Update a webhook
PATCHhttps://api.wapito.com/v1/webhooks/{id}
Send a channel token on every request: Authorization: Bearer wpt_YOUR_TOKEN
Changes the URL, event filter, headers or enabled flag of an existing webhook. Only the fields you send are changed; the signing secret is fixed for the life of the webhook (delete and create one to get a new secret). Disabling a webhook stops new deliveries from being queued, which is the safe way to pause an endpoint you are redeploying rather than letting retries pile up.
Parameters
| Name | In | Type | Required | Description | Example |
|---|---|---|---|---|---|
id | path | string | Required | Webhook id (`whk_` + ULID). | whk_01JRQ8F4X9N2K7YB3C5V6W8H0T |
Request body
| Field | Type | Required | Description |
|---|---|---|---|
enabled | boolean | Optional | Pause or resume delivery. |
events | array of string | Optional | Replacement event list. |
headers | object | Optional | Replacement header map. |
url | string | Optional | New HTTPS endpoint.uri |
{
"enabled": true,
"events": [
"messages",
"messages.status",
"channel"
]
}Responses
200
The webhook after the change.
| Field | Type | Required | Description |
|---|---|---|---|
created_at | string | null | Required | ISO 8601 timestamp.date-time |
enabled | boolean | Required | Disabled webhooks are skipped without queueing jobs. |
events | array of string | Required | Subscribed events: exact names, prefix wildcards such as `messages.*`, or `*`. |
headers | object | Required | Extra headers sent with every delivery. |
id | string | Required | Webhook id (`whk_` + ULID). |
secret_preview | string | null | Required | Masked signing secret, e.g. `whsec_…f31a`. |
url | string | Required | HTTPS endpoint Wapito posts events to.uri |
{
"created_at": "2026-09-01T08:30:00.000Z",
"enabled": true,
"events": [
"messages",
"messages.status",
"groups.participants"
],
"headers": {
"X-Acme-Tenant": "eu-1"
},
"id": "whk_01JRQ8F4X9N2K7YB3C5V6W8H0T",
"secret_preview": "whsec_…f31a",
"url": "https://hooks.acme.example/wapito"
}400
The request body or query string is malformed, or the recipient cannot be parsed into a WhatsApp id.
Show 2 example bodies
invalid_recipient — `to` is not a dialable number or valid WhatsApp id
{
"error": {
"code": "invalid_recipient",
"details": {
"to": "+1555"
},
"message": "The recipient is not a valid WhatsApp address.",
"request_id": "req_01JRQ8F4X9N2K7YB3C5V6W8H0T"
}
}invalid_request — schema validation failed
{
"error": {
"code": "invalid_request",
"details": {
"issues": [
{
"message": "Array must contain at least 2 element(s)",
"path": "body.options"
}
]
},
"message": "The request payload failed validation.",
"request_id": "req_01JRQ8F4X9N2K7YB3C5V6W8H0T"
}
}401
The channel token is missing, malformed, revoked or belongs to a deleted channel.
Show 2 example bodies
token_revoked — the token was rotated in the dashboard
{
"error": {
"code": "token_revoked",
"message": "This channel token has been revoked.",
"request_id": "req_01JRQ8F4X9N2K7YB3C5V6W8H0T"
}
}unauthorized — no or unusable Bearer token
{
"error": {
"code": "unauthorized",
"message": "Missing or invalid channel token.",
"request_id": "req_01JRQ8F4X9N2K7YB3C5V6W8H0T"
}
}403
The token is valid but the channel may not perform this action right now.
Show 2 example bodies
channel_locked — billing lapsed or the channel was locked by an operator
{
"error": {
"code": "channel_locked",
"details": {
"reason": "plan_required"
},
"message": "This channel is locked.",
"request_id": "req_01JRQ8F4X9N2K7YB3C5V6W8H0T"
}
}forbidden — the channel does not own the target object
{
"error": {
"code": "forbidden",
"message": "You are not allowed to perform this action.",
"request_id": "req_01JRQ8F4X9N2K7YB3C5V6W8H0T"
}
}404
The addressed object does not exist, or the number is not on WhatsApp.
