Documentation

WhatsApp (Kirimdev)

Platform Integration for Webku marketing and product utilities. Not WhatsApp-as-a-service for tenant sites.

Who can see it

Only super_admin sees Integration → WhatsApp. Clients never see the menu, including during impersonation (the operator is acting as that client). API keys stay on the server; the browser calls /api/v1/integrations/whatsapp only.

Connection

Save the Kirimdev Bearer key and webhook HMAC secret on Connection. Credentials are encrypted at rest. Sync accounts, pick a default phone_number_id, and register POST /api/v1/webhooks/kirimdev with events message.received and message.status.

Meta templates

Create MARKETING, UTILITY, or AUTHENTICATION templates through Kirimdev. Names must match ^[a-z0-9_]+$. Sync caches them locally. AUTHENTICATION templates power login OTP with a 5-minute hashed code and email fallback.

Contacts and inbox

Contacts are created at Kirimdev POST /v1/{phone_number_id}/contacts with phone_number in E.164 (for example +62812…), not a global /contacts path and not wa_id. List uses the same phone-scoped path. Labels live at GET/POST /v1/labels and attach with POST /v1/{phone_number_id}/contacts/{ctc_id}/labels or /contacts/bulk_label. Inbox conversations come from GET /v1/{phone_number_id}/conversations.

Opt-in

Marketing campaigns only include users who set a WhatsApp number and checked opt-in on Profile. Utility automations (lead, publish, org welcome, OTP) can use the number without marketing opt-in.