Account authorization
Import authentication session
Completes authentication by importing an existing session URL or cookie/session payload. Use placeholder values in client examples and never expose session material in logs.
https://api.unifyport.ai/v1/accounts/{account_id}/auth/sessionBefore you call
Use a server-side X-Api-Key for the workspace that owns the resource. Replace every placeholder before running a sample.
WhatsApp Protocol is a separate channel identified by provider=whatsapp-protocol. It currently supports only session import (auth_mode=session), using existing session credentials to authorize an account. WhatsApp Protocol authorization
Prepare your parameters
- account_id
- Use data.id from account creation or an account query. Account identifiers belong to the workspace selected by X-Api-Key. Get account
Request parameters
Headers
X-Api-KeyWorkspace API key. The workspace is resolved from this header.
Content-TypeUse application/json when sending a JSON request body.
Path parameters
account_idIdentifier used in the authentication route.
Request body
session_urlURL or reference to an existing provider session artifact.
format: uri
whatsapp-protocolobjectWhatsApp Protocol session import credentials, accepted only by /v1/accounts/{account_id}/auth/session in this nested object, not provider_data. When supplied, phone, static_pub_key, static_pri_key, identity_pub_key and identity_pri_key are required. Responses never echo protocol keys or other sensitive credentials. phone checks identity consistency; protocol public and private keys are used only for upstream startup. edge_routing is injected by the platform and must not be submitted.
whatsapp-protocolWhatsApp Protocol session import credentials, accepted only by /v1/accounts/{account_id}/auth/session in this nested object, not provider_data. When supplied, phone, static_pub_key, static_pri_key, identity_pub_key and identity_pri_key are required. Responses never echo protocol keys or other sensitive credentials. phone checks identity consistency; protocol public and private keys are used only for upstream startup. edge_routing is injected by the platform and must not be submitted.
phonePhone input may contain spaces, hyphens, parentheses or a plus sign; the server normalizes it to a positive numeric string.
minLength: 1
platformPlatform value for WhatsApp Protocol session import (int32).
format: int32
app_versionApplication version for WhatsApp Protocol session import.
server_addressProvider server address for WhatsApp Protocol session import.
fallback_server_addresses[]Fallback server addresses for WhatsApp Protocol session import.
countryCountry code for WhatsApp Protocol session import.
deviceDevice value for WhatsApp Protocol session import (uint32).
format: uint32
static_pub_keyProtocol public key; write-only.
minLength: 1
static_pri_keyProtocol private key; write-only.
minLength: 1
identity_pub_keyIdentity public key; write-only.
minLength: 1
identity_pri_keyIdentity private key; write-only.
minLength: 1
hashDeprecated compatibility field; its value is ignored and not stored. Omit it.
peer_kem_publicPeer KEM public key; write-only.
auth_hex_dataCurrent authentication data in hexadecimal; write-only.
authhexdataDeprecated legacy authentication data field in hexadecimal; write-only.
pq_handshake_modePQ handshake mode for WhatsApp Protocol session import.
use_xxkem_handshakeWhether to use the XXKEM handshake for WhatsApp Protocol session import.
Understand the result
Read the authorization result, then check runtime_status. Session import and an active connection are different milestones.
Response 200 OK
{
"request_id": "<REQUEST_ID>",
"data": {
"account_id": "acc_example",
"status": "authorized"
}
}
Response body
account_idProvider account this response refers to.
statusCurrent authorization flow status, for example pending_auth, awaiting_qr_scan, awaiting_code, pending, passkey_required, passkey_pending, passkey_confirmation, passkey_confirmation_sent, authorized, or failed.
Responses
200200 OK
Request succeeded. See the example response body.
400Bad Request
The request body, path, or parameters are invalid.
401Unauthorized
The X-Api-Key header is missing or invalid.
409Conflict
The requested operation conflicts with an existing provider account or resource.
500Internal Server Error
The service encountered an unexpected error.
502Bad Gateway
The provider adapter or upstream provider could not complete the operation.
If the request fails
Inspect HTTP status and error.code/numeric_code, and keep request_id for diagnosis. Correct invalid parameters, complete required authorization or check runtime state as appropriate. Confirm the outcome before retrying a send or another write. Error reference
- invalid_request · 10000 · 400
- Check required fields, formats and channel conditions, then correct the request.
- invalid_api_key · 11001 · 401
- Check X-Api-Key and whether the workspace is active.
- provider_invalid_request · 30001 · 400
- Check required fields, formats and channel conditions, then correct the request.