Developers
Changelog
Every update to the API and the platform. Breaking changes are announced here before they take effect.
September 27, 2026
Three products: Verify, Notifications and Chat
ChangedTawked is now three products on one balance: Tawked Verify for OTP codes, Tawked Notifications for WhatsApp template messages from your own number, and Tawked Chat for your team inbox. Nothing changed under /v1.
September 26, 2026
The partner API grows
NewA partner sandbox key, tk_partner_test_, an Idempotency-Key on every write, verification and message logs, bulk provisioning, archiving, WhatsApp templates and team over the API, and an event feed with webhooks you subscribe to by event.
September 11, 2026
Connect your own WhatsApp number
NewConnect your WhatsApp Business Account from the application page through Meta's Embedded Signup. The account stays yours, and Meta bills you directly.
September 6, 2026
WhatsApp template messages over the API
NewPOST /v1/whatsapp/messages sends an approved template from your application's number with the same key, and its statuses reach you as signed message.* events.
September 2, 2026
Verification lifecycle, idempotency, protection and client webhooks
NewGET /v1/verify/{id}, POST …/resend and POST …/cancel round out the verification lifecycle. start now accepts an Idempotency-Key header, a reference field and autofill-ready messages. Per-application spend caps and per-IP rate limiting guard against pumping, API keys can carry an expiry, an IP allowlist and a check-only scope, and each application can receive its own signed webhooks for verified, failed and expired outcomes.
August 16, 2026
Partner webhooks are live, and the reference is complete
Newservice.approved, service.rejected, service.suspended, and balance.low now deliver to your webhook URL, signed with the signing secret shown in partner settings. The reference also gained the missing GET /v1/partner/services and POST …/resume endpoints.
August 15, 2026
Focus: verification over SMS only
ChangedWe stopped selling the email verify channel and the old notifications product; POST /v1/messages now returns 410 product_retired. Account data and credit ledgers are untouched.
August 11, 2026
API security hardening
ImprovedA per-key rate limit on the /v1/verify endpoints, 120 requests per minute by default, plus security headers and a CSP on every response.
August 10, 2026
Sandbox
Newtk_test_ keys are issued the moment onboarding completes, before application approval, and call the same endpoints with the same shapes. Real messages with a [TEST] stamp, to the account owner's phone only.
August 7, 2026
Per-application verify settings
NewCode length from 4 to 8, expiry from 1 to 15 minutes, attempts from 1 to 5, and an hourly send cap. Set from the dashboard only, so a leaked API key can't weaken your verification.
August 7, 2026
Partner platform
NewOne account for store platforms creates a store as an application via POST /v1/partner/services, with no per-merchant accounts, plus a partner dashboard for stores and settings.
June 8, 2026
Multiple applications
ImprovedManage more than one application under a single account, each with its own keys and logs, sharing one wallet.
May 29, 2026
Launch: Verify API
New/v1/verify/start and /v1/verify/check, API keys, prepaid credits via Moyasar, and the docs, in Arabic and English.