MAILRAFT

MAILRAFT / DOCS V1

Webhooks

The API implements GET and POST /webhooks/integrations/:id. A concrete URL is issued only after the operator binds the integration to your company. Unbound requests are denied, never silently acknowledged.

WhatsApp verifies the GET challenge and signs POST bodies with the app secret. Bodies are limited to 256 KiB; account/phone routing, timestamp bounds, durable replay detection and sanitized audits are enforced. Keep the verify token out of logs and support messages.