curl --request POST \
--url https://app.thinnest.ai/api/v1/codes/templates \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "login_code",
"language": "en",
"expiryMinutes": 10,
"securityRecommendation": true,
"button": "copy_code"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'login_code',
language: 'en',
expiryMinutes: 10,
securityRecommendation: true,
button: 'copy_code'
})
};
fetch('https://app.thinnest.ai/api/v1/codes/templates', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/codes/templates"
payload = {
"name": "login_code",
"language": "en",
"expiryMinutes": 10,
"securityRecommendation": True,
"button": "copy_code"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "5e1d8c3b-7a2f-4d96-b4e0-9c6a2f1d8e73",
"name": "login_code",
"language": "en",
"status": "draft",
"reviewNote": null,
"settings": {
"expiryMinutes": 10,
"securityRecommendation": true,
"button": "copy_code",
"apps": []
},
"preview": {
"body": "*123456* is your verification code. For your security, do not share this code.",
"footer": "Expires in 10 minutes."
},
"agent": "ag_2c7e9a14-5b3d-4f8e-a1c6-7d9b0e3f5a21",
"createdAt": "2026-10-06T10:02:17.904Z"
}{
"error": "Meta allows an expiry between 1 and 90 minutes."
}{
"error": "Send a valid API key as `Authorization: Bearer <key>`."
}{
"error": "One-time codes need a plan with WhatsApp. Pay as you go has no monthly fee."
}{
"error": "A template with that name and language already exists."
}{
"error": "Over 240 requests a minute. Slow down and retry."
}Create Code Template
Saves an authentication template as a draft. WhatsApp writes the words; you choose how long the code lasts, whether to add “For your security, do not share this code.”, and the button — copy_code (works everywhere) or one_tap (hands the code to your Android app, which needs apps). Nothing is sent to WhatsApp until Submit Code Template. A build key may do this.
curl --request POST \
--url https://app.thinnest.ai/api/v1/codes/templates \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "login_code",
"language": "en",
"expiryMinutes": 10,
"securityRecommendation": true,
"button": "copy_code"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'login_code',
language: 'en',
expiryMinutes: 10,
securityRecommendation: true,
button: 'copy_code'
})
};
fetch('https://app.thinnest.ai/api/v1/codes/templates', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/codes/templates"
payload = {
"name": "login_code",
"language": "en",
"expiryMinutes": 10,
"securityRecommendation": True,
"button": "copy_code"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"id": "5e1d8c3b-7a2f-4d96-b4e0-9c6a2f1d8e73",
"name": "login_code",
"language": "en",
"status": "draft",
"reviewNote": null,
"settings": {
"expiryMinutes": 10,
"securityRecommendation": true,
"button": "copy_code",
"apps": []
},
"preview": {
"body": "*123456* is your verification code. For your security, do not share this code.",
"footer": "Expires in 10 minutes."
},
"agent": "ag_2c7e9a14-5b3d-4f8e-a1c6-7d9b0e3f5a21",
"createdAt": "2026-10-06T10:02:17.904Z"
}{
"error": "Meta allows an expiry between 1 and 90 minutes."
}{
"error": "Send a valid API key as `Authorization: Bearer <key>`."
}{
"error": "One-time codes need a plan with WhatsApp. Pay as you go has no monthly fee."
}{
"error": "A template with that name and language already exists."
}{
"error": "Over 240 requests a minute. Slow down and retry."
}Authorizations
Your API key (ta_live_…) from Settings → API keys, sent as Authorization: Bearer <key>. Keep it on a server: it can message every customer you have. A key is full, build or read-only; a request its level does not allow is refused with 403.
Headers
Developers only: the customer workspace this request acts in — its org_… id from POST /customers. Leave it out to act in your own workspace.
"org_3fKq9TzQ1mN8vB2xR7cLpA"
Body
Lowercase letters, digits and underscores, as WhatsApp allows. Unique with language.
512^[a-z0-9_]{1,512}$"login_code"
A WhatsApp template language code.
en, hi, mr, bn, ta, te, kn, ml, gu, pa, ur, ar, es, pt_BR, fr, de, it, nl, ru, tr, id, ms, th, vi, fil, ja, ko, zh_CN, zh_TW, he, sw, en_GB, en_US "en"
How long the code lasts. WhatsApp shows it to the customer in their own language.
1 <= x <= 9010
Adds "For your security, do not share this code."
true
copy_code: the customer taps to copy, then pastes — works everywhere. one_tap: hands the code straight to your Android app; needs apps.
copy_code, one_tap "copy_code"
Required for one_tap: the Android apps the code may be handed to. Ignored for copy_code.
Show child attributes
Show child attributes
Response
The draft.
The template's id (a bare uuid).
The template's name — what template on Send One-Time Code takes.
Its language code.
draft: yours to change. pending: with WhatsApp for review. approved: sends. rejected: see reviewNote. paused: WhatsApp paused it.
draft, pending, approved, rejected, paused WhatsApp's reason, when it gave one.
The three choices. Null only for a template saved before these settings existed.
Show child attributes
Show child attributes
What the customer reads, in WhatsApp's words, with a sample code.
Show child attributes
Show child attributes
The agent the template belongs to (ag_…).
When it was created.