HostMentor Docs

Authentication

Authenticate WhatsApp Business API requests with your HostMentor API key in the apikey header, and keep your keys safe on your server.

Every request needs your API key in the apikey header:

-H "apikey: hm_live_..."

Create and revoke keys at app.hostmentor.com under Messaging → WhatsApp → API keys and webhook. Only team owners, admins and developers can see that page. Keys work while your team's WhatsApp API plan is active.

A new key works within a minute, and a revoked one stops working within a minute.

Keep your keys secret. Anyone with a key can message your customers as your business and use your message credit.

  • Use keys only on your server. Never put one in a website, mobile app or public code repository.
  • If a key leaks, revoke it on the dashboard straight away and create a new one.
  • Use a separate key for each system, so you can revoke one without stopping the others.

Requests without a valid key fail with HTTP 401 and the error invalid_api_key.