Skip to content

Developers

Changelog

Every update to the API and the platform. Breaking changes are announced here before they take effect.

  1. September 27, 2026

    Three products: Verify, Notifications and Chat

    Changed

    Tawked is now three products on one balance: Tawked Verify for OTP codes, Tawked Notifications for WhatsApp template messages from your own number, and Tawked Chat for your team inbox. Nothing changed under /v1.

  2. September 26, 2026

    The partner API grows

    New

    A partner sandbox key, tk_partner_test_, an Idempotency-Key on every write, verification and message logs, bulk provisioning, archiving, WhatsApp templates and team over the API, and an event feed with webhooks you subscribe to by event.

  3. September 11, 2026

    Connect your own WhatsApp number

    New

    Connect your WhatsApp Business Account from the application page through Meta's Embedded Signup. The account stays yours, and Meta bills you directly.

  4. September 6, 2026

    WhatsApp template messages over the API

    New

    POST /v1/whatsapp/messages sends an approved template from your application's number with the same key, and its statuses reach you as signed message.* events.

  5. September 2, 2026

    Verification lifecycle, idempotency, protection and client webhooks

    New

    GET /v1/verify/{id}, POST …/resend and POST …/cancel round out the verification lifecycle. start now accepts an Idempotency-Key header, a reference field and autofill-ready messages. Per-application spend caps and per-IP rate limiting guard against pumping, API keys can carry an expiry, an IP allowlist and a check-only scope, and each application can receive its own signed webhooks for verified, failed and expired outcomes.

  6. August 16, 2026

    Partner webhooks are live, and the reference is complete

    New

    service.approved, service.rejected, service.suspended, and balance.low now deliver to your webhook URL, signed with the signing secret shown in partner settings. The reference also gained the missing GET /v1/partner/services and POST …/resume endpoints.

  7. August 15, 2026

    Focus: verification over SMS only

    Changed

    We stopped selling the email verify channel and the old notifications product; POST /v1/messages now returns 410 product_retired. Account data and credit ledgers are untouched.

  8. August 11, 2026

    API security hardening

    Improved

    A per-key rate limit on the /v1/verify endpoints, 120 requests per minute by default, plus security headers and a CSP on every response.

  9. August 10, 2026

    Sandbox

    New

    tk_test_ keys are issued the moment onboarding completes, before application approval, and call the same endpoints with the same shapes. Real messages with a [TEST] stamp, to the account owner's phone only.

  10. August 7, 2026

    Per-application verify settings

    New

    Code length from 4 to 8, expiry from 1 to 15 minutes, attempts from 1 to 5, and an hourly send cap. Set from the dashboard only, so a leaked API key can't weaken your verification.

  11. August 7, 2026

    Partner platform

    New

    One account for store platforms creates a store as an application via POST /v1/partner/services, with no per-merchant accounts, plus a partner dashboard for stores and settings.

  12. June 8, 2026

    Multiple applications

    Improved

    Manage more than one application under a single account, each with its own keys and logs, sharing one wallet.

  13. May 29, 2026

    Launch: Verify API

    New

    /v1/verify/start and /v1/verify/check, API keys, prepaid credits via Moyasar, and the docs, in Arabic and English.

Chat on WhatsApp