What the API Does Not Cover
Operations deliberately excluded from API keys, and what to do instead
The API covers messaging, the inbox, contacts, channels and team. Everything below is deliberately out of reach of a key - not missing by oversight. Read this before you design around the API, so you don't build on something that will never arrive.
Not Available to API Keys
| Area | Status | What to do instead |
|---|---|---|
| Broadcasts | Not available | Send to recipients individually with sendMessage, or run the broadcast from the dashboard. Note the channel rate and window rules still apply per recipient. |
| Flow authoring | Not available - no flow CRUD | Flows are built in the dashboard. A key cannot create, edit, delete or even list them. It can start and stop a published one in a chat - see flows - with the flowId taken from the dashboard. A flow can also call out to you via flow.* webhook events. |
| Social comments and posts moderation | Not available | Instagram comment and post moderation is dashboard-only. A key can receive comment.* and post.* webhooks but cannot hide, reply to or delete a comment. |
| WhatsApp template Meta content edits | Not editable | Meta owns the approved content. A key can create, delete and update local metadata - see templates. To change approved content, create a new template. |
| GraphQL subscriptions | Not available to keys | Use webhooks. Realtime for machines is always HTTP delivery, never a subscription. |
Creating ADMIN or OWNER members | Refused | A key may only assign AGENT or EDITOR. Promotion stays a dashboard action by an existing admin or owner. See Team. |
| Minting or revoking API keys | Dashboard-only | A leaked key must not mint another, or widen its own scopes. See API keys. |
| Touching system contact fields | Refused | A key can manage and set the custom fields your org defined, never Wexio's built-ins. See Contacts. |
| Private-network media URLs | Refused (400) | media accepts public https:// URLs only - loopback, private ranges, link-local metadata and non-HTTP schemes are blocked. Upload instead. See media by URL. |
The Pattern Behind These
Three rules explain almost every exclusion:
- A key cannot widen its own authority. No minting keys, no changing scopes, no creating admins.
- A key cannot change what an external party approved. Meta owns a template's approved content, so only local metadata is editable.
- Authoring is dashboard work; operating is API work. Flows, broadcasts and moderation views are built by people; the API runs traffic through them. A key can start a published flow but not write one.
Note that provisioning client orgs and registering the fan-out webhook are now key-callable with PARTNER_ADMIN - a headless partner needs no dashboard visit to onboard a client.
Also Worth Knowing
These are not exclusions, but they surprise people:
- PII is masked, not refused. A key without
PII_READgets rows back with identity fieldsnull. Check the scope before concluding the data is absent. See Authentication. - Internal notes are invisible, not redacted, without
NOTES_WRITE- absent from reads, previews and media listings. - A failed send is not an error.
sendMessagereturns successfully withdeliveryStatus: FAILED. Always check it. - Scopes are immutable. To change what a key can do, mint a new one and revoke the old.
PARTNER_ADMINonly means something on a tech-provider org (kindTECH_PROVIDER). On any other org's key it unlocks nothing.- Deleting needs its own scope.
CONVERSATIONS_MANAGEdoes not implyCONVERSATIONS_DELETE, andCONTACTS_MANAGEdoes not implyCONTACTS_ERASE. - Page sizes are clamped to 100 for keys, silently. Page with the cursor.
- A key has no personal inbox - the
mineandmentionscollections are refused, and inbox counts report zero for both. - Content pagination is
limit/offset, contacts arefirst/after, messages are cursor-based. Four conventions coexist - check each signature. - Most channels cannot start a conversation. Only WhatsApp can cold-start, and only with an approved template. See Channel constraints.