# Workchats Developer Docs > Build integrations that send messages into Workchats as an installed App. - [Workchats API](https://developers.workchats.com/index.md): Send messages into Workchats as an installed App's bot user - [Quickstart](https://developers.workchats.com/getting-started/quickstart.md): Register an App, install it on the sandbox, and send your first message - [Concepts](https://developers.workchats.com/getting-started/concepts.md): Apps, installations, bot users, tokens and scopes - [Sandbox](https://developers.workchats.com/getting-started/sandbox.md): Build and test without touching a real company - [OAuth install](https://developers.workchats.com/guides/oauth-install.md): How a company connects your App, and how tokens work - [Sending messages](https://developers.workchats.com/guides/sending-messages.md): Send, edit and delete your bot's messages - [Blocks](https://developers.workchats.com/guides/blocks.md): Rich message layout, and how it rolls out - [Idempotency](https://developers.workchats.com/guides/idempotency.md): One key per message and destination - [Pagination](https://developers.workchats.com/guides/pagination.md): Cursor pagination, the same on every list endpoint - [Rate limits & retries](https://developers.workchats.com/guides/rate-limits-and-retries.md): Limits, how they're enforced, and how to back off - [Errors](https://developers.workchats.com/guides/errors.md): The error envelope, and every code - [Callbacks & signature verification](https://developers.workchats.com/guides/callbacks-and-signature-verification.md): Coming in the next phase - [Security](https://developers.workchats.com/guides/security.md): Handling tokens and secrets safely - [Data & security](https://developers.workchats.com/guides/data-and-security.md): Where message content lives, and what deleting it does - [Reference overview](https://developers.workchats.com/reference/overview.md): How to read the endpoint reference - [Exchange an authorization code for a bot token](https://developers.workchats.com/api-reference/production/oauth/exchange-an-authorization-code-for-a-bot-token.md): Redeems the `code` the consent screen redirected with. Installs the App into the approving admin's company, or reconnects an existing installation with the same bot user, and returns a new bot token. Any earlier token of the installation stops working. - [Revoke a bot token](https://developers.workchats.com/api-reference/production/oauth/revoke-a-bot-token.md): Disconnects the App from the company the token belongs to: every token of the installation stops working at once, and the bot stays in its groups for a later reconnect. - [Check a token](https://developers.workchats.com/api-reference/production/auth/check-a-token.md): Returns the workspace and bot user the token acts as, and the scopes it holds. Needs no scope. Limited to 100 requests a minute per installation. - [List users](https://developers.workchats.com/api-reference/production/users/list-users.md): Lists the workspace's people: its members, and guests who are visible to them. Deactivated and removed people stay listed with `is_active: false`. Bots are never listed. `email` is present only with the `users:read.email` scope, and only when the person lets colleagues see it. Needs `users:read`. Li… - [Get a user](https://developers.workchats.com/api-reference/production/users/get-a-user.md): One person, by id. A bot, a person in another workspace, or a guest members cannot see is `user_not_found`. Needs `users:read`. Limited to 100 requests a minute per installation. - [Look up a user by email](https://developers.workchats.com/api-reference/production/users/look-up-a-user-by-email.md): The person with this email address, in any letter case. An address the person hides from colleagues is `user_not_found`, exactly as an unknown one is. Needs `users:read.email`. Limited to 100 requests a minute per installation. - [List conversations](https://developers.workchats.com/api-reference/production/conversations/list-conversations.md): Lists the groups and named channels the bot is a member of: the ones it can post to. Direct messages are not listed. Needs `conversations:read`. Limited to 20 requests a minute per installation. - [Get a conversation](https://developers.workchats.com/api-reference/production/conversations/get-a-conversation.md): One group or named channel the bot is a member of, by id, as the list returns it. An archived group and its channels are returned with `is_archived: true`. A conversation the bot was never in, one in another workspace, a deleted one, and an announcement channel are all `conversation_not_found`. Afte… - [List a conversation's messages](https://developers.workchats.com/api-reference/production/conversations/list-a-conversations-messages.md): Lists the messages of a group or named channel the bot is a member of, newest first. The bot sees what a person who joined when it did would see: nothing sent before it joined, and no deleted messages. Direct messages cannot be read. `files` names each attached file; `GET /v1/conversations/{conversa… - [Get a file](https://developers.workchats.com/api-reference/production/files/get-a-file.md): Returns a file attached to a message the bot can read in the conversation, with a download link. The link is signed, needs no token and can be opened for 15 minutes; ask again for a fresh one. It redirects to a storage download that works for up to an hour. Access is checked when the link is issued,… - [Send a message](https://developers.workchats.com/api-reference/production/messages/send-a-message.md): Sends a message as the bot: a direct message to a