Overview
Endpoint, request shape, conventions, pagination, and the complete operation index by scope
One endpoint serves everything.
| Endpoint | POST https://<your-wexio-host>/graphql |
| Content type | application/json |
| Auth | Authorization: Bearer wx_<keyId>_<secret>, optionally X-Wexio-Org for a managed child |
These are the same operations the dashboard calls. There is no parallel machine-only API - a key is just another principal, gated by scopes.
Request and Response
curl https://<your-wexio-host>/graphql \
-H "Authorization: Bearer wx_9f3c1a2b4d5e6f70_kQ8s..." \
-H "Content-Type: application/json" \
-d '{
"query": "mutation($id: String!, $in: CreateCombinedMessageInput!) { sendMessage(chatId: $id, input: $in) { _id deliveryStatus } }",
"variables": { "id": "6804f4c2a6f9f35f6e66f1a1", "in": { "text": "On its way 🍕" } }
}'Responses follow the GraphQL spec: a data object, plus an errors array when something failed. Auth and scope failures surface as HTTP status codes - see Errors.
Conventions
| Convention | Detail |
|---|---|
| Entity IDs | Entities expose _id, not id. Values are 24-character hex strings. Newer API-specific types (OrgApiKeyOutput, ContactApi, OrgTeamMember) use id. |
| ID arguments | Mostly String! (chatId, messageId, keyId); some newer ones are ID! (contactApi(id:), the webhook mutations). Both accept the same hex string. |
DateTime | ISO-8601 UTC string, e.g. "2026-10-01T18:00:00.000Z". |
JSON | Arbitrary JSON value. Used for filter and field values. |
| Nullability | A field without ! can be null - unset, or masked because the key lacks PII_READ. |
| Internal notes | Invisible unless the key holds NOTES_WRITE. |
Pagination
Cursor-based. Two input shapes, and they differ in the name of the direction flag - the most common source of confusion.
| Input | Used by | Fields |
|---|---|---|
PaginateMessagesInput | message reads, notes, search | cursor: String, isBefore: Boolean, limit: Int! = 30 |
GetCursorPaginatedInput | searchConversations | cursor: String, limit: Int = 20, before: Boolean = false |
ContactApiPaginationInput | contactsApi | first: Int = 20, after: ID |
| offset args | Help and News reads | limit: Int, offset: Int |
Four conventions coexist, and they are not interchangeable: cursor with isBefore, cursor with before, first/after, and plain limit/offset. Check the operation's own signature rather than assuming.
Cursors come back on the result, with no pageInfo wrapper:
{
data { … }
nextCursor
previousCursor
hasNext
hasPrevious
}Page forward by passing nextCursor as cursor while hasNext is true. SearchConversationsResult also returns totalCount, but only on the first page.
Operation Index
Every key-callable operation, grouped by the scope it requires.
MESSAGES_READ
| Operation | Kind | Purpose |
|---|---|---|
searchConversations / searchChats / conversation / chat / threadsPage | Query | The inbox and individual threads. Search variants are expensive |
conversationMessages | Query | Messages of a conversation |
getMessages | Query | Messages of one chat thread |
apiSearchMessages | Query | Search messages across the org |
apiSearchChatMessages | Query | Search within one chat |
conversationMedia / getChatMedia | Query | Media in a conversation / chat |
conversationMediaCounts / getChatMediaCounts | Query | Media counts by type |
allMedia | Query | Media library |
chatCollections / chatCollection / collectionChats / collectionChatCount / collectionConversations | Query | Collections |
inboxCounts / chatCollectionCounts | Query | Counts. Expensive |
labels / activeLabels / label | Query | Labels |
See Reading the inbox.
MESSAGES_SEND
| Operation | Kind | Purpose |
|---|---|---|
sendMessage | Mutation | Send any message type into a chat |
updateMessage | Mutation | Edit a sent message |
deleteMessage | Mutation | Delete a message |
addMessageReaction / removeMessageReaction | Mutation | Reactions |
createMedia / uploadMultipleMedia / deleteMedia | Mutation | Media upload and removal |
sendWhatsAppTemplateMessage | Mutation | Send an approved WhatsApp template |
retryFailedMessage | Mutation | Retry one failed outbound message |
See Messaging.
CONVERSATIONS_MANAGE
| Operation | Kind | Purpose |
|---|---|---|
readMessages / readAllMessages | Mutation | Mark read |
closeChat / reopenChat | Mutation | Close and reopen |
assignChatToOperator / unassignChat / assignConversationThreads | Mutation | Assignment |
blockConversation | Mutation | Block and unblock |
setConversationAi | Mutation | Toggle the AI assistant |
updateChatField | Mutation | Status, priority, category and other chat fields |
apiCreateChatCollection / apiUpdateChatCollection / apiMoveChatCollection / apiDeleteChatCollection | Mutation | Collections |
createLabel / updateLabel / archiveLabel / restoreLabel / setMessageLabels | Mutation | Labels |
readAllConversation | Mutation | Mark a whole conversation read |
apiStartFlowForChat / apiStopFlowForChat | Mutation | Start or stop a published flow in a chat |
See Managing the inbox.
