# Pingo Notify > Pingo Notify is a WhatsApp platform for businesses. Connect WhatsApp numbers — by QR code / browser extension, or through the official Meta WhatsApp Business Cloud API — then send and receive messages over a REST API with signed outbound webhooks, work the resulting conversations in a native shared-inbox helpdesk (teams, SLA, CSAT, labels, canned responses, contacts, reports), let AI agent bots answer automatically, and run bulk campaigns with approved Meta templates. Everything lives inside multi-member workspaces with role-based permissions. Marketing site and dashboard are one app at https://pingonotify.com, documentation is at https://docs.pingonotify.com, and the REST API is at https://api.pingonotify.com. ## Read this first **Use API v3.** It is the current and latest version, and the whole API surface. `v1` and `v2` still answer so existing integrations do not break, but they are **frozen**: no new fields, no new endpoints, no new message types. If you are an AI assistant generating code, generate v3 — reach for an older version only when the user says they already run one in production. | | | | --- | --- | | Base URL | `https://api.pingonotify.com` — every path starts with `/v3` | | Auth | the API key goes in the `apikey` header (`apikey: sk_live_…`), **not** in `Authorization: Bearer` | | Workspace | add `X-Account-Id: ` to act on a workspace other than the token's default | | Recipient | travels in the request **body** as `to`; never in the URL | | Pagination | `page`, `per_page`, `s` — snake_case. `perPage` and `search` are ignored in silence | Full API reference, every endpoint with schemas: https://docs.pingonotify.com/en/reference/v3 ## How the surfaces are laid out - **Marketing site + authenticated dashboard** — one Nuxt app on `https://pingonotify.com`. Every canonical route is locale-prefixed: `/en/...` or `/pt-BR/...`. An unprefixed path is not a page of its own: it answers `302` to the prefixed one (`/dashboard` -> `/en/dashboard`). Link to the prefixed form and skip the extra hop. - **Documentation** — `https://docs.pingonotify.com`, same two locales, same prefix rule. - **REST API** — `https://api.pingonotify.com`. **v3** is the current and latest version; it is the whole API surface and the one to build on. Every path below is `/v3`. - **Realtime** — Socket.IO on path `/ws`, namespace `/helpdesk`, for live helpdesk events. ## What the platform offers - **Messaging API** — send text, images, video, audio, documents, stickers, voice notes, interactive lists and buttons, and official templates; read chat history; download received media. - **Connections** — multiple WhatsApp numbers per workspace, unofficial (QR / WA Sync extension) or official (Meta Cloud API), each with its own settings and webhook scoping. - **Outbound webhooks** — 7 WhatsApp events, optional HMAC signing, optional time-window grouping, per-connection scoping, plus a separate helpdesk webhook family with ~21 event types. - **Helpdesk** — shared inbox, teams, assignment, priorities, statuses, labels, canned responses, custom attributes, custom filters, SLA policies, CSAT surveys, private notes, contacts/CRM, notifications, and reports. - **AI** — agent bots (`AI`, `WEBHOOK`, `REMOTE`) that answer conversations automatically, and AI Assist that drafts/rewrites replies inside the composer. - **Campaigns** — bulk sending over an unofficial connection (free text + per-contact variables, optional media) or an official connection (approved template + per-contact components). - **Official templates** — full CRUD against Meta, per official connection, including media-header sample upload. - **Workspaces** — multiple accounts per user, invitations, roles `OWNER` / `ADMIN` / `MANAGER` / `AGENT`, workspace selected per request with the `X-Account-Id` header. - **Integrations** — an app catalog (`SquidCore`, `Chatwoot`), OAuth apps for third parties, and the official WordPress plugin. ## Essential links - [Homepage](https://pingonotify.com/en/): product overview, features, pricing CTA, FAQ. - [Pricing](https://pingonotify.com/en/pricing): plan