person (`to.type: user`), or a post in a group or channel the bot is a member of (`to.type: conversation`). People see `text`; `blocks` are stored and shown from a later release. Needs `messages:write`. - [Edit a message](https://developers.workchats.com/api-reference/production/messages/edit-a-message.md): Replaces the text and blocks of a message the bot sent. `blocks` left out clears the old ones. `metadata`, when given, is merged into the stored metadata. `to`, `thread_id` and `unfurl_links` are ignored. Needs `messages:write`. Limited to 60 requests a minute per installation. - [Delete a message](https://developers.workchats.com/api-reference/production/messages/delete-a-message.md): Deletes a message the bot sent, for everyone, and erases its text, blocks, metadata and edit history. Works after the App was removed from the conversation. A message that is already deleted is `404 message_not_found`; treat both as success. Needs `messages:write`. Limited to 60 requests a minute pe… - [Callbacks](https://developers.workchats.com/reference/callbacks.md): Coming in the next phase - [Scopes](https://developers.workchats.com/reference/scopes.md): Every scope a company admin can grant your App - [Error codes](https://developers.workchats.com/reference/error-codes.md): Every code, alphabetically - [Block types](https://developers.workchats.com/reference/block-types.md): Field-level schema for every block and button - [Objects](https://developers.workchats.com/reference/objects.md): The shape of every object the API returns - [Changelog](https://developers.workchats.com/changelog.md): Every public change to the API, newest first - [Versioning](https://developers.workchats.com/policies/versioning.md): v1 is additive-only - [Rate limits](https://developers.workchats.com/policies/rate-limits.md): Published limits, as minimums - [Data residency](https://developers.workchats.com/policies/data-residency.md): Where message content is stored - [Workchats API](https://developers.workchats.com/index.md): Send messages into Workchats as an installed App's bot user - [Quickstart](https://developers.workchats.com/getting-started/quickstart.md): Register an App, install it on the sandbox, and send your first message - [Concepts](https://developers.workchats.com/getting-started/concepts.md): Apps, installations, bot users, tokens and scopes - [Sandbox](https://developers.workchats.com/getting-started/sandbox.md): Build and test without touching a real company - [OAuth install](https://developers.workchats.com/guides/oauth-install.md): How a company connects your App, and how tokens work - [Sending messages](https://developers.workchats.com/guides/sending-messages.md): Send, edit and delete your bot's messages - [Blocks](https://developers.workchats.com/guides/blocks.md): Rich message layout, and how it rolls out - [Idempotency](https://developers.workchats.com/guides/idempotency.md): One key per message and destination - [Pagination](https://developers.workchats.com/guides/pagination.md): Cursor pagination, the same on every list endpoint - [Rate limits & retries](https://developers.workchats.com/guides/rate-limits-and-retries.md): Limits, how they're enforced, and how to back off - [Errors](https://developers.workchats.com/guides/errors.md): The error envelope, and every code - [Callbacks & signature verification](https://developers.workchats.com/guides/callbacks-and-signature-verification.md): Coming in the next phase - [Security](https://developers.workchats.com/guides/security.md): Handling tokens and secrets safely - [Data & security](https://developers.workchats.com/guides/data-and-security.md): Where message content lives, and what deleting it does - [Reference overview](https://developers.workchats.com/reference/overview.md): How to read the endpoint reference - [Exchange an authorization code for a bot token](https://developers.workchats.com/api-reference/staging/oauth/exchange-an-authorization-code-for-a-bot-token.md): Redeems the `code` the consent screen redirected with. Installs the App into the approving admin's company, or reconnects an existing installation with the same bot user, and returns a new bot token. Any earlier token of the installation stops working. - [Revoke a bot token](https://developers.workchats.com/api-reference/staging/oauth/revoke-a-bot-token.md): Disconnects the App from the company the token belongs to: every token of the installation stops working at once, and the bot stays in its groups for a later reconnect. - [Check a token](https://developers.workchats.com/api-reference/staging/auth/check-a-token.md): Returns the workspace and bot user the token acts as, and the scopes it holds. Needs no scope. Limited to 100 requests a minute per installation. - [List users](https://developers.workchats.com/api-reference/staging/users/list-users.md): Lists the workspace's people: its members, and guests who are visible to them. Deactivated and removed people stay listed with `is_active: false`. Bots are never listed. `email` is present only with the `users:read.email` scope, and only when the person lets colleagues see it. Needs `users:read`. Li… - [Get a user](https://developers.workchats.com/api-reference/staging/users/get-a-user.md): One person, by id. A bot, a person in another workspace, or a guest members cannot see is `user_not_found`. Needs `users:read`. Limited to 100 requests a minute per installation. - [Look up a user by email](https://developers.workchats.com/api-reference/staging/users/look-up-a-user-by-email.md): The person with this email address, in any letter case. An address the person hides from colleagues is `user_not_found`, exactly