What it is
Webhooks are HTTPS requests that YCloud sends to your application when message delivery, inbound messages, contacts, templates, calls, and other resources change.Before you begin
- Store your YCloud API key in
YCLOUD_API_KEY. - Deploy a publicly reachable HTTPS endpoint.
- Preserve the raw request body for signature verification.
- Decide which event types your application needs.
How it works
- Create a Webhook endpoint and subscribe it to event types.
- Store the returned endpoint
secret. - YCloud sends an event request to your endpoint.
- Verify
YCloud-Signaturebefore trusting the request. - Return a
2xxresponse promptly. - Process the event idempotently, because delivery may be repeated.
Request
Create an endpoint withPOST /webhookEndpoints.
Request fields
Example request
Subscribe to echo and handover events
For Agents onboarded through the Public REST API, create an endpoint with the following subscriptions. Console-created Agents do not emit these three events. To change an existing endpoint, preserve any event subscriptions you still need.whatsappMessage payload.
The handover event carries whatsappMetaBusinessAgent and retains its Agent/control information.
They do not use the WhatsApp Business App whatsapp.smb.message.echoes contract.
See echo and handover event details
for field definitions, examples, ordering, and handover correlation limits.
Response
The response returns the created endpoint and its signingsecret. Store the
secret securely. YCloud uses it to generate Webhook signatures.
Example response
Response fields
Receive events
Event request
YCloud sends a JSON event object to the configuredurl. The event includes
common fields such as id, type, apiVersion, and createTime, plus a
type-specific payload.
Your handler should:
- Read the raw request body.
- Validate the
YCloud-Signatureheader with the endpoint secret before trusting the payload. - Return a successful
2xxresponse promptly. - Move slow processing to a queue.
- Make event processing idempotent so repeated delivery does not repeat business actions.
Receiver response
Return a successful2xx HTTP response as soon as the signature and request are
accepted. The response body can be empty.
2xx response can
cause YCloud to retry the event, so deduplicate by event id.
Common payload examples
Expand an event to inspect its complete example payload. These examples come from the OpenAPI webhook specification. See all webhook payload examples for every supported event type.Contact attributes changed event
Contact attributes changed event
Example payload when contact attributes are changed
Contact created event
Contact created event
Example payload when a new contact is created
Contact deleted event
Contact deleted event
Example payload when a contact is deleted
Customer cancels subscription event
Customer cancels subscription event
Example payload when a customer cancels subscription
Customer resumes subscription
Customer resumes subscription
Example payload when a customer resumes subscription
WhatsApp template archived event
WhatsApp template archived event
Example payload when a WhatsApp template is archived
WhatsApp template unarchived event
WhatsApp template unarchived event
Example payload when a WhatsApp template is unarchived. The template status is the current status returned by Meta and does not represent a new approval review.
WhatsApp call connect event
WhatsApp call connect event
Example payload when a WhatsApp call is connected
WhatsApp call terminate event
WhatsApp call terminate event
Example payload when a WhatsApp call is terminated
WhatsApp call status updated event
WhatsApp call status updated event
Example payload when a WhatsApp call status is updated
Event schema and interactive payload reference.
Rotate the endpoint secret
Rotate a secret if it is exposed or as part of your security policy:An endpoint that repeatedly fails to receive notifications can move to
pending status and stop receiving events. Monitor webhook failures and endpoint status.
