:30:00.000Z",
  "sender_jid": null,          // solo en grupos
  "sender_name": null         // solo en grupos
}]
POST /api/v1/send Enviar un mensaje de texto Send a text message

Envía un mensaje de texto a un número. Funciona tanto con cuentas QR como Meta.

Sends a text message to a number. Works with both QR and Meta accounts.

Body (JSON)
Body (JSON)
CampoFieldTipoTypeDescripciónDescription
account_id * integer requerido / required ID de la cuenta desde la que enviar Account ID to send from
to * string requerido / required Número destino. Ej: 34612345678 o 34612345678@s.whatsapp.net Destination number. E.g. 34612345678 or 34612345678@s.whatsapp.net
body * string requerido / required Texto del mensaje Message text
cURL
curl -X POST \
  -H "Authorization: Bearer wam_TU_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"account_id": 1, "to": "34612345678", "body": "Hola desde la API"}' \
  "https://tudominio.com/wa-api/api/v1/send"
Respuesta exitosa
Success response
{
  "ok": true,
  "to": "34612345678@s.whatsapp.net",
  "body": "Hola desde la API",
  "wa_id": "3EB0C234D1..."   // ID del mensaje en WhatsApp
}
GET /api/v1/contacts Buscar contactos Search contacts
ParámetroParameterDescripciónDescription
q opcional / optional Búsqueda por nombre o número Search by name or number
account_id opcional / optional Filtrar por cuenta Filter by account
limit opcional / optional Máximo de resultados (defecto: 20) Maximum results (default: 20)
Respuesta
Response
[{
  "account_id": 1,
  "jid": "34612345678@s.whatsapp.net",
  "name": "Juan García",
  "conversation_name": "Juan García"
}]
¿Qué son los webhooks? What are webhooks? WA Manager enviará una petición HTTP POST a tu URL cada vez que llegue un mensaje nuevo (o cuando tú envíes uno). Así tu sistema se entera en tiempo real sin necesidad de consultar la API periódicamente. WA Manager will send an HTTP POST request to your URL every time a new message arrives (or when you send one). This lets your system react in real time without polling the API.
Crear un webhook
Create a webhook
1

Abre el panel de API Keys > pestaña Webhooks

Open the API Keys panel > Webhooks tab

En WA Manager, icono de llave 🔑 → pestaña Webhooks → rellena el formulario.

In WA Manager, key icon 🔑 → Webhooks tab → fill in the form.

2

URL destino

Destination URL

La URL a la que WA Manager enviará los eventos. Debe ser HTTPS y estar accesible desde internet. En n8n será tu URL de webhook de nodo; en Zapier o Make, la URL que te proporcionen al crear el trigger.

The URL WA Manager will send events to. Must be HTTPS and publicly accessible. In n8n it's your node webhook URL; in Zapier or Make, the trigger URL they provide.

3

Secret HMAC (recomendado)

HMAC Secret (recommended)

Introduce una cadena aleatoria como secreto. WA Manager firmará cada petición con HMAC-SHA256 y lo incluirá en el header X-WA-Signature. Así puedes verificar que el mensaje viene realmente de WA Manager.

Enter a random string as the secret. WA Manager will sign each request with HMAC-SHA256 and include it in the X-WA-Signature header. This lets you verify the message is genuinely from WA Manager.

Payload del webhook
Webhook payload

Cada evento se envía como un POST JSON con esta estructura:

Each event is sent as a JSON POST with this structure:

JSON — Payload
{
  "event": "message.inbound",   // o "message.outbound"
  "account_id": 1,
  "timestamp": "2026-08-20T18:30:00.000Z",
  "message": {
    "id": 1234,
    "wa_id": "3EB0C234D1...",
    "jid": "34612345678@s.whatsapp.net",
    "conversation_name": "Juan García",
    "direction": "in",
    "body": "Hola, necesito ayuda",
    "type": "text",
    "status": "received",
    "timestamp_unix": 1724177400,
    "sender_jid": null,        // solo en grupos
    "sender_name": null       // solo en grupos
  }
}
Verificar la firma HMAC
Verify the HMAC signature

