> ## Documentation Index
> Fetch the complete documentation index at: https://docs.xpressbot.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Send session message

> Send a text or media WhatsApp message within the 24-hour session window, via the authorized channel.

Authentication: API key via X-API-Key header (or Authorization: Bearer).
Permissions: User API key
Rate limit: api_messaging — 20 requests/min per API user.



## OpenAPI

````yaml /api-reference/workspace.openapi.json post /api/workspace/v1/whatsapp/message/send
openapi: 3.1.0
info:
  title: Workspace API
  version: 1.0.0
  description: >-
    Manage contacts, labels, custom fields, WhatsApp messaging, and automations
    for your workspace.


    Generate your API key in the Developer Portal (profile menu → Developer) and
    send it in the `X-API-Key` header, or as `Authorization: Bearer <key>`.
    Never put the key in the URL.


    Every endpoint accepts POST with a JSON body, and also accepts GET with the
    same parameters as query-string values. All responses use the envelope `{
    success, data?, message?, error? }`.
servers:
  - url: https://YOUR_DOMAIN
    description: Your deployment, for example https://app.example.com
security: []
tags:
  - name: Channels
  - name: Contacts
  - name: Custom Fields
  - name: Labels
  - name: WhatsApp
  - name: Automations
paths:
  /api/workspace/v1/whatsapp/message/send:
    post:
      tags:
        - WhatsApp
      summary: Send session message
      description: >-
        Send a text or media WhatsApp message within the 24-hour session window,
        via the authorized channel.


        Authentication: API key via X-API-Key header (or Authorization: Bearer).

        Permissions: User API key

        Rate limit: api_messaging — 20 requests/min per API user.
      parameters:
        - name: channelId
          in: query
          required: false
          description: Channel id. Auto-selects when omitted.
          schema:
            type: string
            example: ch_123
        - name: to
          in: query
          required: false
          description: Recipient phone or WhatsApp BSUID.
          schema:
            type: string
            example: '919876543210'
        - name: body
          in: query
          required: false
          description: Text body. Required for text messages.
          schema:
            type: string
        - name: type
          in: query
          required: false
          description: text | image | video | document | audio. Default text.
          schema:
            type: string
        - name: url
          in: query
          required: false
          description: Media URL. Required for media messages.
          schema:
            type: string
        - name: caption
          in: query
          required: false
          description: Media caption.
          schema:
            type: string
        - name: filename
          in: query
          required: false
          description: Filename for documents.
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - to
              properties:
                channelId:
                  type: string
                  description: Channel id. Auto-selects when omitted.
                  example: ch_123
                to:
                  type: string
                  description: Recipient phone or WhatsApp BSUID.
                  example: '919876543210'
                body:
                  type: string
                  description: Text body. Required for text messages.
                type:
                  type: string
                  description: text | image | video | document | audio. Default text.
                url:
                  type: string
                  description: Media URL. Required for media messages.
                caption:
                  type: string
                  description: Media caption.
                filename:
                  type: string
                  description: Filename for documents.
            example:
              channelId: ch_123
              to: '919876543210'
              body: Hello from the API!
      responses:
        '200':
          description: 'Success. Envelope: { success:true, data, message? }.'
          content:
            application/json:
              schema:
                type: object
                required:
                  - success
                properties:
                  success:
                    type: boolean
                    example: true
                  data: {}
                  message:
                    type: string
                  pagination:
                    type: object
                  total:
                    type: number
              example:
                success: true
                data:
                  messaging_product: whatsapp
                  messages:
                    - id: wamid.xxx
                message: Message sent successfully
        '400':
          description: >-
            Missing/invalid parameters. Body has success:false plus error and
            message.
          content:
            application/json:
              schema:
                type: object
                required:
                  - success
                  - error
                properties:
                  success:
                    type: boolean
                    example: false
                  error:
                    type: string
                  message:
                    type: string
        '401':
          description: >-
            Missing or invalid API key (or session expired for session
            endpoints).
          content:
            application/json:
              schema:
                type: object
                required:
                  - success
                  - error
                properties:
                  success:
                    type: boolean
                    example: false
                  error:
                    type: string
                  message:
                    type: string
        '403':
          description: >-
            Authenticated but not authorized — wrong permissions or cross-tenant
            resource.
          content:
            application/json:
              schema:
                type: object
                required:
                  - success
                  - error
                properties:
                  success:
                    type: boolean
                    example: false
                  error:
                    type: string
                  message:
                    type: string
        '429':
          description: >-
            Rate limited. Retry after the Retry-After seconds; see RateLimit-*
            headers.
          content:
            application/json:
              schema:
                type: object
                required:
                  - success
                  - error
                properties:
                  success:
                    type: boolean
                    example: false
                  error:
                    type: string
                  message:
                    type: string
        '500':
          description: >-
            Unexpected server error. Body has success:false plus error and
            message.
          content:
            application/json:
              schema:
                type: object
                required:
                  - success
                  - error
                properties:
                  success:
                    type: boolean
                    example: false
                  error:
                    type: string
                  message:
                    type: string
      security:
        - apiKeyHeader: []
        - bearerAuth: []
components:
  securitySchemes:
    apiKeyHeader:
      type: apiKey
      in: header
      name: X-API-Key
      description: Preferred. API key value directly.
    bearerAuth:
      type: http
      scheme: bearer
      description: Alternative. API key as the bearer token.

````