curl -X POST "https://api.bulkneo.com/v1/messages/document" -H "apikey: YOUR_API_KEY" -H "Content-Type: application/json" -d "{\"instance_id\":\"3f9c1a2b-7d4e-4c81-9f0a-2b6d5e8c1a34\",\"to\":\"919000000000\",\"url\":\"https://example.com/invoice-2043.pdf\",\"filename\":\"invoice-2043.pdf\",\"caption\":\"April invoice\"}"const options = {
method: 'POST',
headers: {apikey: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
instance_id: '3f9c1a2b-7d4e-4c81-9f0a-2b6d5e8c1a34',
to: '919000000000',
url: 'https://example.com/invoice-2043.pdf',
filename: 'invoice-2043.pdf',
caption: 'April invoice'
})
};
fetch('https://api.bulkneo.com/v1/messages/document', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.bulkneo.com/v1/messages/document"
payload = {
"instance_id": "3f9c1a2b-7d4e-4c81-9f0a-2b6d5e8c1a34",
"to": "919000000000",
"url": "https://example.com/invoice-2043.pdf",
"filename": "invoice-2043.pdf",
"caption": "April invoice"
}
headers = {
"apikey": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"success": true,
"data": {
"instance_id": "3f9c1a2b-7d4e-4c81-9f0a-2b6d5e8c1a34",
"to": "919000000000",
"type": "document",
"status": "sent",
"message_id": "3EB0C1D2F4A5B6C7D8E9",
"provider_status": "PENDING"
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "invalid_request",
"message": "Field \"text\" is required and must be a non-empty string."
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "invalid_api_key",
"message": "Invalid or revoked API key."
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "subscription_expired",
"message": "Your subscription has expired. Renew it to continue sending messages."
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "trial_quota_exceeded",
"message": "Trial message quota reached (500 messages). Upgrade to a paid plan to keep sending.",
"details": {
"trial_message_limit": 500
}
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "instance_not_found",
"message": "Instance not found. Check the instance_id and that it belongs to your account."
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "instance_not_connected",
"message": "This WhatsApp instance is not connected. Connect it before sending messages."
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "media_fetch_failed",
"message": "The media at that URL could not be downloaded. Check the link is public, direct, and still valid."
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "rate_limit_exceeded",
"message": "Rate limit exceeded, retry in 12s.",
"details": {
"retry_after_seconds": 12,
"limit_per_minute": 20,
"scope": "messages"
}
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "internal_error",
"message": "An unexpected error occurred."
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "upstream_unavailable",
"message": "The messaging service is temporarily unavailable. Please retry shortly."
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}Send a document
POST /v1/messages/document — any file, sent as an attachment.
curl -X POST "https://api.bulkneo.com/v1/messages/document" -H "apikey: YOUR_API_KEY" -H "Content-Type: application/json" -d "{\"instance_id\":\"3f9c1a2b-7d4e-4c81-9f0a-2b6d5e8c1a34\",\"to\":\"919000000000\",\"url\":\"https://example.com/invoice-2043.pdf\",\"filename\":\"invoice-2043.pdf\",\"caption\":\"April invoice\"}"const options = {
method: 'POST',
headers: {apikey: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
instance_id: '3f9c1a2b-7d4e-4c81-9f0a-2b6d5e8c1a34',
to: '919000000000',
url: 'https://example.com/invoice-2043.pdf',
filename: 'invoice-2043.pdf',
caption: 'April invoice'
})
};
fetch('https://api.bulkneo.com/v1/messages/document', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://api.bulkneo.com/v1/messages/document"
payload = {
"instance_id": "3f9c1a2b-7d4e-4c81-9f0a-2b6d5e8c1a34",
"to": "919000000000",
"url": "https://example.com/invoice-2043.pdf",
"filename": "invoice-2043.pdf",
"caption": "April invoice"
}
headers = {
"apikey": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text){
"success": true,
"data": {
"instance_id": "3f9c1a2b-7d4e-4c81-9f0a-2b6d5e8c1a34",
"to": "919000000000",
"type": "document",
"status": "sent",
"message_id": "3EB0C1D2F4A5B6C7D8E9",
"provider_status": "PENDING"
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "invalid_request",
"message": "Field \"text\" is required and must be a non-empty string."
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "invalid_api_key",
"message": "Invalid or revoked API key."
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "subscription_expired",
"message": "Your subscription has expired. Renew it to continue sending messages."
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "trial_quota_exceeded",
"message": "Trial message quota reached (500 messages). Upgrade to a paid plan to keep sending.",
"details": {
"trial_message_limit": 500
}
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "instance_not_found",
"message": "Instance not found. Check the instance_id and that it belongs to your account."
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "instance_not_connected",
"message": "This WhatsApp instance is not connected. Connect it before sending messages."
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "media_fetch_failed",
"message": "The media at that URL could not be downloaded. Check the link is public, direct, and still valid."
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "rate_limit_exceeded",
"message": "Rate limit exceeded, retry in 12s.",
"details": {
"retry_after_seconds": 12,
"limit_per_minute": 20,
"scope": "messages"
}
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "internal_error",
"message": "An unexpected error occurred."
