GraphQL API

Overview

Endpoint, request shape, conventions, pagination, and the complete operation index by scope

One endpoint serves everything.

EndpointPOST https://<your-wexio-host>/graphql
Content typeapplication/json
AuthAuthorization: Bearer wx_<keyId>_<secret>, optionally X-Wexio-Org for a managed child

These are the same operations the dashboard calls. There is no parallel machine-only API - a key is just another principal, gated by scopes.

Request and Response

curl https://<your-wexio-host>/graphql \
  -H "Authorization: Bearer wx_9f3c1a2b4d5e6f70_kQ8s..." \
  -H "Content-Type: application/json" \
  -d '{
    "query": "mutation($id: String!, $in: CreateCombinedMessageInput!) { sendMessage(chatId: $id, input: $in) { _id deliveryStatus } }",
    "variables": { "id": "6804f4c2a6f9f35f6e66f1a1", "in": { "text": "On its way 🍕" } }
  }'

Responses follow the GraphQL spec: a data object, plus an errors array when something failed. Auth and scope failures surface as HTTP status codes - see Errors.

Conventions

ConventionDetail
Entity IDsEntities expose _id, not id. Values are 24-character hex strings. Newer API-specific types (OrgApiKeyOutput, ContactApi, OrgTeamMember) use id.
ID argumentsMostly String! (chatId, messageId, keyId); some newer ones are ID! (contactApi(id:), the webhook mutations). Both accept the same hex string.
DateTimeISO-8601 UTC string, e.g. "2026-10-01T18:00:00.000Z".
JSONArbitrary JSON value. Used for filter and field values.
NullabilityA field without ! can be null - unset, or masked because the key lacks PII_READ.
Internal notesInvisible unless the key holds NOTES_WRITE.

Pagination

Cursor-based. Two input shapes, and they differ in the name of the direction flag - the most common source of confusion.

InputUsed byFields
PaginateMessagesInputmessage reads, notes, searchcursor: String, isBefore: Boolean, limit: Int! = 30
GetCursorPaginatedInputsearchConversationscursor: String, limit: Int = 20, before: Boolean = false
ContactApiPaginationInputcontactsApifirst: Int = 20, after: ID
offset argsHelp and News readslimit: Int, offset: Int

Four conventions coexist, and they are not interchangeable: cursor with isBefore, cursor with before, first/after, and plain limit/offset. Check the operation's own signature rather than assuming.

Cursors come back on the result, with no pageInfo wrapper:

{
  data { … }
  nextCursor
  previousCursor
  hasNext
  hasPrevious
}

Page forward by passing nextCursor as cursor while hasNext is true. SearchConversationsResult also returns totalCount, but only on the first page.

Operation Index

Every key-callable operation, grouped by the scope it requires.

MESSAGES_READ

OperationKindPurpose
searchConversations / searchChats / conversation / chat / threadsPageQueryThe inbox and individual threads. Search variants are expensive
conversationMessagesQueryMessages of a conversation
getMessagesQueryMessages of one chat thread
apiSearchMessagesQuerySearch messages across the org
apiSearchChatMessagesQuerySearch within one chat
conversationMedia / getChatMediaQueryMedia in a conversation / chat
conversationMediaCounts / getChatMediaCountsQueryMedia counts by type
allMediaQueryMedia library
chatCollections / chatCollection / collectionChats / collectionChatCount / collectionConversationsQueryCollections
inboxCounts / chatCollectionCountsQueryCounts. Expensive
labels / activeLabels / labelQueryLabels

See Reading the inbox.

MESSAGES_SEND

OperationKindPurpose
sendMessageMutationSend any message type into a chat
updateMessageMutationEdit a sent message
deleteMessageMutationDelete a message
addMessageReaction / removeMessageReactionMutationReactions
createMedia / uploadMultipleMedia / deleteMediaMutationMedia upload and removal
sendWhatsAppTemplateMessageMutationSend an approved WhatsApp template
retryFailedMessageMutationRetry one failed outbound message

See Messaging.

CONVERSATIONS_MANAGE

OperationKindPurpose
readMessages / readAllMessagesMutationMark read
closeChat / reopenChatMutationClose and reopen
assignChatToOperator / unassignChat / assignConversationThreadsMutationAssignment
blockConversationMutationBlock and unblock
setConversationAiMutationToggle the AI assistant
updateChatFieldMutationStatus, priority, category and other chat fields
apiCreateChatCollection / apiUpdateChatCollection / apiMoveChatCollection / apiDeleteChatCollectionMutationCollections
createLabel / updateLabel / archiveLabel / restoreLabel / setMessageLabelsMutationLabels
readAllConversationMutationMark a whole conversation read
apiStartFlowForChat / apiStopFlowForChatMutationStart or stop a published flow in a chat

See Managing the inbox.

