You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 1c684af
Browse filesBrowse the repository at this point in the historyBrowse files
This change allows both the `X-MASTER-KEY` and `X-API-KEY` to be sent in the request body for POST requests, providing more flexibility for users.
The key extraction logic has been centralized into a new helper function to improve code maintainability.
The Swagger documentation, Postman collection, and README have all been updated to reflect these changes.
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
Copy file name to clipboardExpand all lines: README.md
+15-12Lines changed: 15 additions & 12 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -168,15 +168,17 @@ All endpoints are prefixed with `/api`.
168
168
169
169
### **Authentication**
170
170
171
-
This API uses a two-key system for security and session management:
171
+
This API uses a two-key system for security and session management. Both keys can be provided in either the request header or the request body for `POST` requests, giving you more flexibility. For `GET` requests, they must be in the header.
172
172
173
173
1. **Master Key (`X-MASTER-KEY`)**:
174
-
- This is a global key that grants access to the API server.
175
-
- It must be included in the header of **every single request**.
174
+
- This is a global key that grants access to the entire API server.
175
+
- It can be included in the `X-MASTER-KEY` header or as a field in the JSON request body. The header will always take precedence if both are provided.
176
176
- This is the key you set in your `.env` file.
177
177
178
178
2. **Session Key (`X-API-KEY`)**:
179
179
- This key identifies a specific WhatsApp session (i.e., a specific phone number).
180
+
- For `POST` requests, it can be in the `X-API-KEY` header or a field in the JSON/form-data body.
181
+
- For `GET` requests, it must be in the `X-API-KEY` header.
180
182
- You can invent any unique string for each session (e.g., `user1_phone`, `work_account`, a random hash, etc.).
181
183
- The first time a new `X-API-KEY` is used with the `/connect` endpoint, a new session will be created for it.
182
184
@@ -266,12 +268,12 @@ Once connected, the server will save the session data in the `./sessions` folder
- **Description**: Sends a plain text message. The `X-API-KEY` can be in the header or, as shown below, in the request body.
272
273
- **Payload**: `application/json`
273
274
```json
274
275
{
276
+
"X-API-KEY": "your_unique_session_key",
275
277
"to": "+1234567890",
276
278
"message": "Hello from the API!"
277
279
}
@@ -281,24 +283,24 @@ Once connected, the server will save the session data in the `./sessions` folder
281
283
282
284
- **Endpoint**: `POST /send-attachment`
283
285
- **Description**: Sends an attachment to a specified number. This endpoint supports three methods: direct file upload, from a URL, or from a Base64 string.
* description: Sends a text message from a specific session. The session is identified by the `X-API-KEY`, which can be passed either in the request header or in the request body. The header takes precedence.
83
+
* parameters:
84
+
* - in: header
85
+
* name: X-API-KEY
86
+
* schema:
87
+
* type: string
88
+
* required: false
89
+
* description: Your unique session key (can be in header or body).
64
90
* requestBody:
65
91
* required: true
66
92
* content:
67
93
* application/json:
68
94
* schema:
69
95
* type: object
70
96
* properties:
71
-
* number:
97
+
* X-API-KEY:
98
+
* type: string
99
+
* description: Your unique session key (if not provided in header).
100
+
* to:
72
101
* type: string
102
+
* description: The recipient's phone number.
73
103
* message:
74
104
* type: string
105
+
* description: The text message to send.
106
+
* required:
107
+
* - to
108
+
* - message
75
109
* responses:
76
110
* 200:
77
111
* description: Message sent successfully.
78
112
* 400:
79
-
* description: Bad request.
113
+
* description: Bad request (e.g., missing parameters or session key).
* description: Sends a file attachment from a specific session. The session is identified by the `X-API-KEY`, which can be passed either in the request header or in the request body. The header takes precedence. This endpoint supports `multipart/form-data` for direct uploads and `application/json` for sending from a URL or Base64 string.
124
+
* parameters:
125
+
* - in: header
126
+
* name: X-API-KEY
127
+
* schema:
128
+
* type: string
129
+
* required: false
130
+
* description: Your unique session key (can be in header or body).
91
131
* requestBody:
92
132
* required: true
93
133
* content:
94
134
* multipart/form-data:
95
135
* schema:
96
136
* type: object
97
137
* properties:
98
-
* number:
138
+
* X-API-KEY:
139
+
* type: string
140
+
* description: Your unique session key (if not provided in header).
141
+
* to:
99
142
* type: string
100
143
* caption:
101
144
* type: string
102
145
* file:
103
146
* type: string
104
147
* format: binary
148
+
* required:
149
+
* - to
150
+
* - file
151
+
* application/json:
152
+
* schema:
153
+
* type: object
154
+
* properties:
155
+
* X-API-KEY:
156
+
* type: string
157
+
* description: Your unique session key (if not provided in header).
158
+
* to:
159
+
* type: string
160
+
* file:
161
+
* type: string
162
+
* description: A public URL to the file or a Base64 encoded string.
163
+
* type:
164
+
* type: string
165
+
* description: The MIME type of the file (required for Base64).
166
+
* caption:
167
+
* type: string
168
+
* required:
169
+
* - to
170
+
* - file
105
171
* responses:
106
172
* 200:
107
173
* description: Attachment sent successfully.
108
174
* 400:
109
-
* description: Bad request.
175
+
* description: Bad request (e.g., missing parameters or session key).
0 commit comments