View as Markdown Open in ChatGPT Open in Claude
POST
WhatsApp API · Media · v3.0

Retrieve media file handle - Step 2 : Create a Session

This API is used to initiate the upload session by sending a POST request and append your upload session {id} along with the required headers indicated below. Upon success, a file handle, {h}, is returned that you can then use with any Partners API endpoints that support file handles returned by the Resumable Upload API.

https://partnersv1.pinbot.ai/v3/upload:MTphdHRhY2htZW50OjNlYTE1ZTkzLTZkZDktNGIwOS1iOTM3LWM4YWZmMTRkYTZkMz9maWxlX2xlbmd0aD0xNjQzMTMmZmlsZV90eXBlPXZpZGVvJTJGbXA0
infoOverview

About this API

This API is used to initiate the upload session by sending a POST request and append your upload session {id} along with the required headers indicated below. Upon success, a file handle, {h}, is returned that you can then use with any Partners API endpoints that support file handles returned by the Resumable Upload API.

keySecurity

Authentication

Include your API credential in the request header. Keep credentials on the server and never expose them in client-side applications.

Locationheader
Field nameapikey
Example valueYOUR_WABA_API_KEY
tuneParameters

Query Parameters

Append these values to the URL query string. Omit optional parameters when they are not needed.

NameTypeRequirementDescription
sigstringNot specifiedRequest value for sig.
uploadInput

Request Body

Send a application/json payload. Replace placeholder values with data from your integration.

{
  "sig": "ARbUFIDlNcIbRnOalIY"
}
{
  "type": "object",
  "properties": {
    "sig": {
      "type": "string",
      "x-parameter-in": "query"
    }
  }
}
codeIntegration

Code Examples

Select your language and customize the request URL. Credential placeholders are intentionally preserved so secrets never appear in generated samples.

shield_lockCredentials protectedAdd secrets only in your secure server environment.
downloadSDK
curl --request POST 'https://partnersv1.pinbot.ai/v3/upload:MTphdHRhY2htZW50OjNlYTE1ZTkzLTZkZDktNGIwOS1iOTM3LWM4YWZmMTRkYTZkMz9maWxlX2xlbmd0aD0xNjQzMTMmZmlsZV90eXBlPXZpZGVvJTJGbXA0' \
  --header 'apikey: <API_KEY>' \
  --header 'Content-Type: application/json' \
  --data '{
  "sig": "ARbUFIDlNcIbRnOalIY"
}'
const response = await fetch('https://partnersv1.pinbot.ai/v3/upload:MTphdHRhY2htZW50OjNlYTE1ZTkzLTZkZDktNGIwOS1iOTM3LWM4YWZmMTRkYTZkMz9maWxlX2xlbmd0aD0xNjQzMTMmZmlsZV90eXBlPXZpZGVvJTJGbXA0', {
  method: 'POST',
  headers: {
    "apikey": "<API_KEY>",
    "Content-Type": "application/json"
  },
  body: JSON.stringify({
    "sig": "ARbUFIDlNcIbRnOalIY"
  })
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
const data = await response.json();
console.log(data);
const response = await fetch('https://partnersv1.pinbot.ai/v3/upload:MTphdHRhY2htZW50OjNlYTE1ZTkzLTZkZDktNGIwOS1iOTM3LWM4YWZmMTRkYTZkMz9maWxlX2xlbmd0aD0xNjQzMTMmZmlsZV90eXBlPXZpZGVvJTJGbXA0', {
  method: 'POST',
  headers: {
    "apikey": "<API_KEY>",
    "Content-Type": "application/json"
  },
  body: JSON.stringify({
    "sig": "ARbUFIDlNcIbRnOalIY"
  })
});

if (!response.ok) throw new Error(`HTTP ${response.status}`);
const data = await response.json();
console.log(data);
import json
import requests

url = 'https://partnersv1.pinbot.ai/v3/upload:MTphdHRhY2htZW50OjNlYTE1ZTkzLTZkZDktNGIwOS1iOTM3LWM4YWZmMTRkYTZkMz9maWxlX2xlbmd0aD0xNjQzMTMmZmlsZV90eXBlPXZpZGVvJTJGbXA0'
headers = {
  "apikey": "<API_KEY>",
  "Content-Type": "application/json"
}
payload = json.loads(r'''{
  "sig": "ARbUFIDlNcIbRnOalIY"
}''')
response = requests.post(url, headers=headers, json=payload)

response.raise_for_status()
print(response.json())
import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;

