WhatsApp templates for store events
@sam-ael/medusa-plugin-whatsapp
Production-focused WhatsApp notification plugin for Medusa v2 with event mapping, template dispatch, and admin-managed operational controls.
Highlights
- Event -> template mapping from Medusa Admin
- WhatsApp Cloud API template sending
- Delivery logs with redacted sensitive fields
- Workflow-driven delivery for worker deployments
- Hardened API responses and stricter payload validation
- Copy to clipboard
POST /admin/whatsapp/mappings/:idas the primary update endpoint - Temporary deprecated Copy to clipboard
PUTcompatibility with deprecation headers - Secret model hardening: access token is env-only
Install
1yarn add @sam-ael/medusa-plugin-whatsapp
Medusa Configuration
123456plugins: [{resolve: "@sam-ael/medusa-plugin-whatsapp",options: {},},]
Environment Variables
12345678WHATSAPP_PHONE_NUMBER_ID=your_phone_number_idWHATSAPP_ACCESS_TOKEN=your_access_tokenWHATSAPP_API_VERSION=v25.0WHATSAPP_BUSINESS_ACCOUNT_ID=your_waba_idWHATSAPP_SEND_CONCURRENCY=2WHATSAPP_API_TIMEOUT_MS=15000WHATSAPP_LOG_RETENTION_DAYS=30
Admin API
Method Endpoint Description Copy to clipboardGET Copy to clipboard/admin/whatsapp/config Read non-secret config Copy to clipboardPOST Copy to clipboard/admin/whatsapp/config Create/update non-secret config Copy to clipboardGET Copy to clipboard/admin/whatsapp/templates Fetch approved WhatsApp templates Copy to clipboardGET Copy to clipboard/admin/whatsapp/mappings List mappings (paginated) Copy to clipboardPOST Copy to clipboard/admin/whatsapp/mappings Create mapping Copy to clipboardPOST Copy to clipboard/admin/whatsapp/mappings/:id Update mapping (primary) Copy to clipboardPUT Copy to clipboard/admin/whatsapp/mappings/:id Deprecated compatibility endpoint Copy to clipboardDELETE Copy to clipboard/admin/whatsapp/mappings/:id Delete mapping Copy to clipboardGET Copy to clipboard/admin/whatsapp/logs List message logs (redacted payloads) Copy to clipboardPOST Copy to clipboard/admin/whatsapp/manual Manual/test message send
Security and Reliability Notes
- Unified error contract: Copy to clipboard
{ success: false, code, message, details? } - Copy to clipboard
WHATSAPP_ACCESS_TOKENis not accepted in API payloads and is not persisted in DB - Redaction policy applied to sensitive request/response payload fields
- Event-send workflow uses bounded concurrency and per-item failure isolation
- Timeout controls and retention cleanup job included
- Indexes added for high-frequency lookup fields
Quality Gates
1234yarn typecheckyarn lintyarn testyarn build
Smoke tests are available under Copy to clipboardsrc/tests.
License
MIT
