{
"event": "message.delivered",
"data": {
"id": "0f4c9c0e-6d2b-4b8a-9c3e-7a1d2e3f4a5b",
"status": "delivered",
"application_id": "c2a10f3e-8b7a-4d2e-9c1a-1a2b3c4d5e6f",
"to": "+9665•• ••• 000",
"template": "order_received_v1",
"lang": "ar",
"reference": "order-1042",
"price_halalas": 0,
"error": null,
"occurred_at": "2026-09-06T09:00:04.512Z",
"created_at": "2026-09-06T09:00:01.087Z"
},
"sent_at": "1788685205201"
}Message delivered
message.delivered. Meta reports the message as delivered to the phone. Sent to the application’s webhook. Only the status reached is announced: a message that jumps to read gets one message.read. Verify tawked-signature against the raw body before trusting it, and make handling idempotent: a delivery can arrive more than once, and deliveries are not guaranteed to arrive in order.
{
"event": "message.delivered",
"data": {
"id": "0f4c9c0e-6d2b-4b8a-9c3e-7a1d2e3f4a5b",
"status": "delivered",
"application_id": "c2a10f3e-8b7a-4d2e-9c1a-1a2b3c4d5e6f",
"to": "+9665•• ••• 000",
"template": "order_received_v1",
"lang": "ar",
"reference": "order-1042",
"price_halalas": 0,
"error": null,
"occurred_at": "2026-09-06T09:00:04.512Z",
"created_at": "2026-09-06T09:00:01.087Z"
},
"sent_at": "1788685205201"
}Authorizations
Authorization: Bearer . An application key (tk_live_, tk_test_) has full access, which covers every product and any product added later, or custom access, chosen when the key is created: one or more of the scopes verify:check, verify:send (includes verify:check), notifications:read, notifications:send (includes notifications:read). A call outside the key's access answers 403 insufficient_scope and names the scope it needs in the WWW-Authenticate response header. A partner key (tk_partner_) always has full access. Whatever its access, a key is a server-side secret.
Headers
Milliseconds since the epoch, as a string; the same value as sent_at.
Hex HMAC-SHA256 of "{timestamp}.{raw body}" with your webhook secret.
The event name, the same as event in the body.
message.delivered Response
Any 2xx answer within 5 seconds acknowledges the delivery. Anything else, a redirect or no answer in time is retried: 5 attempts in all, the first at once and the next after 1 min, 5 min, 30 min, 2 h.