Si configuraste un secreto, el header X-WA-Signature contiene el HMAC-SHA256 del body en hexadecimal. Verifica así:

If you configured a secret, the X-WA-Signature header contains the HMAC-SHA256 of the body in hex. Verify like this:

Node.js
const crypto = require('crypto');

function verifySignature(body, signature, secret) {
  const expected = crypto
    .createHmac('sha256', secret)
    .update(body)           // body como string o Buffer
    .digest('hex');
  return crypto.timingSafeEqual(
    Buffer.from(expected),
    Buffer.from(signature)
  );
}

// En tu endpoint:
const sig = req.headers['x-wa-signature'];
if (!verifySignature(req.rawBody, sig, 'TU_SECRET')) {
  res.status(401).send('Firma inválida');
}
Python
import hmac, hashlib

def verify_signature(body: bytes, signature: str, secret: str) -> bool:
    expected = hmac.new(
        secret.encode(),
        body,
        hashlib.sha256
    ).hexdigest()
    return hmac.compare_digest(expected, signature)
Eventos disponibles
Available events
message.inbound

Mensaje entrante

Inbound message

Un contacto te ha enviado un mensaje (texto, imagen, audio, documento, etc.)

A contact has sent you a message (text, image, audio, document, etc.)

message.outbound

Mensaje saliente

Outbound message

Has enviado un mensaje (desde la app o desde la API).

You sent a message (from the app or via the API).

💡 Responde siempre con HTTP 200 💡 Always respond with HTTP 200 WA Manager espera una respuesta 200 en menos de 10 segundos. Si el endpoint tarda más, haz el procesamiento en segundo plano y responde 200 inmediatamente. WA Manager expects a 200 response within 10 seconds. If processing takes longer, do it in the background and respond 200 immediately.
🔄

n8n

Nodo HTTP Request con header de autorización. Webhook Trigger para recibir mensajes.

HTTP Request node with auth header. Webhook Trigger to receive messages.

⚡

Zapier

Acción Webhooks by Zapier (POST) para enviar. Trigger Catch Hook para recibir.

Webhooks by Zapier action (POST) to send. Catch Hook trigger to receive.

🎯

Make (Integromat)

Módulo HTTP → Make a request. Custom Webhook para recibir eventos.

HTTP → Make a request module. Custom Webhook to receive events.

💻

Código propio

Custom code

Cualquier lenguaje con soporte HTTP. Ejemplos abajo en Node.js y Python.

Any language with HTTP support. Examples below in Node.js and Python.

n8n

Para enviar un mensaje desde n8n, usa el nodo HTTP Request:

To send a message from n8n, use the HTTP Request node:

n8n — HTTP Request node config (JSON)
{
  "method": "POST",
  "url": "https://tudominio.com/wa-api/api/v1/send",
  "authentication": "genericCredentialType",
  "genericAuthType": "httpHeaderAuth",
  // Credencial: Name = "Authorization", Value = "Bearer wam_..."
  "bodyParametersJson": {
    "account_id": 1,
    "to": "{{ $json.phone }}",
    "body": "{{ $json.message }}"
  }
}

Para recibir mensajes en n8n, crea un nodo Webhook y usa la URL generada como destino del webhook en WA Manager:

To receive messages in n8n, create a Webhook node and use the generated URL as the webhook destination in WA Manager:

n8n Webhook → POST → Responde 200 inmediatamente → Procesa el body {{ $json.message.body }} n8n Webhook → POST → Respond 200 immediately → Process body {{ $json.message.body }}
Node.js — Enviar mensaje
Node.js — Send message
JavaScript (Node.js / fetch)
const WA_API_KEY = process.env.WA_API_KEY;
const BASE_URL   = 'https://tudominio.com/wa-api/api/v1';

async function sendWhatsApp(accountId, phone, message) {
  const res = await fetch(`${BASE_URL}/send`, {
    method: 'POST',
    headers: {
      'Content-Type': 'application/json',
      'Authorization': `Bearer ${WA_API_KEY}`,
    },
    body: JSON.stringify({ account_id: accountId, to: phone, body: message }),
  });
  if (!res.ok) throw new Error(await res.text());
  return res.json();
}

