Exchange a connection code for a device credential
Unauthenticated by design: the connection code IS the credential, which is what lets the agent app have no sign-in screen at all. Returns a long-lived per-device secret, shown ONCE, which the device then presents to mint short-lived WebRTC tokens and to heartbeat presence.
Every failure except a full line answers devices.code_invalid without saying why — distinguishing expired from unknown from already-used would turn this into an oracle for whether six digits ever existed.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
curl -X POST "https://example.com/v1/devices/enroll" \ -H "Content-Type: application/json" \ -d '{ "code": "string" }'{ "device_id": "3bafab7b-4400-4bcf-8e6e-09f954699940", "device_secret": "string", "client_name": "string", "extension": "string", "phone_number": "string"}Send a tap-to-call button message POST
Sends an interactive message carrying a call button, letting the contact start a WhatsApp call to you with one tap — the inbound counterpart to requesting permission to call them. `display_text` and `ttl_minutes` fall back to Meta's defaults ("Call Now", 10080 minutes / 7 days) when omitted. ```json { "number_id": "9d2b1f53-8c0e-4f1d-9a6b-5d3a8c47e9f0", "to": "254700000001", "text": "Need a hand with your order? Tap to call us.", "display_text": "Call support", "ttl_minutes": 1440, "payload": "order-SK-4821" } ``` Meta's reference: https://developers.facebook.com/docs/whatsapp/cloud-api/guides/calling **API-key scope:** `whatsapp.messages`.
Mint a WebRTC token for this device POST
Authenticated with the device secret. The PBX identity is taken from the device record — a caller-supplied name is ignored, so a device cannot mint a token that rings as a colleague. Tokens are short-lived (about an hour); refresh on launch and on returning to the foreground.