comparison, monthly/yearly, BRL and USD. - [WhatsApp Helpdesk landing](https://pingonotify.com/en/whatsapp-helpdesk): the helpdesk product page. - [WordPress plugin landing](https://pingonotify.com/en/whatsapp-wordpress-plugin): the WooCommerce/WordPress integration page. - [Sign up (free)](https://pingonotify.com/en/auth/signup): create an account, no credit card. - [Sign in](https://pingonotify.com/en/auth/signin): email + password + verification code. - [Dashboard](https://pingonotify.com/en/dashboard): authenticated overview (usage, connections, plan cycle). - [Documentation home](https://docs.pingonotify.com/en): guides index. - [API v3 guide](https://docs.pingonotify.com/en/api-reference/v3): prose reference — start here, it links to the interactive reference. - [API v3 — Authentication](https://docs.pingonotify.com/en/api-reference/v3/authentication): `apikey` header, `X-Account-Id`, role matrix, plan gates. - [API v3 — Conventions](https://docs.pingonotify.com/en/api-reference/v3/conventions): pagination, errors, identifiers. - [API v3 — Webhooks](https://docs.pingonotify.com/en/api-reference/v3/webhooks): delivery, signing, retries. - [API v3 — Realtime](https://docs.pingonotify.com/en/api-reference/v3/realtime): the `/helpdesk` Socket.IO namespace. - [Interactive API v3 reference (Scalar)](https://docs.pingonotify.com/en/reference/v3): every endpoint with request/response schemas and a try-it console. - [Connections guide](https://docs.pingonotify.com/en/connections) - [API keys guide](https://docs.pingonotify.com/en/apikeys) - [Webhooks guide](https://docs.pingonotify.com/en/webhooks) - [Official WhatsApp API guide](https://docs.pingonotify.com/en/official-whatsapp-api) - [Integrations guide](https://docs.pingonotify.com/en/integrations) - [WordPress plugin guide](https://docs.pingonotify.com/en/plugin-wordpress) - [Message template plugins](https://docs.pingonotify.com/en/template-plugins) - [Hooks and development](https://docs.pingonotify.com/en/hooks-and-development) - [WordPress plugin on wordpress.org](https://wordpress.org/plugins/infixs-pingo-notify/): "Pingo Notify – Automation & Notification Chat Messages". Every link above has a Portuguese twin: replace `/en/` with `/pt-BR/`. ## Connections ### Connection types `ConnectionType` has exactly two values: - `WHATSAPP_UNOFFICIAL` — standard WhatsApp account linked by QR code scan (or by the WA Sync browser extension, which harvests an existing web session). No Meta Business account required. Subject to the instabilities inherent to unofficial WhatsApp access. - `WHATSAPP_OFFICIAL` — WhatsApp Business Cloud API. Requires a Meta Business account: `metaAccessToken`, `metaPhoneNumberId` and `metaBusinessAccountId` are mandatory on create, and `metaAppSecret` is optional (supplying it turns on `x-hub-signature-256` HMAC verification on inbound Meta webhooks). Unlocks approved templates, interactive buttons and the Verified Badge. Not available on the Free plan. How a connection was created determines how it reconnects: `WA_QRCODE` asks for a fresh QR code, `WA_OFFICIAL` re-registers the webhook with Meta, `WA_SYNC` re-syncs through the browser extension. ### Connection status `status` is one of `created`-time values plus the live Evolution state: `connecting`, `open`, `close`, `timeout`, `offline`, `close_waiting_delete`. A connection must be `open` to send. ### Per-connection settings Six booleans live under the nested `settings` object of the create/update payload: - `readMessages` — automatically mark incoming messages as read. - `alwaysOnline` — keep the number appearing online. - `groupsIgnore` — do not process or forward messages from WhatsApp groups. - `syncFullHistory` — synchronize the complete chat history when the connection is established. - `rejectCall` — automatically reject incoming voice calls. - `readStatus` — automatically mark WhatsApp status updates (Stories) as read. One boolean is **top-level**, not inside `settings`: - `enableStatusAlert` — notify the account when the connection drops unexpectedly. ## Helpdesk A native shared inbox built on top of the connections. It is a **PRO-plan feature for writing**: any plan may read the helpdesk, but creating, replying, assigning or configuring requires PRO (`plans.rules.helpdesk === true`). Denied requests return `HELPDESK_PLAN_REQUIRED`. What it covers (all under `/v3/helpdesk/...