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}{
"success": false,
"error": {
"code": "upstream_unavailable",
"message": "The messaging service is temporarily unavailable. Please retry shortly."
},
"request_id": "b1f2c3d4-5e6f-4a7b-8c9d-0e1f2a3b4c5d"
}https://api.bulkneo.com — a send delivers a real WhatsApp message to the number you type, and an instance call really changes your account. Use your own number while you are exploring, and paste a key only from a machine you trust.Your browser remembers what you type into the playground, so a key you paste here is still in the Authorization box on your next visit. Nobody else sees it — it never leaves your machine and it is not part of this site — but on a shared or borrowed computer, clear the site data when you are done.https://www.w3.org/WAI/ER/tests/xhtml/testfiles/resources/pdf/dummy.pdf — a small public test PDF published by the W3C. It proves the whole path works before you host anything of your own. See Sending media.Notes
- Set
filename. It is the name the recipient sees and the name they get if they save the file. Without it the name is taken from the link, which is often something likedownload.phpor a long signed-URL blob. filenameis capped at 255 characters. Slashes (/and\) and control characters are rejected, as are.and..on their own. Nothing is silently rewritten — an unsafe name comes back as400 invalid_request.captionis shown with the file and capped at 1,024 characters.mime_typeis an optional hint such asapplication/pdf.
Example — an invoice
curl -X POST https://api.bulkneo.com/v1/messages/document \
-H "apikey: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"instance_id": "YOUR_INSTANCE_ID",
"to": "919000000000",
"url": "https://example.com/files/inv-2043.pdf",
"filename": "Invoice-2043.pdf",
"caption": "April invoice — due 15 May"
}'
curl -X POST "https://api.bulkneo.com/v1/messages/document" -H "apikey: YOUR_API_KEY" -H "Content-Type: application/json" -d "{\"instance_id\":\"YOUR_INSTANCE_ID\",\"to\":\"919000000000\",\"url\":\"https://example.com/files/inv-2043.pdf\",\"filename\":\"Invoice-2043.pdf\",\"caption\":\"April invoice — due 15 May\"}"
const res = await fetch("https://api.bulkneo.com/v1/messages/document", {
method: "POST",
headers: {
apikey: process.env.BULKNEO_API_KEY,
"Content-Type": "application/json",
},
body: JSON.stringify({
instance_id: process.env.BULKNEO_INSTANCE_ID,
to: "919000000000",
url: `https://example.com/files/inv-${invoiceNo}.pdf`,
filename: `Invoice-${invoiceNo}.pdf`,
caption: "April invoice — due 15 May",
}),
});
const body = await res.json();
if (!res.ok) throw new Error(`${body.error.code}: ${body.error.message}`);
import os
import requests
res = requests.post(
"https://api.bulkneo.com/v1/messages/document",
headers={"apikey": os.environ["BULKNEO_API_KEY"]},
json={
"instance_id": os.environ["BULKNEO_INSTANCE_ID"],
"to": "919000000000",
"url": f"https://example.com/files/inv-{invoice_no}.pdf",
"filename": f"Invoice-{invoice_no}.pdf",
"caption": "April invoice — due 15 May",
},
timeout=30,
)
res.raise_for_status()
422 media_fetch_failed.Authorizations
Your API key, sent in an apikey request header. Never in the URL, never as a Bearer token.
Headers
OPTIONAL. A unique string you choose, 8-255 characters of letters, digits or . _ : ~ -
Send the same key with the same body again within 24 hours and the ORIGINAL result is returned without sending a second message — which is what makes a network retry safe. A different body on the same key is refused with 422 idempotency_key_reused rather than silently overwriting either result.
Responses carry Idempotency-Replayed: true|false while this is active. If that header is ABSENT, idempotency is not enabled on this deployment and retries will send again.
8 - 255^[A-Za-z0-9._:~-]{8,255}$Body
Which of your connected numbers to send FROM. Copy it from your numbers screen in the portal, or from GET /v1/instances. It must belong to your account.
"3f9c1a2b-7d4e-4c81-9f0a-2b6d5e8c1a34"
The recipient, with country code and no leading zero — for example 919000000000. Spaces, dashes, brackets and a leading + are accepted and stripped; 6 to 15 digits must remain.
"919000000000"
A public http(s) link to the file. There is no upload endpoint — we fetch the file from this link, so it must be reachable from the internet and be a direct link to the file itself, not a preview or share page. Private, internal and loopback addresses are refused, as are links containing a username or password.
2048"https://example.com/receipt-2043.png"
The name the recipient sees, for example invoice-2043.pdf. Up to 255 characters. Slashes and control characters are rejected, as are . and ... If you omit it, the name is taken from the link.
255"invoice-2043.pdf"
Text shown with the file. Up to 1,024 characters.
1024"Your receipt"
Optional content-type hint such as application/pdf. It is checked for the shape type/subtype only — we do not verify it matches the file. Usually you can leave it out.
128"application/pdf"
Send this message as a reply, quoting an earlier one. Use the data.message_id returned by a previous send.
128"3EB0C1D2F4A5B6C7D8E9"
Set true when the quoted message is one you sent from this number. Only valid together with quoted_message_id.