CONTACTS_READ, CONTACTS_MANAGE and CONTACTS_ERASE
| Operation | Kind | Scope |
|---|---|---|
contactApi / contactsApi / contactApiByExternalId | Query | CONTACTS_READ |
getPeopleFieldDefinitions / getPeopleFieldValue / getPeopleFieldValues | Query | CONTACTS_READ |
isWhatsAppIdEditable | Query | CONTACTS_READ |
createContactApi / updateContactApi / upsertContactApi | Mutation | CONTACTS_MANAGE |
createPeopleFieldDefinition / updatePeopleFieldDefinition / deletePeopleFieldDefinition | Mutation | CONTACTS_MANAGE |
setPeopleFieldValue / deletePeopleFieldValue | Mutation | CONTACTS_MANAGE |
previewErase | Query | CONTACTS_ERASE |
eraseContact | Mutation | CONTACTS_ERASE |
See Contacts.
CHANNELS_MANAGE
| Operation | Kind | Purpose |
|---|---|---|
channels | Query | List connected integrations |
pauseChannel / resumeChannel / updateChannel | Mutation | Pause, resume, rename, set AI auto-reply |
channelTelegramBotSettings + the 7 Telegram bot mutations | Query / Mutation | Telegram bot settings |
createWhatsAppTemplate / updateWhatsAppTemplate / deleteWhatsAppTemplate | Mutation | Template CRUD |
connectTelegramChannel / connectViberChannel | Mutation | Connect with a bot token |
partnerChannelConnectUrl | Mutation | Hosted connect URL for WhatsApp / Instagram |
connectWhatsAppChannel / connectInstagramChannel | Mutation | Connect with your own Meta credentials |
disconnectChannel | Mutation | Disconnect |
webIntegration / webIntegrationById | Query | Read the web widget |
createWebIntegration / updateWebIntegration / rotateWebIntegrationSecret / deleteWebIntegration | Mutation | Manage the web widget |
whatsAppTemplates / whatsAppTemplate | Query | Read approved templates |
syncWhatsAppTemplates | Mutation | Re-sync templates from Meta |
See Channels.
CONVERSATIONS_DELETE
Irreversible, and not implied by CONVERSATIONS_MANAGE.
| Operation | Kind | Purpose |
|---|---|---|
apiDeleteChat | Mutation | Delete one thread with its messages and media |
apiDeleteConversation | Mutation | Delete a conversation. removePeople: true additionally needs CONTACTS_ERASE |
See deleting.
NOTES_WRITE
| Operation | Kind | Purpose |
|---|---|---|
getChatNotes / conversationNotes | Query | Read internal notes |
sendConversationNote | Mutation | Post an internal note on a conversation |
Posting a note is sendMessage with internal: true - also gated by this scope.
TEAM_READ and TEAM_MANAGE
| Operation | Kind | Scope |
|---|---|---|
orgTeamMembers | Query | TEAM_READ |
addOrgMemberDirect / updateOrgMemberRole / removeOrgMember | Mutation | TEAM_MANAGE |
See Team.
CONTENT_READ and CONTENT_MANAGE
| Area | Read (CONTENT_READ) | Manage (CONTENT_MANAGE) |
|---|---|---|
| Help articles | helpArticles, helpArticle | createHelpArticle, updateHelpArticle, createHelpArticleTranslation, publishHelpArticle, unpublishHelpArticle, deleteHelpArticle |
| Help folders | helpFolders, helpFolder, helpFolderTree, helpFolderCounts, helpFolderCountsBatch | createHelpFolder, updateHelpFolder, moveHelpFolder, deleteHelpFolder |
| Help tags | helpTags, helpTag | createHelpTag, updateHelpTag, deleteHelpTag |
| News posts | newsPosts, newsPost | createNewsPost, updateNewsPost, createNewsPostTranslation, publishNewsPost, scheduleNewsPost, unpublishNewsPost, archiveNewsPost, deleteNewsPost |
| News taxonomy | newsCategories, newsCategory, newsTags, newsTag | createNewsCategory, updateNewsCategory, deleteNewsCategory, createNewsTag, updateNewsTag, deleteNewsTag |
See Content.
PARTNER_ADMIN
Tech provider orgs only (kind TECH_PROVIDER). Unlocks nothing on any other org's key.
| Operation | Kind | Purpose |
|---|---|---|
createClientOrg / clientOrgs / deprovisionClientOrg | Mutation / Query | Provision and tear down client orgs - Client orgs |
registerPartnerWebhook / partnerWebhooks / rotatePartnerWebhookSecret / setPartnerWebhookEvents / setPartnerWebhookStatus / deletePartnerWebhook | Mutation / Query | The fan-out webhook - Webhook subscriptions |
partnerUsageSummary / partnerUsageHistory | Query | Usage rollup and month-by-month history - Usage |
Each of these accepts an API key with PARTNER_ADMIN or a member login on the provider org.
Dashboard Only
Not callable with a key, by design:
| Operation | Why |
|---|---|
mintOrgApiKey / orgApiKeys / revokeOrgApiKey | A leaked key must not mint another, or widen its own scopes - API keys |
Not Available to Keys
Broadcasts, flow authoring, social comment and post moderation, creating or updating WhatsApp templates, GraphQL subscriptions, minting keys, and creating ADMIN/OWNER members. See Limitations for the full list and the workarounds.