`): - **Inboxes** — one per connection, with members and working hours. - **Conversations** — list/filter, statuses, priorities, assignment to an agent or a team, participants, labels, mark-as-read, delete. Scoped views in the UI: all, participating, unattended, and per label. - **Messages** — send with attachments, edit, delete, retry a failed send. - **Teams** — grouping of agents for assignment and reporting. - **Labels** — a workspace-wide catalog, applied to conversations and contacts. - **Canned responses** — saved replies, searchable from the composer. - **Custom attributes** and **custom filters** — extra structured fields on contacts/conversations and saved filter views. - **Contacts / CRM** — contacts with notes, labels, avatar, conversation history, merge, and contact sync from a connection. - **SLA** — SLA policies, per-conversation SLA state, SLA reports, `helpdesk.sla.missed` events. - **CSAT** — post-resolution surveys; the public survey lives at `/public/helpdesk/csat/{conversationId}`. - **Notifications** — in-app notifications, unread counts, snooze, per-user notification settings and push subscriptions. - **Reports** — agent overview, conversation traffic, CSAT, label, per-inbox, per-team. - **Outbound webhooks** — a separate webhook family scoped to the account or to one inbox (see Webhooks below). - **Inbound webhook** — `POST /webhooks/helpdesk/{inboxId}` for pushing messages into an inbox from your own app. ## AI ### Agent bots `/v3/helpdesk/agent-bots`. A bot is attached to one or more inboxes and answers automatically. `HelpdeskAgentBotType`: - `AI` (default) — answers with the workspace's own LLM configuration. Requires `systemPrompt` (persona + task, up to 8000 chars); `model` optionally overrides the workspace model. - `WEBHOOK` — an external bot: Pingo posts the conversation event to your URL and sends back what you return. - `REMOTE` — an AI agent supplied by an installed integration (for example SquidCore); selected by provider slug plus the provider's own agent id. Bots can be enabled/disabled without deletion, and have a per-bot response delay (debounce, 0–300 seconds) so a burst of customer messages is answered once instead of line by line. ### AI Assist `/v3/helpdesk/ai`. Per-workspace OpenAI-compatible configuration (`GET`/`PUT /config`) plus `POST /generate`, which drafts or rewrites a reply from inside the composer. Writing the configuration (the API key) requires `OWNER` or `ADMIN`; `MANAGER` and `AGENT` can read the status and use generation. ## Campaigns Bulk sending, queued and throttled server-side (`/v3/campaigns`): - `POST /v3/campaigns/whatsapp/unofficial` — over a `WHATSAPP_UNOFFICIAL` connection. Free text with `{{handlebars}}` placeholders, optional `mediaData`, and a `targets` array where each entry is `{ "to": "...", "variables": { ... } }`. - `POST /v3/campaigns/whatsapp/official` — over a `WHATSAPP_OFFICIAL` connection, using an approved Meta template. Each target may carry `components` that override the template's base components for that contact. Requires a paid plan. - `GET /v3/campaigns/{id}` — progress and status. - `POST /v3/campaigns/{id}/cancel` — stop a running campaign. Every campaign message counts against the plan's monthly message quota. ## Official Meta templates Managed per official connection at `/v3/connections/{id}/templates` (list, create, read, edit, delete). Listing returns every status straight from Meta — approved, pending and rejected. Meta itself locks approved templates against editing; only rejected ones can be changed. `POST /v3/connections/{id}/templates/header-media` uploads the sample file for a media header and returns the `handle` to embed in the template's `example.header_handle`. ## Workspaces and roles Every request acts on exactly one workspace (account). Without a header it is the token's / user's default account; send `X-Account-Id: ` to act on another workspace you belong to. Pointing it at a workspace you are not a member of returns 403. List the workspaces you can use with `GET /v3/accounts`. Roles gate reads as well as writes: a member only sees the resources their role covers. `AGENT`, in particular, gets `403` on almost every `GET` outside the helpdesk (connections, webhooks, API tokens, stats): - `OWNER` — everything, including billing, workspace update, transfer and deletion. - `ADMIN` — operational administration: members, connections, integrations, webhooks, API tokens, OAuth apps, messages, the whole helpdesk (including the AI configuration) and stats. No billing, no account mutation. - `MANAGER` — members, connections, integrations, webhooks and the whole helpdesk; may send messages and read stats; reads (but does not manage) the AI configuration. No API tokens, no OAuth apps, no billing. - `AGENT` — helpdesk only: reads the workspace and its members, and operates conversations (reply, assign, label, status, participants, mark-read) in the inboxes they belong to. Cannot delete conversations. A member can never grant a role at or above their own. ## Plans and limits Source of truth: the `plans` seed and `plan-body-size.ts`. Live prices are on the [pricing page](https://pingonotify.com/en/pricing). | Plan | Messages / month | Connections | `rules.messageTypes` | Max text length | Helpdesk | |---|---|---|---|---|---| | `FREE` (default on signup) | 32 | 1 | `conversation` | 600 | no | | `STANDARD` | 1,000 | 3 | `conversation`, `imageMessage`, `documentMessage` | 1,500 | no | | `PRO` | 10,000 | 8 | `conversation`, `imageMessage`, `videoMessage`, `audioMessage`, `documentMessage`, `stickerMessage` | 3,000 | yes | Media size ceilings (`rules.bodySize`, per media kind). Paid plans carry explicit values; `FREE` and not-yet-renewed legacy plans fall back to the defaults in the first column: | Media | Fallback (`FREE`) | `STANDARD` | `PRO` | |---|---|---|---| | image | 5 MB | 5 MB | 5 MB | | video | 5 MB | 8 MB | 16 MB | | audio | 5 MB | 8 MB | 16 MB | | document | 10 MB | 16 MB | 100 MB | | sticker | 5 MB | 5 MB | 5 MB | These mirror the WhatsApp Cloud API ceilings (document 100 MB, video/audio 16 MB, image 5 MB); no tier exceeds them. Sticker deliberately follows the image ceiling instead of Meta's 500 KB, because sticker routes go through the unofficial transport. `GET /v3/summary` returns the active workspace's quota, usage and billing cycle. Exceeding a limit returns 403 with a code such as `USER_PLAN_EXCEEDED_CONNECTIONS` or `USER_PLAN_EXCEEDED_MESSAGES`. Official connections and official campaigns require a paid plan. ### Billing - **Intervals**: `monthly` or `yearly`; **currencies**: `BRL` and `USD`, chosen by country. - **Payment methods**: credit card via Stripe (3D Secure, automatic recurring charges) and PIX (Brazil / BRL only, QR-code instant payment). - Message credits reset each cycle and do not roll over. Upgrades and downgrades are possible at any time; used credits are neither refunded nor carried over. - Cancelling keeps access until the end of the paid cycle. - Managed from `/en/settings/plans`, `/en/settings/invoices` and `/en/settings/billing`. ## API authentication Two credentials reach the API: 1. **Session cookie (`__session`)** — a JWT issued to the browser after email + password sign-in plus a verification code (delivered by email or WhatsApp). Used by the dashboard. 2. **API key** — a long-lived token for server-side integrations. It is created from `/en/dashboard/apikeys` or with `POST /v3/api-tokens`, and its full value (`sk_live_…`) is returned **once**, at creation; Pingo stores only a hash. Send the API key verbatim, prefix included, in the **`apikey` header**: ``` apikey: sk_live_a1b2c3d4e5f6... ``` `Authorization: Bearer ` does **not** work — it is ignored, and the request fails with 401. An API key carries **no scopes of its own**. `POST /v3/api-tokens` accepts only `name` and an optional `description`; the token inherits the permissions of the user who created it, in the workspace it belongs to. Treat a token as that