Send a tap-to-call button message
Sends an interactive message carrying a call button, letting the contact start a WhatsApp call to you with one tap — the inbound counterpart to requesting permission to call them.
display_text and ttl_minutes fall back to Meta's defaults
("Call Now", 10080 minutes / 7 days) when omitted.
{ "number_id": "9d2b1f53-8c0e-4f1d-9a6b-5d3a8c47e9f0", "to": "254700000001", "text": "Need a hand with your order? Tap to call us.", "display_text": "Call support", "ttl_minutes": 1440, "payload": "order-SK-4821"}Meta's reference: https://developers.facebook.com/docs/whatsapp/cloud-api/guides/calling
API-key scope: whatsapp.messages.
Authorization
bearerAuth Long-lived ES256 JWT minted from the dashboard (https://app.sautikit.com/developers/api-keys). Signed by the
platform keyring. Carries workspace_id and scopes claims;
revoked via the platform deny-list.
In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/v1/whatsapp/call-buttons" \ -H "Content-Type: application/json" \ -d '{ "to": "254700000001", "text": "Need a hand with your order? Tap to call us." }'{ "wamid": "string", "status": "accepted"}{ "error": { "code": "validation.bad_request", "message": "string", "request_id": "string", "details": [ "string" ], "resolution": "string", "reason": "invalid_characters", "suggested_e164": "+254727524723" }}{ "error": { "code": "validation.bad_request", "message": "string", "request_id": "string", "details": [ "string" ], "resolution": "string", "reason": "invalid_characters", "suggested_e164": "+254727524723" }}{ "error": { "code": "validation.bad_request", "message": "string", "request_id": "string", "details": [ "string" ], "resolution": "string", "reason": "invalid_characters", "suggested_e164": "+254727524723" }}Delete media DELETE
Deletes an uploaded media object at Meta. Meta's reference: https://developers.facebook.com/docs/whatsapp/cloud-api/reference/media **API-key scope:** `whatsapp.messages`.
Exchange a connection code for a device credential POST
Unauthenticated by design: the connection code IS the credential, which is what lets the agent app have no sign-in screen at all. Returns a long-lived per-device secret, shown ONCE, which the device then presents to mint short-lived WebRTC tokens and to heartbeat presence. Every failure except a full line answers `devices.code_invalid` without saying why — distinguishing expired from unknown from already-used would turn this into an oracle for whether six digits ever existed.