---
title: Wapiworld developer platform
description: REST API, OAuth MCP, CLI, Agent Skills, webhook operations, and safety contract.
canonical: https://app.wapiworld.com/developers/
last-updated: 2026-08-25
---

# Wapiworld developer platform

Build tenant-scoped WhatsApp sender workflows with the REST API, the public npm CLI, or the OAuth-protected Streamable HTTP MCP at https://mcp.wapiworld.com/mcp.

## Developer resources

- [Developer page](https://app.wapiworld.com/developers/)
- [OpenAPI specification](https://app.wapiworld.com/openapi.json)
- [Authentication guide](https://app.wapiworld.com/auth.md)
- [MCP server card](https://app.wapiworld.com/.well-known/mcp/server-card.json)
- [Agent Skills index](https://app.wapiworld.com/.well-known/agent-skills/index.json)
- [AI Catalog](https://app.wapiworld.com/.well-known/ai-catalog.json)
- [CLI package](https://www.npmjs.com/package/wapiworld)
- [Public CLI source](https://github.com/wapiworld/cli)
- [Public Agent Skills source](https://github.com/wapiworld/skills)
- [Public Claude plugin source](https://github.com/wapiworld/claude-plugin)

## MCP tools

- `list_projects` — List a bounded page of tenant-scoped Wapiworld projects.
- `list_instances` — List safe WhatsApp sender summaries without secrets or QR pairing data.
- `get_instance` — Fetch safe operational details for one WhatsApp sender.
- `get_instance_status` — Check one sender connection without authentication data.
- `get_message_recording_policy` — Inspect default recording and retention policy without reading messages.
- `list_webhook_subscriptions` — List sanitized webhook configuration and delivery health for an OAuth operator.
- `send_message` — Send one explicitly confirmed WhatsApp text; non-idempotent and never automatically retried.

## Authentication

REST API keys use HTTP Basic authentication and are pinned to one project with per-resource scopes. The MCP uses OAuth 2.0 with `wapiworld:read` and a separate `wapiworld:write` scope. Begin read-only and request write only for a deliberate send.

## Safety boundary

The public MCP never returns recorded message bodies, previews, sender names, contact or chat identifiers, WhatsApp message identifiers, QR pairing data, API keys, instance secrets, proxy credentials, webhook signing secrets, complete webhook URLs, or raw provider errors.

`send_message` is destructive, open-world, and non-idempotent. Show the exact sender, recipient, and complete text; warn that recording settings may persist the text; obtain explicit confirmation for exactly one send; call once; and never automatically retry an uncertain outcome. Transport acceptance is not proof of delivery or reading.