var client = HttpClient.newHttpClient();
String body = """
{
  "sig": "ARbUFIDlNcIbRnOalIY"
}
""";
var request = HttpRequest.newBuilder(URI.create("https://partnersv1.pinbot.ai/v3/upload:MTphdHRhY2htZW50OjNlYTE1ZTkzLTZkZDktNGIwOS1iOTM3LWM4YWZmMTRkYTZkMz9maWxlX2xlbmd0aD0xNjQzMTMmZmlsZV90eXBlPXZpZGVvJTJGbXA0"))
    .header("apikey", "<API_KEY>")
    .header("Content-Type", "application/json")
    .method("POST", HttpRequest.BodyPublishers.ofString(body))
    .build();

var response = client.send(request, HttpResponse.BodyHandlers.ofString());
System.out.println(response.statusCode());
System.out.println(response.body());
<?php
$curl = curl_init();
$payload = '{
  "sig": "ARbUFIDlNcIbRnOalIY"
}';
curl_setopt_array($curl, [
    CURLOPT_URL => 'https://partnersv1.pinbot.ai/v3/upload:MTphdHRhY2htZW50OjNlYTE1ZTkzLTZkZDktNGIwOS1iOTM3LWM4YWZmMTRkYTZkMz9maWxlX2xlbmd0aD0xNjQzMTMmZmlsZV90eXBlPXZpZGVvJTJGbXA0',
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_CUSTOMREQUEST => 'POST',
    CURLOPT_HTTPHEADER => ["apikey: <API_KEY>","Content-Type: application/json"],
    CURLOPT_POSTFIELDS => $payload,
]);
$response = curl_exec($curl);
if ($response === false) throw new Exception(curl_error($curl));
curl_close($curl);
echo $response;
using System.Net.Http.Headers;
using System.Text;

using var client = new HttpClient();
client.DefaultRequestHeaders.Add("apikey", "<API_KEY>");
var json = """
{
  "sig": "ARbUFIDlNcIbRnOalIY"
}
""";
using var content = new StringContent(json, Encoding.UTF8, "application/json");
var response = await client.PostAsync("https://partnersv1.pinbot.ai/v3/upload:MTphdHRhY2htZW50OjNlYTE1ZTkzLTZkZDktNGIwOS1iOTM3LWM4YWZmMTRkYTZkMz9maWxlX2xlbmd0aD0xNjQzMTMmZmlsZV90eXBlPXZpZGVvJTJGbXA0", content);
response.EnsureSuccessStatusCode();
Console.WriteLine(await response.Content.ReadAsStringAsync());
package main

import (
    "fmt"
    "io"
    "net/http"
    "bytes"
)

func main() {
    request, err := http.NewRequest("POST", "https://partnersv1.pinbot.ai/v3/upload:MTphdHRhY2htZW50OjNlYTE1ZTkzLTZkZDktNGIwOS1iOTM3LWM4YWZmMTRkYTZkMz9maWxlX2xlbmd0aD0xNjQzMTMmZmlsZV90eXBlPXZpZGVvJTJGbXA0", bytes.NewBufferString("{\n  \"sig\": \"ARbUFIDlNcIbRnOalIY\"\n}"))
    if err != nil { panic(err) }
    request.Header.Set("Content-Type", "application/json")
    request.Header.Set("Accept", "application/json")
    request.Header.Set("apikey", "<API_KEY>")
    response, err := http.DefaultClient.Do(request)
    if err != nil { panic(err) }
    defer response.Body.Close()
    data, err := io.ReadAll(response.Body)
    if err != nil { panic(err) }
    if response.StatusCode >= 400 { panic(fmt.Sprintf("HTTP %d: %s", response.StatusCode, data)) }
    fmt.Println(string(data))
}
downloadOutput

Response

A successful request returns the documented response payload. Delivery and asynchronous events may arrive separately through configured webhooks.

{
"h":
"4::dmlkZW8vbXA0:ARa3wu4QWKmzupRJa-dmysHBZrmo4TxDVwJgvvtbhvqMqPb-UC
GRtNE_S6FjueRXMCx_SDgd9JEQ6IYQKfgEOKM-IAQyzIH-fDz10LSpckfiWA:e:171688
5369:769756078280509:100083728822881:ARYnUsRqjwJdiFsDk9c"
}
{
  "type": "object",
  "properties": {
    "raw_example": {
      "type": "string"
    }
  }
}
ruleHTTP Responses

Status Codes

200The request was successful.
400Bad request or invalid parameters.
401API key is missing or invalid.
403The request is not authorized for this resource.
404The requested resource was not found.
500The server encountered an error.
Global API SearchProducts, versions, endpoints, paths, and payload fields
Esc
Full search page
manage_searchSearch the complete API catalogEnter at least two characters to begin.