API Reference
WhatsApp Messaging

Ask a contact for permission to call them

POST
/v1/whatsapp/call-permissions/request

Sends a call-permission request to a contact. You cannot place a WhatsApp call to someone who has not granted permission, so this is the step that unlocks outbound WhatsApp calling to them.

Two forms, selected by mode:

  • free_form (default) — an interactive permission-request message built from text. Subject to the same 24-hour customer service window as any free-form message.
  • template — an already-approved template whose components include a call_permission_request component. Use this outside the 24-hour window.

The contact's answer arrives as the whatsapp.call_permission.updated workspace webhook.

{  "connection_id": "3f1a9c22-58d4-4f7e-9b10-2c6e8a4d5f31",  "wa_id": "254700000001",  "mode": "free_form",  "text": "May we call you about your order?"}

Meta's reference: https://developers.facebook.com/docs/whatsapp/cloud-api/guides/call-permissions

API-key scope: whatsapp.messages.

Authorization

bearerAuth
AuthorizationBearer <token>

Long-lived ES256 JWT minted from the dashboard (https://app.sautikit.com/developers/api-keys). Signed by the platform keyring. Carries workspace_id and scopes claims; revoked via the platform deny-list.

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

curl -X POST "https://example.com/v1/whatsapp/call-permissions/request" \  -H "Content-Type: application/json" \  -d '{    "connection_id": "d3547de1-d1f2-4344-b4c2-17169b7526f9",    "wa_id": "254700000001"  }'
{  "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",  "workspace_id": "0967198e-ec7b-4c6b-b4d3-f71244cadbe9",  "connection_id": "d3547de1-d1f2-4344-b4c2-17169b7526f9",  "wa_id": "254700000001",  "status": "string",  "is_permanent": true,  "expires_at": "2019-08-24T14:15:22Z",  "last_requested_at": "2019-08-24T14:15:22Z",  "created_at": "2019-08-24T14:15:22Z",  "updated_at": "2019-08-24T14:15:22Z"}
{  "error": {    "code": "validation.bad_request",    "message": "string",    "request_id": "string",    "details": [      "string"    ],    "resolution": "string",    "reason": "invalid_characters",    "suggested_e164": "+254727524723"  }}
{  "error": {    "code": "validation.bad_request",    "message": "string",    "request_id": "string",    "details": [      "string"    ],    "resolution": "string",    "reason": "invalid_characters",    "suggested_e164": "+254727524723"  }}

Get a contact's WhatsApp call permission GET

Returns whether a contact has granted permission for you to call them on WhatsApp. A contact with no recorded permission comes back as `no_permission` — absence is a meaningful answer here, not a 404. Pass `live=true` to additionally check with Meta and refresh the stored value. A failed live check degrades to the stored value rather than failing the request. **API-key scope:** `whatsapp.messages`.

Upload media POST

Uploads a file to WhatsApp and returns the media id you then send in an image/video/audio/document message. Send a `multipart/form-data` body with a `file` part. The MIME type comes from a `type` field if you send one, otherwise from the part's own `Content-Type` — Meta requires it and will not sniff. The sending number is named in the QUERY (`number_id` or `connection_id`) so the body stays a pure file upload. ```bash curl -X POST \ "https://api.sautikit.com/v1/whatsapp/media?number_id=$NUMBER_ID" \ -H "Authorization: Bearer $SAUTIKIT_API_KEY" \ -F "type=application/pdf" \ -F "file=@invoice.pdf" ``` The returned `id` goes straight into a send: ```json { "number_id": "9d2b1f53-8c0e-4f1d-9a6b-5d3a8c47e9f0", "to": "254712345678", "type": "document", "document": { "id": "1234567890123456", "filename": "Invoice-INV-2291.pdf" } } ``` Prefer an uploaded `id` over a public `link`. A link is re-fetched by WhatsApp on every send and cached for only 10 minutes, so a receipt sent to 200 customers is 200 fetches of your server; an uploaded id is fetched once. WhatsApp's limits apply and are enforced upstream: 5 MB images, 16 MB audio and video, 100 MB documents, 500 KB stickers. Supported types include JPEG/PNG, MP4, MP3/M4A/OGG(Opus), PDF and the common Office formats, and WebP for stickers. Meta's reference: https://developers.facebook.com/docs/whatsapp/cloud-api/reference/media **API-key scope:** `whatsapp.messages`.