API & webhooks integration
Your systems, talking WhatsApp
Send messages and templates from your backend, and get messages, statuses and leads pushed to your server, signed.
Pro and upRole-based, expiring keysHMAC-SHA256 signed

{
"to": "+919876543210",
"type": "template",
"payload": { "type": "template",
"template": { "name": "order_update",
"variables": ["Rahul", "ORD-1042"] } }
}x-webhook-event: message.status
x-webhook-signature: sha256=9f2c…e41a
{ "event": "message.status",
"data": { "messageId": "3f1c…",
"status": "delivered" } }What it does
What you get with the API
Drawn with the dashboard’s own pieces, with sample data.
Send from anywhere
Text, templates, media and interactive messages from your backend, CRM or a cron job.
/api/v1/send · Bearer wa_••••POST{ "to": "+919876543210", "type": "template", "payload": { "type": "template", "template": { "name": "order_update", "variables": ["Rahul", "ORD-1042"] } } }Get pushed, not polled
Messages, statuses, template decisions, leads and tasks as they happen, with retries.
Webhook endpointOnlead.createdA new lead arriveslead.stage_changedA lead moves stagemessage.receivedA customer writesconversation.closedA chat is closedflow.completedAn in-chat form is submittedtemplate.approvedMeta approves a template
Signed HMAC-SHA256 · retried on failureVerify every delivery
An HMAC-SHA256 signature over the timestamp and the raw body.
verify.js// signed over `${timestamp}.${rawBody}` const expected = 'sha256=' + crypto .createHmac('sha256', secret) .update(ts + '.' + rawBody) .digest('hex');Keys you control
A key per integration, with its access and an expiry, revoked at once.
API keysNew key- ZapierSend and read · expires in 300 daysActive
- Website backendSend and read · expires in 41 daysActive
- Old CRM syncRead only · revokedRevoked
Setup
Connect the API in 4 steps
- 1In Fliok
Issue an API key
Pick its access and an expiry. Copy it once; it is never shown again.
- 2In Your code
Call the API
Send messages and media, or read conversations, contacts and leads.
- 3In Fliok
Add a webhook endpoint
Your URL and the events you want; Fliok signs every delivery.
- 4In Your code
Verify and go live
Check each signature, watch each key’s last use, revoke at once.
Good to know
- Free-form text only inside the 24-hour window; outside it, send a template.
- Team management and AI settings stay in the dashboard.
- Meta’s per-message charges apply as usual.
Pro and above: API keys, the REST API and signed webhooks are part of the developer features.
At fliok.com/docs/api: every endpoint and webhook event, with request and response examples.
Each delivery carries an HMAC-SHA256 signature over the timestamp and the raw body, made with your endpoint’s secret. Check it before you trust the body.
Build on your WhatsApp
Start on the Free plan, then connect the API on Pro or higher.
Free forever plan · Keep your WhatsApp app