Developers
Cronate API
Productize Cronate for your own clients with the same backend the dashboard uses. API access ships with Starter, Growth, and Scale — no separate API SKU. Quotas (email, AI credits, WhatsApp inboxes, automation runs) are shared with your Cronate plan.
Authentication
Create keys in the dashboard under Settings → API. Send the secret once as a Bearer token:
Authorization: Bearer crn_live_<your_secret> GET https://api.cronate.com/v1/crm/contacts
Keys are workspace-scoped. Use them from your server — never from a public browser app. Dashboard cookie sessions continue to work on unversioned paths for the Cronate UI.
Versioning
Public clients should call /v1/…. Nginx rewrites those paths to the same service routes the dashboard uses (/wa, /meta, /mail, /crm, /flows, /bot).
WhatsApp through Cronate
Cronate is a Meta tech provider. Merchants connect their WABA via Embedded Signup in the Cronate dashboard. Your app sends and receives WhatsApp through Cronate endpoints only — Meta access tokens are never returned by the API. Meta bills conversation fees to the merchant WABA directly (no Cronate markup).
# List conversations
GET /v1/wa/conversations
# Send (body matches dashboard send payload)
POST /v1/wa/conversations/{id}/sendErrors
API-key responses use a consistent shape:
{
"error": {
"code": "feature_disabled",
"message": "API access requires Starter or higher."
}
}401 unauthorized— missing/invalid key403 feature_disabled— plan or role gate403 forbidden— read-only / owner-only
Outbound webhooks
Register HTTPS endpoints in Settings → API (Starter+). Cronate POSTs JSON with headers:
X-Cronate-EventX-Cronate-Timestamp(unix seconds)X-Cronate-Signature— hex HMAC-SHA256 of{timestamp}.{rawBody}using your endpoint secret
Events: wa.message.inbound, meta.message.inbound, crm.contact.created, crm.contact.updated, crm.form.submitted, mail.campaign.status.
Resources
| Prefix | Includes |
|---|---|
| /v1/wa | Accounts, conversations, send, templates, tickets, SSE |
| /v1/meta | IG/Messenger accounts, conversations, comments, SSE |
| /v1/mail | Templates, campaigns, domains, transactional, analytics, asset uploads (multipart, max 15 MB) |
| /v1/crm | Contacts, tags, stages, products, forms (incl. file fields + public upload), reminders |
| /v1/flows | Flows CRUD, agent, runs |
| /v1/bot | Website bot config and conversations |
OpenAPI
Download the machine-readable spec:
- cronate.com/api/openapi.json
- https://api.cronate.com/v1/openapi.json (proxied in production)