API Reference
WhatsApp Messaging

Download media

GET
/v1/whatsapp/media/{id}

Streams the bytes of a media object.

Inbound messages carry media as an id, not a URL — {"type":"image","image":{"id":"1234567890123456"}}. This endpoint is how you turn that id into the file.

Sautikit proxies the bytes rather than redirecting you, deliberately: Meta serves media from a short-lived host whose URL expires in five minutes and is authorised only by your workspace's access token. A redirect would hand you a link that is both dead on arrival and, if it worked, would carry that token.

The response is the raw file. Content-Type is the MIME type Meta reports, and X-Sautikit-Media-Sha256 carries Meta's checksum so you can verify what you received.

curl "https://api.sautikit.com/v1/whatsapp/media/$MEDIA_ID?number_id=$NUMBER_ID" \  -H "Authorization: Bearer $SAUTIKIT_API_KEY" \  -o receipt.pdf

Meta's reference: https://developers.facebook.com/docs/whatsapp/cloud-api/reference/media

API-key scope: whatsapp.messages.

Authorization

bearerAuth
AuthorizationBearer <token>

Long-lived ES256 JWT minted from the dashboard (https://app.sautikit.com/developers/api-keys). Signed by the platform keyring. Carries workspace_id and scopes claims; revoked via the platform deny-list.

In: header

Path Parameters

id*string

Meta's media id, as carried on an inbound message (e.g. image.id).

Query Parameters

number_id?string

The Sautikit number the media belongs to. Mutually exclusive with connection_id.

Formatuuid
connection_id?string

The WhatsApp connection the media belongs to. Mutually exclusive with number_id.

Formatuuid

Response Body

application/octet-stream

application/json

application/json

curl -X GET "https://example.com/v1/whatsapp/media/string"
"string"
{  "error": {    "code": "validation.bad_request",    "message": "string",    "request_id": "string",    "details": [      "string"    ],    "resolution": "string",    "reason": "invalid_characters",    "suggested_e164": "+254727524723"  }}
{  "error": {    "code": "validation.bad_request",    "message": "string",    "request_id": "string",    "details": [      "string"    ],    "resolution": "string",    "reason": "invalid_characters",    "suggested_e164": "+254727524723"  }}

Upload media POST

Uploads a file to WhatsApp and returns the media id you then send in an image/video/audio/document message. Send a `multipart/form-data` body with a `file` part. The MIME type comes from a `type` field if you send one, otherwise from the part's own `Content-Type` — Meta requires it and will not sniff. The sending number is named in the QUERY (`number_id` or `connection_id`) so the body stays a pure file upload. ```bash curl -X POST \ "https://api.sautikit.com/v1/whatsapp/media?number_id=$NUMBER_ID" \ -H "Authorization: Bearer $SAUTIKIT_API_KEY" \ -F "type=application/pdf" \ -F "file=@invoice.pdf" ``` The returned `id` goes straight into a send: ```json { "number_id": "9d2b1f53-8c0e-4f1d-9a6b-5d3a8c47e9f0", "to": "254712345678", "type": "document", "document": { "id": "1234567890123456", "filename": "Invoice-INV-2291.pdf" } } ``` Prefer an uploaded `id` over a public `link`. A link is re-fetched by WhatsApp on every send and cached for only 10 minutes, so a receipt sent to 200 customers is 200 fetches of your server; an uploaded id is fetched once. WhatsApp's limits apply and are enforced upstream: 5 MB images, 16 MB audio and video, 100 MB documents, 500 KB stickers. Supported types include JPEG/PNG, MP4, MP3/M4A/OGG(Opus), PDF and the common Office formats, and WebP for stickers. Meta's reference: https://developers.facebook.com/docs/whatsapp/cloud-api/reference/media **API-key scope:** `whatsapp.messages`.

Delete media DELETE

Deletes an uploaded media object at Meta. Meta's reference: https://developers.facebook.com/docs/whatsapp/cloud-api/reference/media **API-key scope:** `whatsapp.messages`.