https://public-api.staging.workchats.com), never a real company. See
Sandbox for how to get access.
1
Register your App
Apps are registered by Octogle, not self-serve. Tell your Octogle contact:
- the App’s name (shown on the consent screen and on every message it sends)
- the OAuth redirect URI your backend will receive
codeon
client_id and a client_secret, and access to a sandbox
company with a staging App registration. Tokens issued in the sandbox are
prefixed wc_bot_test_ rather than wc_bot_live_, so they’re easy to tell
apart in logs.Keep client_secret server-side. It’s a credential, not something to ship
in a browser or mobile build.2
Install on the sandbox
Send the company admin to the authorize URL your Octogle contact gives you
for the sandbox (a staging counterpart of
The admin sees a consent screen naming your App and the scopes it’s asking
for, and picks which groups and channels the bot may join. On approval,
Workchats redirects to This token doesn’t expire and there’s no refresh token — save it now.
Reinstalling later keeps the same bot user but issues a new token, and the
old one stops working (
https://app.workchats.com/oauth/authorize), with:redirect_uri?code=<code>&state=<state>.Exchange the code for a token:200
401 token_revoked). Replace the stored token
whenever you finish a new install.3
Confirm the token works
200
4
Send a DM
Look up a recipient by email, then send:The
201
Idempotency-Key matters as soon as you retry on a timeout. See
Idempotency before you write real send logic.Next
- Sending messages covers
blocks, edits and deletes. - Errors lists every code you can get back.
- Concepts explains Apps, installations and scopes in more depth.