wapi.
SDKs

TypeScript

A typed client with no runtime dependencies, vendored rather than installed.

@wapi/sdk wraps the whole surface with no runtime dependencies — it uses global fetch, so Node 18+, Bun and Deno all work. It exists mostly so you do not have to remember which of the six success envelopes a given endpoint uses.

Vendor it rather than installing it

npm cannot install a subdirectory of a git repository, and this client lives inside a monorepo — so npm install github:crafter-station/wapi would fetch the root package, not the SDK. Since the client is dependency-free source, copying it in is a real channel rather than a workaround:

npx giget@latest gh:crafter-station/wapi/sdk/typescript/src src/wapi
#   import { WapiClient } from "./wapi/index.js";

Append #v0.3.1 to that spec to pin a tag for anything you deploy.

Use it

import { WapiClient } from "@wapi/sdk";

const wapi = new WapiClient({ apiKey: process.env.WAPI_KEY });

const { msgId } = await wapi.messages.send({ to: "+51999888777", text: "hello" });
const groups = await wapi.groups.list();
const meta = await wapi.groups.metadata(groups[0].jid);

The client unwraps envelopes for you: send returns the data object rather than { success, data }. Failures throw, carrying the status and the parsed body, so the per-field errors map from a 422 is reachable on the caught error instead of being lost.

Two clients, two credentials

// Account-level work needs a Personal Access Token.
const admin = new WapiClient({ apiKey: process.env.WAPI_PAT });
const sessions = await admin.sessions.list();

// Session-level work needs that session's own key.
const wapi = new WapiClient({ apiKey: sessions[0].api_key });
await wapi.messages.send({ to: "+51999888777", text: "hello" });

That is the whole reason there are two constructions rather than one client with a mode flag. See Authentication.

Keep it on the server

Never construct this in a client component. The key grants full control of a WhatsApp account, and anything in a browser bundle is world-readable — call it from a server route or a server action. The agent skill ships a server-only wrapper that turns a mistake here into a build error rather than a leaked credential.

On this page