person's credential, and create it under a member whose role matches what the integration actually needs. (The `connections` / `messages` scopes you may see on the consent screen at `/en/auth/integration` belong to **OAuth apps** — third-party applications asking a Pingo user for authorization — not to API keys.) Rotate a key with `PATCH /v3/api-tokens/{id}` and `{"refreshToken": true}` (the old secret stops working immediately); revoke it with `DELETE /v3/api-tokens/{id}`. Only `OWNER` and `ADMIN` manage tokens. ## Webhooks ### WhatsApp events Configured at `/v3/webhooks` (or `/en/dashboard/webhooks`). Exactly seven event keys are accepted: | Event key | Meaning | |---|---| | `messages.upsert` | Message received | | `messages.update` | Message status/content updated | | `messages.delete` | Message deleted | | `messages.edited` | Message edited | | `send.message` | Message sent (emitted by unofficial connections) | | `presence.update` | Presence update | | `connection.update` | Connection status change (accepted, but not currently dispatched) | Rules that matter: - `url` must be a valid absolute URL; deliveries are `POST` with a JSON body. - `connections` is a list of connection UUIDs. **If it is omitted, no connection is linked and nothing is delivered.** - `messageGroupDelay` (1–300 seconds) buffers messages and delivers them in one request instead of one per message. The body stays the same envelope (`event`, `connectionId`, `remoteJid`, `sender`, `data`); what changes is that **`data` becomes an array** of the objects you would otherwise receive one at a time. Handle both with `const messages = Array.isArray(body.data) ? body.data : [body.data]`. - `enableSimulateTyping` optionally emits a typing indicator on the connection. - Media in a delivered payload carries a `downloadMediaUrl` — an absolute, signed, time-limited link to `GET /v3/connections/media/{mediaId}/download?token=…`, so your consumer downloads the file without holding any Pingo credential. - Failed deliveries (network error or HTTP >= 400) are recorded and retried. ### HMAC signing Set `hmacEnabled: true` on the webhook. Pingo generates the secret server-side (it is never accepted from the client); read it with `GET /v3/webhooks/{id}/secret` and replace it with `POST /v3/webhooks/{id}/secret/rotate`. Signed deliveries carry two headers: - `X-Pingo-Signature-256: sha256=` - `X-Pingo-Timestamp: ` The signature is `HMAC-SHA256` over the preimage `"{timestamp}.{rawBody}"` — the timestamp, a literal dot, then the exact raw body as sent. Verify by recomputing over the raw body and comparing in constant time; the timestamp gives you replay protection. ### Helpdesk webhooks A separate family at `/v3/helpdesk/webhooks`, scoped to the whole account or to a single inbox, with `POST /v3/helpdesk/webhooks/{id}/test` to fire a sample. Subscriptions are picked from ~21 event types, all prefixed `helpdesk.`: `helpdesk.conversation.created`, `.updated`, `.status_changed`, `.assignee_changed`, `.priority_changed`, `.labels_changed`, `.deleted`, `.read`, `.ai_agent_changed`; `helpdesk.message.created`, `.updated`, `.deleted`, `.status_changed`; `helpdesk.mention.created`; `helpdesk.csat.response_received`; `helpdesk.label.created`, `.updated`, `.deleted`; `helpdesk.sla.missed`; `helpdesk.contact_sync.updated`; `helpdesk.conversation_sync.updated`. (`helpdesk.notification.created` is realtime-only and cannot be subscribed to.) The body is `{ "event": "...", "data": { ... }, "deliveredAt": "" }`. Headers are `X-Helpdesk-Event` and `X-Helpdesk-Signature` — the latter a plain hex `HMAC-SHA256` of the raw body (no `sha256=` prefix, no timestamp): a different scheme from the WhatsApp webhooks above. ## API examples **Base URL:** `https://api.pingonotify.com` — every path below is v3. Every authenticated example carries `apikey: sk_live_…`. Add `X-Account-Id: ` to act on a workspace other than the token's default; omit it and the token's own workspace is used. The recipient travels in the **body** as `to` (or in the query string, for the history `GET`); `connectionId` stays in the path. `to` accepts `{countryCode}{number}` for an individual (e.g. `5511999999999`) or `{groupId}@g.us` for a group. ### 1. Create an API key The very first key comes from the dashboard (`/en/dashboard/apikeys`); afterwards a token can mint others. ```bash curl -X POST https://api.pingonotify.com/v3/api-tokens \ -H 'apikey: sk_live_YOUR_KEY' \ -H 'content-type: application/json' \ -d '{ "name": "Production server", "description": "Order notifications from the shop backend" }' ``` Response — `token` appears here and nowhere else, ever: ```json { "id": "0195f3a0-1234-7890-abcd-ef0123456789", "name": "Production server", "description": "Order notifications from the shop backend", "token": "sk_live_xF3k9...", "prefix": "sk_live", "tokenLast4": "9f2a", "createdAt": "2026-01-01T00:00:00.000Z" } ``` ### 2. List connections ```bash curl https://api.pingonotify.com/v3/connections \ -H 'apikey: sk_live_YOUR_KEY' ``` Returns `{ "data": [ … ] }` — not paginated. Each entry carries `id`, `name`, `type`, `status`, `profileName` and the phone number. Take the `id` of a connection whose `status` is `open`; that is the `{connectionId}` used below. ### 3. Send a text message ```bash curl -X POST https://api.pingonotify.com/v3/connections/{connectionId}/chats/messages \ -H 'apikey: sk_live_YOUR_KEY' \ -H 'content-type: application/json' \ -d '{ "to": "5511999999999", "text": "Your order #1234 has shipped.", "delay": 1000 }' ``` `delay` (milliseconds) is an optional human-like pause before delivery. `linkPreview` and `mentionsEveryOne` are optional booleans. Setting `inputMode: "html"` lets you send basic HTML that is converted to WhatsApp formatting, and `placeholders` fills `{{variables}}` in `text` (with `language` and `currency` steering number/date/money formatting). ### 4. Send media Same endpoint — adding `mediaData` turns the request into a media message, and `text` becomes the caption. `mimetype` is required. ```bash curl -X POST https://api.pingonotify.com/v3/connections/{connectionId}/chats/messages \ -H 'apikey: sk_live_YOUR_KEY' \ -H 'content-type: application/json' \ -d '{ "to": "5511999999999", "text": "Here is your invoice.", "mediaData": { "mediatype": "document", "mimetype": "application/pdf", "media": "https://example.com/invoice-1234.pdf", "fileName": "invoice-1234.pdf" } }' ``` `media` accepts a public URL or a Base64 string. `mediatype` is one of `image`, `video`, `audio`, `document`. The media type must be allowed by `rules.messageTypes` and stay under the plan's size ceiling. Stickers, voice notes, templates, lists and buttons have their own sub-routes on the same prefix: `.../chats/messages/sticker`, `/send-voice-audio`, `/send-template`, `/send-list`, `/send-button` — each also taking `to` in the body. ### 5. Read chat history The recipient goes in the query string, because a `GET` has no body: ```bash curl -G https://api.pingonotify.com/v3/connections/{connectionId}/chats/messages \ -H 'apikey: sk_live_YOUR_KEY' \ --data-urlencode 'to=5511999999999' \ --data-urlencode 'page=1' \ --data-urlencode 'per_page=20' ``` Pagination is snake_case across every listing endpoint: `page`, `per_page` and `s` (free-text search). The camelCase spellings (`perPage`, `search`) are silently ignored — the request succeeds and returns the default page size. ### 6. Create a webhook ```bash curl -X POST https://api.pingonotify.com/v3/webhooks \ -H 'apikey: sk_live_YOUR_KEY' \ -H 'content-type: application/json' \ -d '{ "url": "https://example.com/hooks/pingo", "events": ["messages.upsert", "messages.update"], "connections": ["0195f3a0-1234-7890-abcd-ef0123456789"], "hmacEnabled": true, "messageGroupDelay": 5 }' ``` Then read the generated signing secret once and store it: ```bash curl https://api.pingonotify.com/v3/webhooks/{webhookId}/secret \ -H 'apikey: sk_live_YOUR_KEY' ``` Remember: omitting `connections` links the webhook to nothing and delivers nothing. ### 7. Download received media Two ways, depending on where you are: ```bash # By WhatsApp message id, authenticated with your API key curl https://api.pingonotify.com/v3/connections/chats/messages/{wamid}/download \ -H 'apikey: sk_live_YOUR_KEY' # From a webhook payload: follow the signed downloadMediaUrl as-is, no credential curl -L 'https://api.pingonotify.com/v3/connections/media/{mediaId}/download?token=...' ``` The second URL is minted by Pingo inside the webhook body, is time-limited, and is the intended path for a webhook consumer. ### 8. Act on another workspace ```bash curl https://api.pingonotify.com/v3/helpdesk/conversations \ -H 'apikey: sk_live_YOUR_KEY' \ -H 'X-Account-Id: 0195f3a0-1234-7890-abcd-ef0123456789' ``` ## Dashboard routes All routes are locale-prefixed (`/en/...