as an unknown one is. Needs `users:read.email`. Limited to 100 requests a minute per installation. - [List conversations](https://developers.workchats.com/api-reference/staging/conversations/list-conversations.md): Lists the groups and named channels the bot is a member of: the ones it can post to. Direct messages are not listed. Needs `conversations:read`. Limited to 20 requests a minute per installation. - [Get a conversation](https://developers.workchats.com/api-reference/staging/conversations/get-a-conversation.md): One group or named channel the bot is a member of, by id, as the list returns it. An archived group and its channels are returned with `is_archived: true`. A conversation the bot was never in, one in another workspace, a deleted one, and an announcement channel are all `conversation_not_found`. Afte… - [List a conversation's messages](https://developers.workchats.com/api-reference/staging/conversations/list-a-conversations-messages.md): Lists the messages of a group or named channel the bot is a member of, newest first. The bot sees what a person who joined when it did would see: nothing sent before it joined, and no deleted messages. Direct messages cannot be read. `files` names each attached file; `GET /v1/conversations/{conversa… - [Get a file](https://developers.workchats.com/api-reference/staging/files/get-a-file.md): Returns a file attached to a message the bot can read in the conversation, with a download link. The link is signed, needs no token and can be opened for 15 minutes; ask again for a fresh one. It redirects to a storage download that works for up to an hour. Access is checked when the link is issued,… - [Send a message](https://developers.workchats.com/api-reference/staging/messages/send-a-message.md): Sends a message as the bot: a direct message to a person (`to.type: user`), or a post in a group or channel the bot is a member of (`to.type: conversation`). People see `text`; `blocks` are stored and shown from a later release. Needs `messages:write`. - [Edit a message](https://developers.workchats.com/api-reference/staging/messages/edit-a-message.md): Replaces the text and blocks of a message the bot sent. `blocks` left out clears the old ones. `metadata`, when given, is merged into the stored metadata. `to`, `thread_id` and `unfurl_links` are ignored. Needs `messages:write`. Limited to 60 requests a minute per installation. - [Delete a message](https://developers.workchats.com/api-reference/staging/messages/delete-a-message.md): Deletes a message the bot sent, for everyone, and erases its text, blocks, metadata and edit history. Works after the App was removed from the conversation. A message that is already deleted is `404 message_not_found`; treat both as success. Needs `messages:write`. Limited to 60 requests a minute pe… - [Callbacks](https://developers.workchats.com/reference/callbacks.md): Coming in the next phase - [Scopes](https://developers.workchats.com/reference/scopes.md): Every scope a company admin can grant your App - [Error codes](https://developers.workchats.com/reference/error-codes.md): Every code, alphabetically - [Block types](https://developers.workchats.com/reference/block-types.md): Field-level schema for every block and button - [Objects](https://developers.workchats.com/reference/objects.md): The shape of every object the API returns - [Changelog](https://developers.workchats.com/changelog.md): Every public change to the API, newest first - [Versioning](https://developers.workchats.com/policies/versioning.md): v1 is additive-only - [Rate limits](https://developers.workchats.com/policies/rate-limits.md): Published limits, as minimums - [Data residency](https://developers.workchats.com/policies/data-residency.md): Where message content is stored - [Workchats API](https://developers.workchats.com/index.md): Send messages into Workchats as an installed App's bot user - [Quickstart](https://developers.workchats.com/getting-started/quickstart.md): Register an App, install it on the sandbox, and send your first message - [Concepts](https://developers.workchats.com/getting-started/concepts.md): Apps, installations, bot users, tokens and scopes - [Sandbox](https://developers.workchats.com/getting-started/sandbox.md): Build and test without touching a real company - [OAuth install](https://developers.workchats.com/guides/oauth-install.md): How a company connects your App, and how tokens work - [Sending messages](https://developers.workchats.com/guides/sending-messages.md): Send, edit and delete your bot's messages - [Blocks](https://developers.workchats.com/guides/blocks.md): Rich message layout, and how it rolls out - [Idempotency](https://developers.workchats.com/guides/idempotency.md): One key per message and destination - [Pagination](https://developers.workchats.com/guides/pagination.md): Cursor pagination, the same on every list endpoint - [Rate limits & retries](https://developers.workchats.com/guides/rate-limits-and-retries.md): Limits, how they're enforced, and how to back off - [Errors](https://developers.workchats.com/guides/errors.md): The error envelope, and every code - [Callbacks & signature verification](https://developers.workchats.com/guides/callbacks-and-signature-verification.md): Coming in the next phase - [Security](https://developers.workchats.com/guides/security.md): Handling tokens and secrets safely - [Data & security](https://developers.workchats.com/guides/data-and-security.md): Where message content lives, and what deleting it does - [Reference overview](https://developers.workchats.com/reference/overview.md): How to read the endpoint reference - [Exchange an