Calling the API
Send the access token in the Authorization header on every call. The same endpoints that work with an account's own API key work with your token, limited to the permissions the account allowed.
Authorization: Bearer spo_at_...Only this header works. A token in the query string or the body is ignored.
WhatsApp apps
Base URL https://api.splashifypro.com. The request and response shapes are those of the Public API.
Email apps
Base URL https://api.splashifypro.com. The shapes are those of the Email API.
Everything else is refused
Any endpoint not listed above answers 403 endpoint_not_allowed, even with a valid token. That includes the account's settings, wallet, team, API keys, IP allowlist, webhooks, GraphQL, SMS, RCS, broadcasts and every /api/v1/app/* route. Paths must match exactly: a trailing slash or an encoded slash in the path is refused.
Delivery status
There are no webhooks to apps yet, so poll for status:
- WhatsApp:
GET /api/v1/public/messages/:id?phone=<number with country code>, with theidfrom the send answer. Your app sees only the messages it sent itself. See Message status API. - Email:
GET /api/v1/partner/email/emails/:message_id.
When an account removes your app, your next call gets 401 invalid_token and your next refresh gets invalid_grant. That is how you learn about it.
Billing
Every message your app sends is charged to the connected account exactly like a message sent with its own API key: from its wallet at its normal rates (or its credit limit for postpaid Email accounts). Nothing is charged to you. Messages your app sends show Connected app in the account's inbox.
Plan rule (WhatsApp)
A WhatsApp account can use the API only while its plan includes API access, and your app's calls share the account's per-minute API limit with its own API key. When the plan does not allow it, your calls get the same 403 answers the account's API key would get. See Limits and errors.
IP allowlist
If the account only accepts API calls from its allowed IP addresses, your app's calls must come from one of them, the same as for its API key. List your server IP addresses in your app's Settings tab: we show them to customers on the consent screen so they can add them. Calls from other addresses get 403 ip_blocked. For Email apps, calls from IPv6 addresses are refused when the account has an allowlist.
401 or 403?
- 401 means the token itself is no good: expired, revoked, removed by the account, or the app is suspended. Refresh, or ask the user to connect again.
- 403 means the token is fine but this call is not allowed: a missing permission, an endpoint outside the list, bulk sending from an unverified app, the account's plan, the IP allowlist, or an account that is not active.
Every answer is listed in Limits and errors.