Connect baseNode to everything else.
One call to send a template, signed webhooks for every event, and inbound URLs for leads and bookings. Works with Zapier, Make, n8n, Google Sheets, HubSpot, Pipedrive, Slack, Teams, Telegram, Calendly and Cal.com.
1. Authenticate
Create an API key in Settings, Developer API. Choose read-only or read and write, and an expiry. Send it as X-API-Key. Keys can't create other keys, and every request is rate-limited per key.
curl https://YOUR-API/contacts -H "X-API-Key: bn_live_..."
2. Send a template
One endpoint for no-code tools and scripts. It creates the contact if needed. Marketing templates need consent: true, which records your proof of opt-in (and the source you give).
POST /send
{
"phone": "98765 43210",
"template": "order_ready",
"params": ["Ravi", "#1042"],
"name": "Ravi",
"tags": ["web-order"],
"consent": true,
"consent_source": "checkout"
}Google Apps Script: UrlFetchApp.fetch(url, {method: "post", contentType: "application/json", headers: {"X-API-Key": key}, payload: JSON.stringify(body)})
3. Receive events (signed webhooks)
Add an endpoint in Settings, Webhooks, choose events, and copy the signing secret. Each delivery carries X-Basenode-Signature: sha256=…, an HMAC-SHA256 of the raw body. Failed deliveries are retried and logged. Private and internal addresses are refused.
message.receivedmessage.statusconversation.resolvedcontact.opted_outform.submittedcsat.receivedcampaign.completeddeal.stage_changedpayment.receivedappointment.createdimport hmac, hashlib
def valid(secret: str, body: bytes, header: str) -> bool:
expected = "sha256=" + hmac.new(secret.encode(), body, hashlib.sha256).hexdigest()
return hmac.compare_digest(expected, header)4. Bring leads and bookings in
In the app, Connections gives you private URLs. Post a lead from any form, ad or site, and a workflow can reply on WhatsApp within seconds.
POST /inbound/lead/<token>
{"name": "Asha", "phone": "98765 43210", "source": "facebook",
"consent": true, "city": "Vizag"} # extra fields become custom fieldsCalendly and Cal.com bookings post to their own URLs. Signatures are verified (Calendly with a signing key and timestamp, Cal.com with an HMAC), and each booking becomes an appointment with automatic reminders.