curl --request POST \
--url https://app.thinnest.ai/api/v1/codes \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"to": "+91 98123 45678",
"code": "394812"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({to: '+91 98123 45678', code: '394812'})
};
fetch('https://app.thinnest.ai/api/v1/codes', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/codes"
payload = {
"to": "+91 98123 45678",
"code": "394812"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"sent": true,
"to": "919812345678",
"template": "login_code",
"language": "en",
"messageRef": "wamid.HBgMOTE5ODEyMzQ1Njc4FQIAERgSNEQ3QTlFMkI1QzFGOEQ2MEEA"
}Send One-Time Code
Sends a code you generated to a WhatsApp number, using your approved authentication template — the code goes into the message and the copy-code button. We do not generate, store, expire or check the code; that stays yours. One number may be sent at most 5 codes in 10 minutes, and the workspace at most 120 sends a minute (codes keep the top of the budget it shares with Send Message). Each code is charged at WhatsApp’s authentication rate, which is far higher for numbers abroad. Needs a full key.
curl --request POST \
--url https://app.thinnest.ai/api/v1/codes \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"to": "+91 98123 45678",
"code": "394812"
}
'const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({to: '+91 98123 45678', code: '394812'})
};
fetch('https://app.thinnest.ai/api/v1/codes', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://app.thinnest.ai/api/v1/codes"
payload = {
"to": "+91 98123 45678",
"code": "394812"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"sent": true,
"to": "919812345678",
"template": "login_code",
"language": "en",
"messageRef": "wamid.HBgMOTE5ODEyMzQ1Njc4FQIAERgSNEQ3QTlFMkI1QzFGOEQ2MEEA"
}Authorizations
Your API key (ta_live_…) from Settings → API keys, sent as Authorization: Bearer <key>. Keep it on a server: it can message every customer you have. A key is full, build or read-only; a request its level does not allow is refused with 403.
Headers
Any unique string. A retry with the same key within 24 hours returns the first request's answer instead of acting twice.
255Developers only: the customer workspace this request acts in — its org_… id from POST /customers. Leave it out to act in your own workspace.
"org_3fKq9TzQ1mN8vB2xR7cLpA"
Body
The number to send the code to. Include the + and the country code (a leading 00 works too). Without a +, a number of ten digits or fewer — or one starting with 0 — is read as an Indian number and 91 is added.
"+91 98123 45678"
The code you generated, 16 characters at most after trimming.
1 - 16"394812"
Which approved authentication template, by name. Needed only when you have more than one.
"login_code"
Which approved language version, exactly as approved — en, hi. Needed only when one template name is approved in several languages.
"en"
Same as the Idempotency-Key header, for clients that cannot set headers. The header wins when both are sent.
Response
WhatsApp accepted the code. A replay of an Idempotency-Key returns the first answer, whatever it was, with an Idempotent-Replayed: true header.
WhatsApp accepted the code.
The number it went to, digits only with the country code.
The template it was sent with.
The language version it was sent in.
WhatsApp's receipt for the message.