Self-hosted WhatsApp API

WhatsApp over HTTP, on your own box.

Link a number, get an API key, send and receive messages over a plain REST API. Wire-compatible with WasenderAPI, so existing clients work by changing one base URL.

Read the guide

Sessions live on your server. Credentials never leave your database.

connectedPOST /api/send-message
curl -X POST https://api.wapi.crafter.run/api/send-message   -H "Authorization: Bearer $KEY"   -d '{"to":"+51999888777","text":"hello"}'
{ "success": true,
  "data": { "msgId": 100024, "status": "in_progress" } }

Watch it

Your WhatsApp, over HTTP.

Seventy-eight seconds on a live account: messages, images, stickers, video and documents landing in a real thread with WhatsApp’s own delivery ticks, then a group — and finally a sandbox, where a contact who does not exist fires a genuine webhook.

Every command in it was recorded from the real CLI against a real session, and the number is masked at capture time — see ops/capture-demo.mjs.

The gap

The official API cannot see your groups.

Meta’s Cloud API covers business messaging, not the conversations most teams actually run on: group chats, personal threads, the number people already message. Reaching those means driving a real WhatsApp client.

wapi does that, and puts a stable REST surface in front of it.

What you get

Twenty-nine endpoints, one polymorphic send.

Send anything

Text, images, video, audio notes, documents, stickers, locations, contact cards and polls — all through one endpoint, discriminated by which field you set.

Receive everything

Twenty-two webhook events with retry and backoff, from messages and receipts to group participant changes and calls.

Groups and contacts

List groups, read metadata and participants, resolve LID identities, and send to a group with the same call you use for a person.

How it works

Three steps, about two minutes.

  1. 01

    Create a session

    One session per phone number. It gets its own API key, webhook config and optional proxy.

  2. 02

    Scan the QR

    The code streams to your dashboard live. Credentials are stored encrypted, so a redeploy reconnects instead of asking you to scan again.

  3. 03

    Call the API

    Send with the session key. Point a webhook URL at your app and inbound messages arrive as JSON.

Worth knowing

It drives an unofficial client.

wapi is built on Baileys, which speaks WhatsApp’s protocol directly. That is what makes group access possible, and it is against WhatsApp’s terms — numbers driven this way can be restricted or banned.

There is per-session proxy support and an account-protection mode that paces sends to one every five seconds. Neither is a guarantee. Use a number you can afford to lose.

Link a number and send your first message.

Documentation