curl --request PUT \
--url https://your-instance.example.com/api/sessions/{session}/client-rules \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"allowedActions": "send_message,send_reaction,send_typing",
"allowedOrigins": "https://myapp.com,https://staging.myapp.com",
"enabled": true,
"maxDaily": 100,
"rateLimit": 5,
"recipientMode": "conversation"
}
'const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
allowedActions: 'send_message,send_reaction,send_typing',
allowedOrigins: 'https://myapp.com,https://staging.myapp.com',
enabled: true,
maxDaily: 100,
rateLimit: 5,
recipientMode: 'conversation'
})
};
fetch('https://your-instance.example.com/api/sessions/{session}/client-rules', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://your-instance.example.com/api/sessions/{session}/client-rules"
payload = {
"allowedActions": "send_message,send_reaction,send_typing",
"allowedOrigins": "https://myapp.com,https://staging.myapp.com",
"enabled": True,
"maxDaily": 100,
"rateLimit": 5,
"recipientMode": "conversation"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://your-instance.example.com/api/sessions/{session}/client-rules"
payload := strings.NewReader("{\n \"allowedActions\": \"send_message,send_reaction,send_typing\",\n \"allowedOrigins\": \"https://myapp.com,https://staging.myapp.com\",\n \"enabled\": true,\n \"maxDaily\": 100,\n \"rateLimit\": 5,\n \"recipientMode\": \"conversation\"\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-instance.example.com/api/sessions/{session}/client-rules",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'allowedActions' => 'send_message,send_reaction,send_typing',
'allowedOrigins' => 'https://myapp.com,https://staging.myapp.com',
'enabled' => true,
'maxDaily' => 100,
'rateLimit' => 5,
'recipientMode' => 'conversation'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"allowedActions": "send_message,send_reaction,send_typing",
"allowedOrigins": "https://myapp.com,https://staging.myapp.com",
"enabled": true,
"maxDaily": 100,
"rateLimit": 5,
"recipientMode": "conversation"
}{
"docs": "https://docs.polymorfa.com/api/messages/send",
"error": "missing required field: chatId"
}{
"error": "missing or invalid API key"
}{
"docs": "<string>",
"error": "<string>"
}Set client rules
Creates or updates the client token rules for a session. These rules are enforced on every client token request in real time.
curl --request PUT \
--url https://your-instance.example.com/api/sessions/{session}/client-rules \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"allowedActions": "send_message,send_reaction,send_typing",
"allowedOrigins": "https://myapp.com,https://staging.myapp.com",
"enabled": true,
"maxDaily": 100,
"rateLimit": 5,
"recipientMode": "conversation"
}
'const options = {
method: 'PUT',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
allowedActions: 'send_message,send_reaction,send_typing',
allowedOrigins: 'https://myapp.com,https://staging.myapp.com',
enabled: true,
maxDaily: 100,
rateLimit: 5,
recipientMode: 'conversation'
})
};
fetch('https://your-instance.example.com/api/sessions/{session}/client-rules', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));import requests
url = "https://your-instance.example.com/api/sessions/{session}/client-rules"
payload = {
"allowedActions": "send_message,send_reaction,send_typing",
"allowedOrigins": "https://myapp.com,https://staging.myapp.com",
"enabled": True,
"maxDaily": 100,
"rateLimit": 5,
"recipientMode": "conversation"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.put(url, json=payload, headers=headers)
print(response.text)package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://your-instance.example.com/api/sessions/{session}/client-rules"
payload := strings.NewReader("{\n \"allowedActions\": \"send_message,send_reaction,send_typing\",\n \"allowedOrigins\": \"https://myapp.com,https://staging.myapp.com\",\n \"enabled\": true,\n \"maxDaily\": 100,\n \"rateLimit\": 5,\n \"recipientMode\": \"conversation\"\n}")
req, _ := http.NewRequest("PUT", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://your-instance.example.com/api/sessions/{session}/client-rules",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PUT",
CURLOPT_POSTFIELDS => json_encode([
'allowedActions' => 'send_message,send_reaction,send_typing',
'allowedOrigins' => 'https://myapp.com,https://staging.myapp.com',
'enabled' => true,
'maxDaily' => 100,
'rateLimit' => 5,
'recipientMode' => 'conversation'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}{
"allowedActions": "send_message,send_reaction,send_typing",
"allowedOrigins": "https://myapp.com,https://staging.myapp.com",
"enabled": true,
"maxDaily": 100,
"rateLimit": 5,
"recipientMode": "conversation"
}{
"docs": "https://docs.polymorfa.com/api/messages/send",
"error": "missing required field: chatId"
}{
"error": "missing or invalid API key"
}{
"docs": "<string>",
"error": "<string>"
}Authorizations
Scoped API key created via POST /api/account/keys.
Path Parameters
Session name
Body
Rules
AllowedActions is a comma-separated list of actions client tokens can perform. e.g. "send_message,send_reaction,send_typing,send_seen,read_presence"
"send_message,send_reaction,send_typing"
AllowedOrigins is a comma-separated list of origins for CORS enforcement.
"https://myapp.com,https://staging.myapp.com"
Enabled controls whether client tokens are accepted for this session.
true
MaxDaily is the max messages per day per ephemeral session.
100
RateLimit is the max requests per minute per ephemeral session.
5
RecipientMode controls who client tokens can message. "conversation" = only reply to JIDs that messaged first. "any" = no restriction. "verified" = only message verified JIDs (future). "none" = read-only, no sending.
"conversation"
Response
OK
AllowedActions is a comma-separated list of actions client tokens can perform. e.g. "send_message,send_reaction,send_typing,send_seen,read_presence"
"send_message,send_reaction,send_typing"
AllowedOrigins is a comma-separated list of origins for CORS enforcement.
"https://myapp.com,https://staging.myapp.com"
Enabled controls whether client tokens are accepted for this session.
true
MaxDaily is the max messages per day per ephemeral session.
100
RateLimit is the max requests per minute per ephemeral session.
5
RecipientMode controls who client tokens can message. "conversation" = only reply to JIDs that messaged first. "any" = no restriction. "verified" = only message verified JIDs (future). "none" = read-only, no sending.
"conversation"