Double-handling with the native assistant
Registering an inbound webhook is additive: it never disables Minimo’s own native WhatsApp
assistant. The contract is:
- No webhook registered → the native assistant handles the conversation as usual (unchanged
behavior).
- Webhook registered + native assistant OFF on that channel → your bot owns the replies. This
is the intended Path B setup.
- Webhook registered + native assistant ON → the customer gets two replies (one from the
native assistant, one from your bot). Minimo does not auto-resolve this; it is treated as an
operator misconfiguration.
When you connect your own bot, turn the native WhatsApp assistant off on that channel in the dashboard. Otherwise
every inbound message is answered twice.
Your bot is responsible for sending the reply — Minimo does not generate one on your behalf when a
webhook is in play. Receiving the envelope and producing a response is entirely your code; you
send it back with the Send endpoint.
Current limits
- One event. Only
whatsapp.message.received is forwarded today. Delivery-status events
(sent / delivered / read) and template-approval updates are not pushed on this surface — poll
List WhatsApp Templates for template
status.
- No media bytes in the webhook. The envelope carries a
providerMediaId, not the file —
fetch the bytes from the provider yourself. Stored history (the Read API) does expose a
fetchable media.url.
- Session text needs an open window. A
type: "text" send only succeeds inside the 24-hour
window opened by the customer’s last message. Outside it, use an approved template.
- Read API page size is clamped to a maximum of 100.
- Webhook retries stop after 5 attempts; a dead-letter is recorded in the delivery logs.
- Events are at-least-once. Dedup on
X-Minimo-Delivery (the wamid).
Common errors
Security checklist
- Issue a WhatsApp-only API key for your bot (least privilege), not a broad key.
- Always register webhooks with a secret and verify
X-Minimo-Signature on every delivery.
- Verify against the raw request body, byte-for-byte — see
Verify the signature.
- Respond
2xx fast and process asynchronously; a slow endpoint burns your retry budget.
- Never log or expose the webhook secret or the API key.