Can my own AI read WhatsApp messages through a webhook, without automated replies?
In short: yes, including on the free plan. Every incoming message is delivered to your webhook, your AI works on it, and your team keeps replying from the WhatsApp Business app. ZapClaw never sends a message on its own.
How it works
- Connect your number through Coexistence, so it keeps working in the WhatsApp Business app on your phone.
- Set your webhook URL in the ZapClaw dashboard. Every inbound message arrives as a signed JSON
POST(X-ZapClaw-Signature, HMAC-SHA256). - Your system reads it, for example a local AI that prepares a draft answer.
- A person sends the reply from the WhatsApp Business app. The send API stays optional.
The one requirement: a public HTTPS address
ZapClaw only delivers to a public https:// URL. It refuses localhost, private and internal IP ranges, and hostnames that resolve to them, even after a redirect. If your AI runs on your own machine or office network, put a public HTTPS entry point in front of it, such as a reverse proxy or a tunnel you control, and check the signature on every request.
On the free plan
Sent and received messages both count toward the 500 per month; messages typed on the phone do not. If your endpoint is down, ZapClaw makes up to 3 delivery attempts per event, and failed events stay in the delivery log so you can replay them from the dashboard.
The payloads and the signature check are in the webhook documentation.