The WhatsApp Business API is not just an outbound messaging channel — it's a two-way communication platform. When a customer sends a message, an event fires. When a message is delivered, another event fires. When a template is approved or rejected, you get notified. All of this happens through webhooks — and understanding how they work is essential for building any real-time WhatsApp automation on top of WasapFlow Bridge.
A webhook is an HTTP callback. When a specific event occurs — like a WhatsApp message being received — the API sends an HTTP POST request to a URL you've configured in advance. Your server receives the JSON payload, processes it, and responds.
Unlike polling (where your server asks the API every N seconds "any new messages?"), webhooks are event-driven. Events arrive in real time — typically within 1–2 seconds of the trigger. This makes webhooks the only practical approach for building responsive chatbots, live inbox UIs, or instant notification systems.
WasapFlow Bridge acts as a relay between Meta's Cloud API and your application. When Meta fires a webhook event to our system, we forward it to your configured webhook URL within milliseconds — with a consistent, normalized payload format across all event types.
Our webhooks include an HMAC-SHA256 signature in the X-Hub-Signature-256 header. This allows your backend to verify that the payload genuinely came from WasapFlow and hasn't been tampered with in transit. Always verify this signature before processing any incoming webhook payload.
Your webhook endpoint must respond with HTTP 200 within 20 seconds. If it doesn't, the delivery will be retried. Build your handler to respond quickly and do heavy processing asynchronously — receive the event, push it to a queue, return 200, then process from the queue.
Make your handler idempotent — Meta may occasionally deliver the same event more than once due to retries. Use the message_id field as a deduplication key and skip reprocessing events you've already handled.
For local development, use a tunneling tool like ngrok or Cloudflare Tunnel to expose your local server for webhook testing before deploying to production.
Always verify the X-Hub-Signature-256 header before processing any webhook payload. An unverified endpoint can be exploited by anyone who discovers your URL. WasapFlow Bridge makes this easy — each partner gets a unique webhook secret used for HMAC signing. Never hardcode this secret in client-side code or commit it to a public repository.
Create a free partner account today. 20-day trial, no credit card required.