Download the PHP package tabi/sdk without Composer
On this page you can find all versions of the php package tabi/sdk. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Informations about the package sdk
tabi/sdk
Official PHP SDK for the Tabi WhatsApp Business Messaging API.
Table of Contents
- Installation
- Getting Started
- Configuration
- OTP over WhatsApp
- Resource groups
- Resources
- Auth
- Channels
- Messages
- Contacts
- Conversations
- Webhooks
- API Keys
- Files
- Campaigns
- Automation Templates
- Automation Installs
- Quick Replies
- Analytics
- Notifications
- Integrations
- Workspaces
- Error Handling
- Return values
- Requirements
- Related
- Support
- License
Installation
Getting Started
Credential sources
| Value | Location |
|---|---|
| API key / JWT | Dashboard → Developer → API Keys (or login flow for JWT) |
| Base URL | https://api.tabi.africa/api/v1 (default when the second constructor argument is omitted) |
| Channel ID | Dashboard → Channels → open a channel → copy the ID from the URL |
Configuration
OTP over WhatsApp
Hosted OTP uses Tabi\SDK\Resources\Channels::sendOtp and verifyOtp, which map to POST /channels/{channelId}/otp/send and POST /channels/{channelId}/otp/verify on the Tabi API.
Hosted OTP (recommended)
- Create or reuse a workspace API key (or JWT) with the same scopes as
messages()->send()(for examplemessages:send). - Call
sendOtpwith the channel UUID and an E.164phonevalue. - Call
verifyOtpwith the same channel,phone, and the code the user submitted.
REST: POST /api/v1/channels/{channelId}/otp/send and POST /api/v1/channels/{channelId}/otp/verify.
Security: Call these endpoints only from server-side code. Client applications must talk to the integrator’s backend; the Tabi API key must not be embedded in mobile or browser clients.
Compliance and rate limits
- OTP traffic shares the same WhatsApp Business channel and rate limits as other sends.
- Follow Meta / WhatsApp Business policies for templates, opt-in, and account configuration (Meta Business Manager).
- Limit OTP to legitimate verification flows (for example sign-in); do not use it for cold outreach or bulk marketing.
Custom OTP (without hosted routes)
- Generate codes and store hashes in application-controlled storage (for example Redis).
- Deliver the code with
messages()->send(), usingmessageClassand other fields as required by the HTTP API reference for transactional messages.
Resource groups (feature areas)
The SDK mirrors how the Tabi API is organised. Each method on TabiClient returns a resource object mapped to one REST area.
| Group | Client methods | What it covers |
|---|---|---|
| Getting started | auth(), workspaces() |
Login/register/tokens; workspaces, members, invites |
| Messaging & inbox | channels(), messages(), conversations(), contacts(), quickReplies(), notifications() |
WhatsApp lines, sends, threads, people, shortcuts |
| Automations & campaigns | automationTemplates(), automationInstalls(), campaigns() |
Template catalog, installed flows, broadcasts |
| Integrations | apiKeys(), webhooks(), integrations() |
Keys (create with JWT), outbound webhooks, third-party links |
| Media & insights | files(), analytics() |
Uploads, KPIs |
Request parameters: Resource methods document JSON bodies and query maps in PHPDoc using array{ key: type, … } shapes. These mirror the REST DTOs in the HTTP API reference (OpenAPI schemas).
Resources
Auth
Login, register, refresh tokens, session helpers, and invite preview.
Channels
Create, list, connect, and manage WhatsApp channels.
Messages
Send text and rich messages, list timeline, reply, reactions, and media.
Contacts
Create, update, import, tags, and consent.
Conversations
List, update, resolve, reopen, and read state.
Webhooks
Subscriptions, delivery logs, secrets, and test capture.
API Keys
Create and manage API keys. Creating keys requires a user JWT from the dashboard (not an API key).
| Field | Type | Required | Description |
|---|---|---|---|
name |
string | yes | Label in the dashboard |
channelId |
string (UUID) | no | Restrict key to one channel |
scopes |
string[] | no | e.g. ['channels:read', 'messages:send']; omit for full access in scope |
expiresAt |
ISO 8601 string | no | Key stops working after this time |
Files
List files, metadata, signed URLs, delete.
Campaigns
Draft, schedule, and control broadcast campaigns.
Automation Templates
Browse the template catalog.
Automation Installs
Install, configure, enable/disable, uninstall.
Quick Replies
Canned responses for agents.
Analytics
Dashboard and reporting ranges (pass date/query params as arrays).
Notifications
In-app notification inbox.
Integrations
Third-party providers (CRM, helpdesk, etc.).
Workspaces
Workspaces and team members.
Error Handling
Failed HTTP responses throw Tabi\SDK\TabiException with the status code and decoded body when available.
Common HTTP status codes
| Status | Meaning |
|---|---|
400 |
Bad request — check your payload |
401 |
Unauthorized — invalid or expired token |
403 |
Forbidden — insufficient permissions |
404 |
Not found |
409 |
Conflict — duplicate or invalid state |
429 |
Rate limited — retry with backoff |
500 |
Server error — contact support |
Return values
Successful responses that use the API’s { "success": true, "data": ... } envelope return the data value only (typically an array). Other successful shapes are returned as decoded JSON (mixed). Refer to the API docs for each endpoint’s schema.
Requirements
- PHP >= 8.1
- Extensions: curl, json
Related
- JavaScript / TypeScript:
tabi-sdkon npm - HTTP reference: tabi.africa/api-docs
Support
- Product overview: tabi.africa/sdks
- HTTP API reference: tabi.africa/api-docs
License
MIT — see LICENSE for details.
All versions of sdk with dependencies
ext-curl Version *
ext-json Version *