// Uso:
sendWhatsApp(1, '34612345678', 'Hola desde Node.js!')
  .then(r => console.log('Enviado:', r.wa_id));
Python — Recibir webhook con FlaskReceive webhook with Flask
Python (Flask)
from flask import Flask, request, abort
import hmac, hashlib, json

app = Flask(__name__)
WA_SECRET = "mi_secreto_hmac"

@app.route('/webhook/whatsapp', methods=['POST'])
def wa_webhook():
    sig = request.headers.get('X-WA-Signature', '')
    expected = hmac.new(
        WA_SECRET.encode(), request.data, hashlib.sha256
    ).hexdigest()
    if not hmac.compare_digest(sig, expected):
        abort(401)

    data = request.get_json()
    msg = data['message']
    print(f"Mensaje de {msg['jid']}: {msg['body']}")

    # Procesa aquí: guarda en BD, notifica al agente, etc.

    return '', 200   # ← responder siempre 200 rápido
PHP — Enviar mensaje
PHP — Send message
PHP
<?php
$apiKey  = 'wam_TU_API_KEY';
$baseUrl = 'https://tudominio.com/wa-api/api/v1';

function sendWhatsApp($accountId, $phone, $message): array {
    global $apiKey, $baseUrl;
    $ch = curl_init("$baseUrl/send");
    curl_setopt_array($ch, [
        CURLOPT_POST           => true,
        CURLOPT_RETURNTRANSFER => true,
        CURLOPT_HTTPHEADER     => [
            "Authorization: Bearer $apiKey",
            'Content-Type: application/json',
        ],
        CURLOPT_POSTFIELDS => json_encode([
            'account_id' => $accountId,
            'to'         => $phone,
            'body'       => $message,
        ]),
    ]);
    $body = curl_exec($ch);
    curl_close($ch);
    return json_decode($body, true);
}

$result = sendWhatsApp(1, '34612345678', '¡Hola desde PHP!');
echo 'wa_id: ' . $result['wa_id'];

Todos los errores devuelven un objeto JSON con el campo error descriptivo. El código HTTP indica la categoría del problema.

All errors return a JSON object with a descriptive error field. The HTTP code indicates the problem category.

401

Unauthorized

API key ausente, con formato incorrecto (debe empezar por wam_) o revocada.

API key missing, wrongly formatted (must start with wam_) or revoked.

400

Bad Request

Falta un campo obligatorio en el body o un parámetro de query. El mensaje de error indica cuál.

A required body field or query parameter is missing. The error message indicates which one.

403

Forbidden

La API key está restringida a una cuenta concreta y has intentado acceder a otra.

The API key is restricted to a specific account and you tried to access a different one.

404

Not Found

La cuenta, conversación o recurso solicitado no existe o no te pertenece.

The account, conversation or requested resource does not exist or does not belong to you.

500

Internal Server Error

Error inesperado del servidor. Comprueba que la cuenta esté conectada y el mensaje de error del campo error.

Unexpected server error. Check that the account is connected and read the error field message.

502

Bad Gateway

Error al comunicarse con Meta Cloud API (solo cuentas tipo Meta). Revisa el token o el estado de tu app en Meta for Developers.

Error communicating with Meta Cloud API (Meta account type only). Check your token or app status in Meta for Developers.

Formato de error
Error format
{
  "error": "API key no encontrada o revocada"
}
Consejos de depuración
Debugging tips
✓ Checklist cuando algo falla ✓ Checklist when something fails
Vantis Uniasser

¿Necesitas ayuda con la integración?

Need help with the integration?

📧 info@uniasser.com 💬 +34 964 505 095