Self-hosted WhatsApp API
WhatsApp over HTTP, on your own box.
Link a number, get an API key, send and receive messages over a plain REST API. Wire-compatible with WasenderAPI, so existing clients work by changing one base URL.
Sessions live on your server. Credentials never leave your database.
curl -X POST https://api.wapi.crafter.run/api/send-message -H "Authorization: Bearer $KEY" -d '{"to":"+51999888777","text":"hello"}'{ "success": true,
"data": { "msgId": 100024, "status": "in_progress" } }Watch it
Your WhatsApp, over HTTP.
Seventy-eight seconds on a live account: messages, images, stickers, video and documents landing in a real thread with WhatsApp’s own delivery ticks, then a group — and finally a sandbox, where a contact who does not exist fires a genuine webhook.
Every command in it was recorded from the real CLI against a real session, and the number is masked at capture time — see ops/capture-demo.mjs.
The gap
The official API cannot see your groups.
Meta’s Cloud API covers business messaging, not the conversations most teams actually run on: group chats, personal threads, the number people already message. Reaching those means driving a real WhatsApp client.
wapi does that, and puts a stable REST surface in front of it.
What you get
Twenty-nine endpoints, one polymorphic send.
Send anything
Text, images, video, audio notes, documents, stickers, locations, contact cards and polls — all through one endpoint, discriminated by which field you set.
Receive everything
Twenty-two webhook events with retry and backoff, from messages and receipts to group participant changes and calls.
Groups and contacts
List groups, read metadata and participants, resolve LID identities, and send to a group with the same call you use for a person.
How it works
Three steps, about two minutes.
- 01
Create a session
One session per phone number. It gets its own API key, webhook config and optional proxy.
- 02
Scan the QR
The code streams to your dashboard live. Credentials are stored encrypted, so a redeploy reconnects instead of asking you to scan again.
- 03
Call the API
Send with the session key. Point a webhook URL at your app and inbound messages arrive as JSON.
Worth knowing
It drives an unofficial client.
wapi is built on Baileys, which speaks WhatsApp’s protocol directly. That is what makes group access possible, and it is against WhatsApp’s terms — numbers driven this way can be restricted or banned.
There is per-session proxy support and an account-protection mode that paces sends to one every five seconds. Neither is a guarantee. Use a number you can afford to lose.