CONTACTS_READ, CONTACTS_MANAGE and CONTACTS_ERASE

OperationKindScope
contactApi / contactsApi / contactApiByExternalIdQueryCONTACTS_READ
getPeopleFieldDefinitions / getPeopleFieldValue / getPeopleFieldValuesQueryCONTACTS_READ
isWhatsAppIdEditableQueryCONTACTS_READ
createContactApi / updateContactApi / upsertContactApiMutationCONTACTS_MANAGE
createPeopleFieldDefinition / updatePeopleFieldDefinition / deletePeopleFieldDefinitionMutationCONTACTS_MANAGE
setPeopleFieldValue / deletePeopleFieldValueMutationCONTACTS_MANAGE
previewEraseQueryCONTACTS_ERASE
eraseContactMutationCONTACTS_ERASE

See Contacts.

CHANNELS_MANAGE

OperationKindPurpose
channelsQueryList connected integrations
pauseChannel / resumeChannel / updateChannelMutationPause, resume, rename, set AI auto-reply
channelTelegramBotSettings + the 7 Telegram bot mutationsQuery / MutationTelegram bot settings
createWhatsAppTemplate / updateWhatsAppTemplate / deleteWhatsAppTemplateMutationTemplate CRUD
connectTelegramChannel / connectViberChannelMutationConnect with a bot token
partnerChannelConnectUrlMutationHosted connect URL for WhatsApp / Instagram
connectWhatsAppChannel / connectInstagramChannelMutationConnect with your own Meta credentials
disconnectChannelMutationDisconnect
webIntegration / webIntegrationByIdQueryRead the web widget
createWebIntegration / updateWebIntegration / rotateWebIntegrationSecret / deleteWebIntegrationMutationManage the web widget
whatsAppTemplates / whatsAppTemplateQueryRead approved templates
syncWhatsAppTemplatesMutationRe-sync templates from Meta

See Channels.

CONVERSATIONS_DELETE

Irreversible, and not implied by CONVERSATIONS_MANAGE.

OperationKindPurpose
apiDeleteChatMutationDelete one thread with its messages and media
apiDeleteConversationMutationDelete a conversation. removePeople: true additionally needs CONTACTS_ERASE

See deleting.

NOTES_WRITE

OperationKindPurpose
getChatNotes / conversationNotesQueryRead internal notes
sendConversationNoteMutationPost an internal note on a conversation

Posting a note is sendMessage with internal: true - also gated by this scope.

TEAM_READ and TEAM_MANAGE

OperationKindScope
orgTeamMembersQueryTEAM_READ
addOrgMemberDirect / updateOrgMemberRole / removeOrgMemberMutationTEAM_MANAGE

See Team.

CONTENT_READ and CONTENT_MANAGE

AreaRead (CONTENT_READ)Manage (CONTENT_MANAGE)
Help articleshelpArticles, helpArticlecreateHelpArticle, updateHelpArticle, createHelpArticleTranslation, publishHelpArticle, unpublishHelpArticle, deleteHelpArticle
Help foldershelpFolders, helpFolder, helpFolderTree, helpFolderCounts, helpFolderCountsBatchcreateHelpFolder, updateHelpFolder, moveHelpFolder, deleteHelpFolder
Help tagshelpTags, helpTagcreateHelpTag, updateHelpTag, deleteHelpTag
News postsnewsPosts, newsPostcreateNewsPost, updateNewsPost, createNewsPostTranslation, publishNewsPost, scheduleNewsPost, unpublishNewsPost, archiveNewsPost, deleteNewsPost
News taxonomynewsCategories, newsCategory, newsTags, newsTagcreateNewsCategory, updateNewsCategory, deleteNewsCategory, createNewsTag, updateNewsTag, deleteNewsTag

See Content.

PARTNER_ADMIN

Tech provider orgs only (kind TECH_PROVIDER). Unlocks nothing on any other org's key.

OperationKindPurpose
createClientOrg / clientOrgs / deprovisionClientOrgMutation / QueryProvision and tear down client orgs - Client orgs
registerPartnerWebhook / partnerWebhooks / rotatePartnerWebhookSecret / setPartnerWebhookEvents / setPartnerWebhookStatus / deletePartnerWebhookMutation / QueryThe fan-out webhook - Webhook subscriptions
partnerUsageSummary / partnerUsageHistoryQueryUsage rollup and month-by-month history - Usage

Each of these accepts an API key with PARTNER_ADMIN or a member login on the provider org.

Dashboard Only

Not callable with a key, by design:

OperationWhy
mintOrgApiKey / orgApiKeys / revokeOrgApiKeyA leaked key must not mint another, or widen its own scopes - API keys

Not Available to Keys

Broadcasts, flow authoring, social comment and post moderation, creating or updating WhatsApp templates, GraphQL subscriptions, minting keys, and creating ADMIN/OWNER members. See Limitations for the full list and the workarounds.

On this page