Create connector

Names are unique per app. Credentials can be set here or later through the upsert routes.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…

Request parameters

ParameterTypeRequiredInDescription
AuthorizationstringYesHeaderPartner app token, sent raw. Bearer <token> is also accepted.
Content-TypestringYesHeaderapplication/json
appIdstring (uuid)YesPathPartner Portal app id. Stands in for Meta's entity_id.
namestringYesBodyUnique per app.
descriptionstringYesBodyHuman-readable description.
base_urlstringYesBodyRoot URL the connector calls.
connector_protocolstringNoBodyOne of: HTTP, MCP. Default HTTP.
auth_typestringYesBodyThe only supported values. connector_protocol cannot change after creation. One of: OAUTH2_CLIENT_CREDENTIALS, API_KEY, NONE.
auth_configobjectNoBodySet the block matching auth_type.
auth_config.api_keyobjectNoBodyAt least one of the three lists must be non-empty.
auth_config.api_key.headersarray of objectNoBodyEntries sent as HTTP headers.
auth_config.api_key.headers[].field_namestringYesBodyHeader, query or body field name.
auth_config.api_key.headers[].valuestringYesBodyWrite-only; never returned.
auth_config.api_key.headers[].prefixstringNoBodye.g. Bearer .
auth_config.api_key.query_paramsarray of objectNoBodyEntries sent as query parameters.
auth_config.api_key.query_params[].field_namestringYesBodyHeader, query or body field name.
auth_config.api_key.query_params[].valuestringYesBodyWrite-only; never returned.
auth_config.api_key.query_params[].prefixstringNoBodye.g. Bearer .
auth_config.api_key.body_paramsarray of objectNoBodyEntries sent in the request body.
auth_config.api_key.body_params[].field_namestringYesBodyHeader, query or body field name.
auth_config.api_key.body_params[].valuestringYesBodyWrite-only; never returned.
auth_config.api_key.body_params[].prefixstringNoBodye.g. Bearer .
auth_config.oauth2_client_credentialsobjectNoBodyOAuth 2.0 client-credentials settings.
auth_config.oauth2_client_credentials.token_urlstringYesBodyOAuth token endpoint.
auth_config.oauth2_client_credentials.scopes_to_requestarray of stringNoBodyOAuth scopes to request.
auth_config.oauth2_client_credentials.token_request_content_typestringNoBodyOne of: application/x-www-form-urlencoded, application/json.
auth_config.oauth2_client_credentials.client_idstringYesBodyOAuth client id.
auth_config.oauth2_client_credentials.client_secretstringYesBodyWrite-only; never returned.
user_auth_injection_configobjectNoBodyWhere the consumer's own auth token is injected on outbound calls.
user_auth_injection_config.locationstringYesBodyOne of: body, headers, path, query.
user_auth_injection_config.field_namestringYesBodyHeader, query or body field name.
user_auth_injection_config.prefixstringYesBodyText placed before the value, e.g. Bearer .
requires_certificatebooleanNoBodytrue if outbound calls need a client certificate (mTLS).

Example request

curl --location --request POST 'https://partner.gupshup.io/partner/app/<appId>/bizai/agent_connectors' \
  --header 'Authorization: <PARTNER_APP_TOKEN>' \
  --header 'Content-Type: application/json' \
  --data '{
  "name": "Shopify Order Management",
  "description": "Connects to Shopify API for managing customer orders and inventory",
  "base_url": "https://api.shopify.com",
  "connector_protocol": "HTTP",
  "auth_type": "API_KEY",
  "auth_config": {
    "api_key": {
      "headers": [
        {
          "field_name": "X-Shopify-Access-Token",
          "value": "your-token",
          "prefix": ""
        }
      ]
    }
  },
  "requires_certificate": false
}'

Response parameters — 201

ParameterTypeDescription
idstringResource id. Meta pfbid… id.
namestringName.
descriptionstringHuman-readable description.
base_urlstringRoot URL the connector calls.
connector_protocolstringOne of: HTTP, MCP.
auth_typestringOne of: OAUTH2_CLIENT_CREDENTIALS, API_KEY, NONE.
auth_configobjectCredentials for the chosen auth_type.
user_auth_injection_configobjectWhere the consumer's own auth token is injected on outbound calls.
user_auth_injection_config.locationstringOne of: body, headers, path, query.
user_auth_injection_config.field_namestringHeader, query or body field name.
user_auth_injection_config.prefixstringText placed before the value, e.g. Bearer .
connection_statusobjectWhether the connector's credentials work.
connection_status.statusstringOne of: PENDING_OAUTH, ACTIVE, EXPIRED, ERROR.
connection_status.error_messagestringError text.
mcp_tool_syncobject / nullNull for HTTP connectors.
mcp_tool_sync.statusstringOne of: ERROR, PENDING, READY.
mcp_tool_sync.last_attempted_atintegerLast attempt, Unix seconds.
mcp_tool_sync.last_successful_atintegerLast success, Unix seconds.
mcp_tool_sync.fingerprintstringHash identifying the stored value.
mcp_tool_sync.tool_countintegerNumber of tools discovered.
mtls_configobjectClient certificate status. The private key is never returned.
mtls_config.has_certificatebooleantrue if a certificate is stored.
mtls_config.fingerprintstringHash identifying the stored value.
mtls_config.expires_atintegerExpiry, Unix seconds.
mtls_config.subjectstringCertificate subject.
mtls_config.client_certificatestringStored client certificate, PEM.
mtls_config.ca_certificatestringStored CA chain, PEM.

Example response — 201 Created

{
  "id": "pfbid0ConnectorExampleId",
  "name": "Shopify Order Management",
  "description": "Connects to Shopify API for managing customer orders and inventory",
  "base_url": "https://api.shopify.com",
  "connector_protocol": "HTTP",
  "auth_type": "API_KEY",
  "auth_config": {
    "api_key": {
      "headers": [
        {
          "field_name": "X-Shopify-Access-Token",
          "prefix": ""
        }
      ]
    }
  },
  "connection_status": {
    "status": "ACTIVE"
  },
  "mcp_tool_sync": null,
  "mtls_config": {
    "has_certificate": false
  }
}

Error responses

400 Bad Request — The app is not live, or WASS does not consider it live.

{
  "message": "App is not live.",
  "status": "error"
}

400 Bad Request — The app has no phone number attached. Checked before the live check.

{
  "message": "Phone id not found for the given App",
  "status": "error"
}

401 Unauthorized — Authorization is missing or invalid, belongs to another app, or appId is unknown or not a UUID.

{
  "status": "error",
  "message": "Unauthorised access to the resource. Please review request parameters and headers and retry"
}

405 Method Not Allowed — Any method other than GET, POST, PUT or DELETE, e.g. PATCH.

{
  "status": "error",
  "message": "Request method 'PATCH' is not supported"
}

429 Too Many Requests — More than 30 /bizai/** requests in 60 seconds for this app. The 31st is rejected.

{
  "status": "error",
  "message": "Too Many Requests"
}
Path Params
uuid
required

Partner Portal app id. Stands in for Meta's entity_id.

Body Params
string
required

Unique per app.

string
required
uri
required
string
enum
Defaults to HTTP
Allowed:
string
enum
required

The only supported values. connector_protocol cannot change after creation.

Allowed:
auth_config
object

Set the block matching auth_type.

user_auth_injection_config
object

Where the consumer's own auth token is injected on outbound calls.

boolean
Responses

429

Per-app rate limit exceeded. Retry after the 60-second window.

Language
Credentials
Header
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json