Skip to main content
This walks through the shortest path from nothing to a message landing in a Workchats DM: register your App, install it on the sandbox company, confirm the token works, then send. All of this runs against the staging sandbox (https://public-api.staging.workchats.com), never a real company. See Sandbox for how to get access.
1

Register your App

Apps are registered by Octogle, not self-serve. Tell your Octogle contact:
  • the App’s name (shown on the consent screen and on every message it sends)
  • the OAuth redirect URI your backend will receive code on
You get back a client_id and a client_secret, and access to a sandbox company with a staging App registration. Tokens issued in the sandbox are prefixed wc_bot_test_ rather than wc_bot_live_, so they’re easy to tell apart in logs.Keep client_secret server-side. It’s a credential, not something to ship in a browser or mobile build.
2

Install on the sandbox

Send the company admin to the authorize URL your Octogle contact gives you for the sandbox (a staging counterpart of https://app.workchats.com/oauth/authorize), with:
The admin sees a consent screen naming your App and the scopes it’s asking for, and picks which groups and channels the bot may join. On approval, Workchats redirects to redirect_uri?code=<code>&state=<state>.Exchange the code for a token:
200
This token doesn’t expire and there’s no refresh token — save it now. Reinstalling later keeps the same bot user but issues a new token, and the old one stops working (401 token_revoked). Replace the stored token whenever you finish a new install.
3

Confirm the token works

200
4

Send a DM

Look up a recipient by email, then send:
201
The Idempotency-Key matters as soon as you retry on a timeout. See Idempotency before you write real send logic.

Next

  • Sending messages covers blocks, edits and deletes.
  • Errors lists every code you can get back.
  • Concepts explains Apps, installations and scopes in more depth.