Show 3 example bodies
message_not_found — the message id is unknown to the engine
{
"error": {
"code": "message_not_found",
"message": "The requested message does not exist.",
"request_id": "req_01JRQ8F4X9N2K7YB3C5V6W8H0T"
}
}not_found — unknown id
{
"error": {
"code": "not_found",
"message": "The requested resource does not exist.",
"request_id": "req_01JRQ8F4X9N2K7YB3C5V6W8H0T"
}
}not_on_whatsapp — the number is not registered
{
"error": {
"code": "not_on_whatsapp",
"message": "This number is not registered on WhatsApp.",
"request_id": "req_01JRQ8F4X9N2K7YB3C5V6W8H0T"
}
}422
The request is well formed but cannot be acted on.
Show the example body
webhook_url_invalid — not HTTPS, or resolves to a private address
{
"error": {
"code": "webhook_url_invalid",
"details": {
"url": "http://localhost:3000/hook"
},
"message": "The webhook URL is not reachable or not allowed.",
"request_id": "req_01JRQ8F4X9N2K7YB3C5V6W8H0T"
}
}429
A rate limit, a plan quota or one of the anti-ban guards stopped the request. Every one of these is safe to retry later; read `Retry-After` when present.
Show 5 example bodies
cold_send_limit — too many first messages to new recipients this hour
{
"error": {
"code": "cold_send_limit",
"details": {
"resets_at": "2026-09-15T09:00:00.000Z",
"window_cap": 20
},
"message": "The hourly limit for messages to new recipients is reached.",
"request_id": "req_01JRQ8F4X9N2K7YB3C5V6W8H0T"
}
}quota_exceeded — plan quota for the day or month
{
"error": {
"code": "quota_exceeded",
"details": {
"quota": "sent",
"resets_at": "2026-09-16T00:00:00.000Z",
"used": 150
},
"message": "The plan quota for this resource is exhausted.",
"request_id": "req_01JRQ8F4X9N2K7YB3C5V6W8H0T"
}
}rate_limited — per-minute API rate limit
{
"error": {
"code": "rate_limited",
"details": {
"retry_after": 12
},
"message": "Too many requests.",
"request_id": "req_01JRQ8F4X9N2K7YB3C5V6W8H0T"
}
}send_rate_limited — the send queue did not drain within 20 s
{
"error": {
"code": "send_rate_limited",
"details": {
"retry_after": 5
},
"message": "The send queue for this channel is saturated.",
"request_id": "req_01JRQ8F4X9N2K7YB3C5V6W8H0T"
}
}warmup_limit — the warm-up ladder cap for today
{
"error": {
"code": "warmup_limit",
"details": {
"cap": 200,
"day": 2
},
"message": "The warm-up limit for this channel is reached.",
"request_id": "req_01JRQ8F4X9N2K7YB3C5V6W8H0T"
}
}500
Something went wrong inside Wapito. Quote `request_id` when reporting it.
Show the example body
internal_error — unexpected failure
{
"error": {
"code": "internal_error",
"message": "Something went wrong on our side.",
"request_id": "req_01JRQ8F4X9N2K7YB3C5V6W8H0T"
}
}Errors
Code examples
import requests
url = "https://api.wapito.com/v1/webhooks/whk_01JRQ8F4X9N2K7YB3C5V6W8H0T"
payload = {
"events": ["messages", "messages.status", "channel"],
"enabled": True
}
headers = {
"Authorization": "Bearer wpt_YOUR_TOKEN",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.json())Related
Other endpoints in this group
Reference
Try it on your own number
Create a channel, link a WhatsApp number by QR or pairing code, and call the API in a couple of minutes. The Sandbox plan is free and needs no card.