` or `/pt-BR/...`) under `https://pingonotify.com`. | Route | Description | |---|---| | `/dashboard` | Overview — message usage, connection status, plan cycle progress. | | `/dashboard/connections` | Create, connect (QR, WA Sync or official API), configure and delete connections. | | `/dashboard/connections/templates` | Manage official Meta templates for an official connection (reached from the connection card, `?connectionId=`). | | `/dashboard/helpdesk/inbox` | Shared inbox. `?scope=participating` and `?scope=unattended` filter it; `?label=` filters by label. | | `/dashboard/helpdesk/contacts` | Contacts / CRM. | | `/dashboard/helpdesk/settings` | Inboxes, teams, labels, canned responses, SLA, CSAT, agent bots, AI configuration. | | `/dashboard/integrations` | Install and manage integrations from the app catalog. | | `/dashboard/members` | Workspace members and invitations. | | `/dashboard/webhooks` | Create, edit and manage webhooks — URL, events, connection scoping, HMAC. | | `/dashboard/apikeys` | Create, rotate and revoke API keys. | | `/settings` | Account profile. | | `/settings/members` | Members, from the settings side. | | `/settings/appearance` | Theme and appearance. | | `/settings/plans` | Upgrade, downgrade or switch billing cycle. | | `/settings/invoices` | Invoice history, payment status, retry failed payments. | | `/settings/billing` | Payment method and billing data. | `/plans`, `/billing` and `/dashboard/invoices` still resolve, but only as legacy redirects to `/settings/plans`, `/settings/billing` and `/settings/invoices`. `/dashboard/messages` exists as a stub and is not in the navigation — do not link to it. ## Policies and legal - [Privacy Policy (EN)](https://pingonotify.com/en/policies/privacy-policy): data collection, usage, billing, security, data sharing, user rights, contact. - [Terms of Use (EN)](https://pingonotify.com/en/policies/terms-of-use): service description, registration, plans and payments, acceptable use, API responsibilities, liability, support, cancellation, jurisdiction. - [Privacy Policy (PT-BR)](https://pingonotify.com/pt-BR/policies/privacy-policy) - [Terms of Use (PT-BR)](https://pingonotify.com/pt-BR/policies/terms-of-use) Key points: - Pingo Notify collects registration data and usage statistics. - Message credits reset each cycle and do not accumulate. - Users are solely responsible for the content of the messages they send. - The platform is not liable for instabilities of unofficial WhatsApp access. - Jurisdiction: District of Curitiba, Paraná, Brazil. - Contact: contact@pingonotify.com ## Notes - This file is a condensed entry point. The authoritative sources are the docs at https://docs.pingonotify.com and the interactive v3 reference at https://docs.pingonotify.com/en/reference/v3. - **v3** is the current and latest version of the API — the only one to build on. - The API key header is `apikey`, and the key value includes its `sk_live_` prefix. `Authorization: Bearer` is not accepted. - API keys have no scopes; they inherit the creating member's role in one workspace. - A key is displayed exactly once. If it is lost, rotate or recreate it. - The helpdesk is readable on every plan but writable only on PRO. Official connections, official campaigns and the richer message types depend on the plan. - PIX is available to Brazilian customers only (BRL). - English (`/en/*`) and Brazilian Portuguese (`/pt-BR/*`) are the only locales, on the site and in the docs. Unprefixed paths redirect (302) to the prefixed form rather than serving their own page.