contact.consent
A contact opted in or out of a category - by replying STOP or START (source: keyword),
or through the API. After a STOP, business-initiated marketing and notification
templates to them are refused; update your own records too.
Verify every callback
Check X-PaalChat-Signature on the raw body, reject timestamps older than 5 minutes, and de-duplicate on X-PaalChat-Delivery. Answer 2xx within 10 seconds. See Webhooks and callbacks.
Headers
X-PaalChat-Event
string
X-PaalChat-Delivery
string
Unique per event (equals body id). De-duplicate on it.
Format uuid.
X-PaalChat-Signature
string
t=<unix seconds>,v1=<hex HMAC-SHA256(secret, "<t>.<raw body>")>. Reject if invalid or older than 300 seconds.
Pattern ^t=\d+,v1=[a-f0-9]{64}$.
Body
id
string
Equals X-PaalChat-Delivery.
Format uuid.
sandbox
boolean
true for sandbox businesses (test keys) - nothing reached WhatsApp.
event
any
Always contact.consent.
occurred_at
string
Format date-time.
business
object
external_id
string
business.external_id
data
object
contact_id
integer
data.contact_id
contact_external_id
string | null
data.contact_external_id
phone
string | null
data.phone
category
string
data.category
One of: marketing, notifications, transactional.
status
string
data.status
One of: granted, revoked.
source
string
data.source
keyword (the contact replied STOP or START), api, inbox, or the source you sent.