## Simulate an incoming message

`POST https://whatsapp.paaltech.org/api/v1/businesses/{external_id}/sandbox/incoming`

Test keys only. A customer writes to a connected sandbox business: the message goes
through the live path - contact, conversation, inbox, `message.received` callback - and
opens the 24-hour window for `from`.

Ability: `messages.send`

### Path parameters

| Name | Type | Required | Description |
|---|---|---|---|
| `external_id` | string | yes | Your own ID for the business (Multi-SKUUL - the tenant ID). Max 191 characters. Pattern `^[A-Za-z0-9._:-]+$` |

### Body

| Name | Type | Required | Description |
|---|---|---|---|
| `from` | string | yes | The customer's WhatsApp number (digits). Pattern `^[1-9][0-9]{6,14}$` |
| `text` | string | yes | Max 4096 characters |
| `profile_name` | string | null | no |  |
| `phone_number_id` | string | null | no | Which sandbox number receives it (when there are several). |

### Request

```bash
curl --request POST \
  --url 'https://whatsapp.paaltech.org/api/v1/businesses/presec/sandbox/incoming' \
  --header "Authorization: Bearer $PAALCHAT_TOKEN" \
  --header 'Accept: application/json' \
  --header 'Content-Type: application/json' \
  --data '{
  "from": "233241234567",
  "text": "Is there school on Friday?",
  "profile_name": "Ama Mensah"
}'
```

### Responses

- **201** - The stored incoming message.
- **401** - unauthenticated - missing, invalid, revoked or expired token

```json
{
  "error": {"code": "unauthenticated", "message": "A valid product token is required."}
}
```

- **403** - missing_ability, or sandbox_only (a live key).
- **404** - not_found - not yours, or does not exist

```json
{"error": {"code": "not_found", "message": "Business not found."}}
```

- **409** - sandbox_not_connected - connect the sandbox business first.
- **422** - validation_failed - fields are invalid; see errors.

```json
{
  "error": {
    "code": "validation_failed",
    "message": "The external id field format is invalid. (and 1 more error)"
  },
  "errors": {
    "external_id": ["The external id field format is invalid."],
    "name": ["The name field is required."]
  }
}
```

- **429** - rate_limited - over 300 requests/minute for this product

```json
{
  "error": {
    "code": "rate_limited",
    "message": "Too many requests. Slow down and retry after the Retry-After header."
  }
}
```