authorization code for a bot token](https://developers.workchats.com/api-reference/dev/oauth/exchange-an-authorization-code-for-a-bot-token.md): Redeems the `code` the consent screen redirected with. Installs the App into the approving admin's company, or reconnects an existing installation with the same bot user, and returns a new bot token. Any earlier token of the installation stops working. - [Revoke a bot token](https://developers.workchats.com/api-reference/dev/oauth/revoke-a-bot-token.md): Disconnects the App from the company the token belongs to: every token of the installation stops working at once, and the bot stays in its groups for a later reconnect. - [Check a token](https://developers.workchats.com/api-reference/dev/auth/check-a-token.md): Returns the workspace and bot user the token acts as, and the scopes it holds. Needs no scope. Limited to 100 requests a minute per installation. - [List users](https://developers.workchats.com/api-reference/dev/users/list-users.md): Lists the workspace's people: its members, and guests who are visible to them. Deactivated and removed people stay listed with `is_active: false`. Bots are never listed. `email` is present only with the `users:read.email` scope, and only when the person lets colleagues see it. Needs `users:read`. Li… - [Get a user](https://developers.workchats.com/api-reference/dev/users/get-a-user.md): One person, by id. A bot, a person in another workspace, or a guest members cannot see is `user_not_found`. Needs `users:read`. Limited to 100 requests a minute per installation. - [Look up a user by email](https://developers.workchats.com/api-reference/dev/users/look-up-a-user-by-email.md): The person with this email address, in any letter case. An address the person hides from colleagues is `user_not_found`, exactly as an unknown one is. Needs `users:read.email`. Limited to 100 requests a minute per installation. - [List conversations](https://developers.workchats.com/api-reference/dev/conversations/list-conversations.md): Lists the groups and named channels the bot is a member of: the ones it can post to. Direct messages are not listed. Needs `conversations:read`. Limited to 20 requests a minute per installation. - [Get a conversation](https://developers.workchats.com/api-reference/dev/conversations/get-a-conversation.md): One group or named channel the bot is a member of, by id, as the list returns it. An archived group and its channels are returned with `is_archived: true`. A conversation the bot was never in, one in another workspace, a deleted one, and an announcement channel are all `conversation_not_found`. Afte… - [List a conversation's messages](https://developers.workchats.com/api-reference/dev/conversations/list-a-conversations-messages.md): Lists the messages of a group or named channel the bot is a member of, newest first. The bot sees what a person who joined when it did would see: nothing sent before it joined, and no deleted messages. Direct messages cannot be read. `files` names each attached file; `GET /v1/conversations/{conversa… - [Get a file](https://developers.workchats.com/api-reference/dev/files/get-a-file.md): Returns a file attached to a message the bot can read in the conversation, with a download link. The link is signed, needs no token and can be opened for 15 minutes; ask again for a fresh one. It redirects to a storage download that works for up to an hour. Access is checked when the link is issued,… - [Send a message](https://developers.workchats.com/api-reference/dev/messages/send-a-message.md): Sends a message as the bot: a direct message to a person (`to.type: user`), or a post in a group or channel the bot is a member of (`to.type: conversation`). People see `text`; `blocks` are stored and shown from a later release. Needs `messages:write`. - [Edit a message](https://developers.workchats.com/api-reference/dev/messages/edit-a-message.md): Replaces the text and blocks of a message the bot sent. `blocks` left out clears the old ones. `metadata`, when given, is merged into the stored metadata. `to`, `thread_id` and `unfurl_links` are ignored. Needs `messages:write`. Limited to 60 requests a minute per installation. - [Delete a message](https://developers.workchats.com/api-reference/dev/messages/delete-a-message.md): Deletes a message the bot sent, for everyone, and erases its text, blocks, metadata and edit history. Works after the App was removed from the conversation. A message that is already deleted is `404 message_not_found`; treat both as success. Needs `messages:write`. Limited to 60 requests a minute pe… - [Callbacks](https://developers.workchats.com/reference/callbacks.md): Coming in the next phase - [Scopes](https://developers.workchats.com/reference/scopes.md): Every scope a company admin can grant your App - [Error codes](https://developers.workchats.com/reference/error-codes.md): Every code, alphabetically - [Block types](https://developers.workchats.com/reference/block-types.md): Field-level schema for every block and button - [Objects](https://developers.workchats.com/reference/objects.md): The shape of every object the API returns - [Changelog](https://developers.workchats.com/changelog.md): Every public change to the API, newest first - [Versioning](https://developers.workchats.com/policies/versioning.md): v1 is additive-only - [Rate limits](https://developers.workchats.com/policies/rate-limits.md): Published limits, as minimums - [Data residency](https://developers.workchats.com/policies/data-residency.md): Where message content is stored ## OpenAPI Specs - [dev](/openapi/dev.json) - [prod](/openapi/prod.json) - [staging](/openapi/staging.json)