Skip to main content

Double-handling with the native assistant

Registering an inbound webhook is additive: it never disables Minimo’s own native WhatsApp assistant. The contract is:
  • No webhook registered → the native assistant handles the conversation as usual (unchanged behavior).
  • Webhook registered + native assistant OFF on that channel → your bot owns the replies. This is the intended Path B setup.
  • Webhook registered + native assistant ON → the customer gets two replies (one from the native assistant, one from your bot). Minimo does not auto-resolve this; it is treated as an operator misconfiguration.
When you connect your own bot, turn the native WhatsApp assistant off on that channel in the dashboard. Otherwise every inbound message is answered twice.
Your bot is responsible for sending the reply — Minimo does not generate one on your behalf when a webhook is in play. Receiving the envelope and producing a response is entirely your code; you send it back with the Send endpoint.

Current limits

  • One event. Only whatsapp.message.received is forwarded today. Delivery-status events (sent / delivered / read) and template-approval updates are not pushed on this surface — poll List WhatsApp Templates for template status.
  • No media bytes in the webhook. The envelope carries a providerMediaId, not the file — fetch the bytes from the provider yourself. Stored history (the Read API) does expose a fetchable media.url.
  • Session text needs an open window. A type: "text" send only succeeds inside the 24-hour window opened by the customer’s last message. Outside it, use an approved template.
  • Read API page size is clamped to a maximum of 100.
  • Webhook retries stop after 5 attempts; a dead-letter is recorded in the delivery logs.
  • Events are at-least-once. Dedup on X-Minimo-Delivery (the wamid).

Common errors

Security checklist

  • Issue a WhatsApp-only API key for your bot (least privilege), not a broad key.
  • Always register webhooks with a secret and verify X-Minimo-Signature on every delivery.
  • Verify against the raw request body, byte-for-byte — see Verify the signature.
  • Respond 2xx fast and process asynchronously; a slow endpoint burns your retry budget.
  • Never log or expose the webhook secret or the API key.