Skip to main content
POST
cURL (Windows)
The playground on this page is live. There is no test mode and no sandbox: pressing Send authenticates with the key you paste and really calls https://api.bulkneo.com — a send delivers a real WhatsApp message to the number you type, and an instance call really changes your account. Use your own number while you are exploring, and paste a key only from a machine you trust.Your browser remembers what you type into the playground, so a key you paste here is still in the Authorization box on your next visit. Nobody else sees it — it never leaves your machine and it is not part of this site — but on a shared or borrowed computer, clear the site data when you are done.
Hand someone your support desk’s number, or your delivery agent’s, as a card they can tap to call or save.

Notes

  • contacts takes 1 to 10 cards in one message.
  • full_name and phone_number are required on every card.
  • phone_number must include the country code — at least 10 digits after spaces, dashes and brackets are stripped. A shorter number is rejected with 400 invalid_request.
  • organization, email and url are optional extras shown on the card.
  • email must look like an address — something, an @, and a domain containing a dot, with no spaces. not-an-email is refused with 400 invalid_request rather than shipped as a card the recipient cannot use.
  • url must be a full http(s) link. A bare domain like example.com is refused, as is any URL carrying a username or password. Send https://example.com, not example.com.

Example

Authorizations

apikey
string
header
required

Your API key, sent in an apikey request header. Never in the URL, never as a Bearer token.

Headers

Idempotency-Key
string

OPTIONAL. A unique string you choose, 8-255 characters of letters, digits or . _ : ~ -

Send the same key with the same body again within 24 hours and the ORIGINAL result is returned without sending a second message — which is what makes a network retry safe. A different body on the same key is refused with 422 idempotency_key_reused rather than silently overwriting either result.

Responses carry Idempotency-Replayed: true|false while this is active. If that header is ABSENT, idempotency is not enabled on this deployment and retries will send again.

Required string length: 8 - 255
Pattern: ^[A-Za-z0-9._:~-]{8,255}$

Body

application/json
instance_id
string<uuid>
required

Which of your connected numbers to send FROM. Copy it from your numbers screen in the portal, or from GET /v1/instances. It must belong to your account.

Example:

"3f9c1a2b-7d4e-4c81-9f0a-2b6d5e8c1a34"

to
string
required

The recipient, with country code and no leading zero — for example 919000000000. Spaces, dashes, brackets and a leading + are accepted and stripped; 6 to 15 digits must remain.

Example:

"919000000000"

contacts
object[]
required

1 to 10 contact cards.

Required array length: 1 - 10 elements
quoted_message_id
string

Send this message as a reply, quoting an earlier one. Use the data.message_id returned by a previous send.

Maximum string length: 128
Example:

"3EB0C1D2F4A5B6C7D8E9"

quoted_from_me
boolean
default:false

Set true when the quoted message is one you sent from this number. Only valid together with quoted_message_id.

Response

Accepted for delivery. data.type is always contact on this endpoint.

success
boolean
data
object
request_id
string<uuid>