When groups via API make sense
Managing a group from the phone works until the day you have forty cohorts, each with students joining and leaving every week. From then on, someone spends the afternoon adding numbers and removing people who stopped paying, and makes mistakes. The groups API takes over that manual work, and who gets in is decided by your system's rules, not by the memory of whoever runs the group.
The most common scenarios:
- Classes and courses: one group per cohort, created when the cohort opens, with students joining when enrollment is confirmed and leaving when access ends. Edtech platforms rely heavily on this model.
- Customer communities: groups for subscribers of a plan, with join requests approved automatically when the subscription is active.
- VIP or onboarding support: one group per customer with the support team, created when the contract is signed.
- Internal operations: groups for field teams or stores, with admins set by job role in the HR system.
What the groups API can do
| Action | Route | SDK method |
|---|---|---|
| Create a group | POST /groups/create | groups.create |
| Add, remove, promote, demote | POST /groups/{groupId}/participants | groups.manageParticipants |
| Invite link and revocation | GET /groups/{groupId}/invite, POST .../invite/revoke | getInviteLink, revokeInviteLink |
| Name, description and photo | PUT .../name, .../description, .../profile-picture | setName, setDescription, setPicture |
| Settings | PUT /groups/{groupId}/settings | setSettings |
| Join requests | POST .../join-requests/approve and /reject | approveJoinRequests, rejectJoinRequests |
| List and look up | GET /groups/list, GET .../info | list, getInfo |
Step by step: from a new cohort to a ready group
- Create the group with its rules in place. At creation, set whether only admins can send messages (
admin_only_messages), whether joining requires approval (admin_approval) and whether only admins can add people (admin_add_only). - Store the group ID next to the cohort in your database. Every following operation uses it.
- Promote the teacher or the person in charge to admin, so a human can moderate too.
- Share the invite link in the welcome email or the student area.
- Approve requests from the webhook, checking each number's enrollment.
import { DApi } from 'd-api-sdk'
const dapi = new DApi({ apiKey: process.env.DAPI_KEY })
const { groupId } = await dapi.groups.create({
sessionId: 'school',
name: 'Python Cohort - October',
participants: ['14155550123'],
description: 'Announcements and questions for the cohort',
admin_only_messages: false,
admin_approval: true,
})
// store the groupId with the cohort before moving on
await dapi.groups.manageParticipants(groupId, {
sessionId: 'school',
participants: ['14155550123'],
action: 'promote',
})
await dapi.groups.setSettings(groupId, {
sessionId: 'school',
memberAddMode: 'admin',
})Settings and join approval
Once created, the group can be adjusted at /groups/{groupId}/settings:
announce: only admins can send messages. Good for announcement channels.locked: only admins can edit the name, description and photo.joinApproval: people joining through the link need to be approved.memberAddMode:adminso only admins can add people,allto open it up.
Join approval is what makes the invite link safe. The link may leak, but anyone not in your database does not get in. And if it leaks too widely, revoke the link and generate a new one.
Group events on the webhook
Group activity reaches your webhook as dedicated events:
groups_participants.join,.leave,.promoteand.demote, with the group, the affected participants and who performed the action.group_participants.join-requestwhen someone asks to join, plus the.approvedand.revokedvariants.
Treat these events as the source of truth. If a human admin removes someone from the phone, the leave event arrives and your system updates the enrollment, with no side spreadsheet.
As a safety net, run a periodic reconciliation: look up the group with getInfo, compare the participants with who should be there, and fix the differences. That covers events your receiver failed to process and changes made while the integration was off. For short-lived cohorts, it is also worth creating the group with disappearing_messages turned on, so the history is not kept longer than needed.
How to keep groups from becoming spam
Groups are the WhatsApp feature with the highest potential for reports. Adding someone who was not expecting it, to a group that pushes promotions all day, is the shortest path to getting the number blocked. A few rules:
- Prefer an invite link with approval over adding people directly.
- Space out group creation and bulk adds; do not do everything in the same minute.
- Make it clear in the description why the group exists and how to leave.
- Separate numbers: the one that manages groups should not be your main support number.
More details in how to avoid bans. Groups are a feature of the unofficial WhatsApp API, connected by QR code; see what else it offers on the unofficial WhatsApp API page.
