Skip to content

Developer hub

This section is for developers and technical integrations. If you want to use WhatSetter day to day (campaigns, conversations, meetings), go to the dashboard guides.

REST API

34 endpoints to read leads and conversations, import contacts, send messages through the anti-ban engine, drive campaigns, block numbers and read your tracked links. Quickstart · Authentication

Signed webhooks

WhatSetter pushes events to your server the moment they happen: lead qualified, lead ruled out, number disconnected. Every delivery is signed with HMAC-SHA256. Set up webhooks

MCP server

34 tools for Claude, Cursor, VS Code, ChatGPT, Gemini CLI and Codex CLI. Your assistant reads your leads, imports contacts or blocks a dial prefix from a chat. Connect an assistant

API reference

One page per endpoint, generated from the OpenAPI 3.1 spec, with schemas, examples and a “Try it” console. Open the reference

Each guide shows the same request in cURL, JavaScript and Python, the response you get, and the errors that matter for that endpoint.

  • One key for everything. The same ws_live_… key works for the REST API and the MCP server. Revoke it and both stop within a minute.
  • Scopes. Every key carries permissions (leads:read, messages:send, blocklist:manage and so on). Grant each integration the minimum it needs. See Authentication and permissions.
  • The anti-ban cannot be bypassed. The API applies the same protections as the dashboard: no cold outreach through POST /messages, a daily quota per WhatsApp number, humanized sends.
  • One error envelope. Every error is { "error": { "code": "…", "message": "…" } } with a stable code. See Errors, limits and idempotency.
  • Your workspace only. A key sees its own workspace. An id that belongs to another workspace answers 404, never 403.
What Count
REST endpoints 34
MCP tools 34
Scopes 14, plus Full access
Webhook events 5, of which 3 are emitted today