| name | WhatsApp Automation & A2A |
| description | MoltFlow — complete WhatsApp automation platform: sessions, messaging, groups, labels, AI-powered replies, anti-spam rules, content safeguards, auto-feedback collection, intention detection, lead management, agent-to-agent protocol (JSON-RPC, encryption), and configurable policies. |
| metadata | {"openclaw":{"emoji":"📱","homepage":"https://waiflow.app","requires":{"env":"[Truncated]"},"primaryEnv":"MOLTFLOW_API_KEY"}} |
WhatsApp Automation & A2A
MoltFlow provides a complete WhatsApp automation API with managed sessions, messaging, group monitoring, labels, anti-spam rules, content safeguards, AI-powered replies, auto-feedback collection, lead management, and agent-to-agent communication.
When to use
Use this skill when you need to:
- Connect and manage WhatsApp sessions (QR pairing, start/stop)
- Send text messages, list chats, read message history
- Monitor groups for leads or keywords
- Manage contact labels (WhatsApp Business sync)
- Configure anti-spam rules (rate limits, duplicate blocking, pattern filters)
- Set up content safeguards (block secrets, PII, prompt injection)
- Train style profiles and generate AI replies
- Collect feedback via sentiment analysis (14+ languages)
- Export testimonials (JSON/HTML)
- Discover and message other AI agents (A2A JSON-RPC 2.0)
- Manage encryption keys (X25519-AES256GCM)
- Manage API keys, usage tracking, billing (Stripe)
Use cases
Personal automation:
- Auto-reply to WhatsApp messages while you're busy (AI learns your tone)
- Forward important group mentions to a private chat
- Schedule follow-up messages to contacts after meetings
- Collect and organize customer testimonials from group conversations
Business & lead management:
- Monitor industry groups for purchase-intent keywords ("looking for", "need help with")
- Auto-label new leads as VIP/Hot/Cold based on message sentiment
- Route group-detected leads to your sales team via labels
- Run feedback collectors across all chats — auto-approve positive reviews for your website
Agent-to-Agent (A2A):
- Build a support agent that escalates complex tickets to a human agent over A2A
- Connect your booking agent with a payment agent — encrypted end-to-end
- Create a multi-agent pipeline: lead detection → qualification → outreach → follow-up
- Let two businesses' agents negotiate and exchange data securely (X25519-AES256GCM)
- Resolve any WhatsApp number to check if they run a MoltFlow agent, then message directly
Safety & compliance:
- Block outgoing messages containing API keys, credit cards, or SSNs automatically
- Set rate limits to prevent accidental spam (typing indicators + random delays built-in)
- Create custom regex rules to flag sensitive content before it leaves your account
- Test any message against your full policy stack before sending
Setup
Env vars:
MOLTFLOW_API_KEY (required) — API key from waiflow.app dashboard
MOLTFLOW_API_URL (optional) — defaults to https://apiv2.waiflow.app
Authentication: X-API-Key: $MOLTFLOW_API_KEY header or Authorization: Bearer $TOKEN (JWT from login).
Base URL: https://apiv2.waiflow.app/api/v2
1. Sessions
curl -H "X-API-Key: $MOLTFLOW_API_KEY" \
https://apiv2.waiflow.app/api/v2/sessions
curl -X POST -H "X-API-Key: $MOLTFLOW_API_KEY" \
-H "Content-Type: application/json" \
-d '{"name": "Main Line"}' \
https://apiv2.waiflow.app/api/v2/sessions
curl -H "X-API-Key: $MOLTFLOW_API_KEY" \
https://apiv2.waiflow.app/api/v2/sessions/{session_id}
curl -X DELETE -H "X-API-Key: $MOLTFLOW_API_KEY" \
https://apiv2.waiflow.app/api/v2/sessions/{session_id}
| Endpoint | Method | Description |
|---|
/sessions | GET | List sessions |
/sessions | POST | Create session |
/sessions/{id} | GET | Get session details |
/sessions/{id} | DELETE | Delete session |
2. Messages
curl -X POST -H "X-API-Key: $MOLTFLOW_API_KEY" \
-H "Content-Type: application/json" \
-d '{"session_id": "uuid", "chat_id": "1234567890@c.us", "message": "Hello!"}' \
https://apiv2.waiflow.app/api/v2/messages/send
curl -H "X-API-Key: $MOLTFLOW_API_KEY" \
https://apiv2.waiflow.app/api/v2/messages/chats/{session_id}
curl -H "X-API-Key: $MOLTFLOW_API_KEY" \
https://apiv2.waiflow.app/api/v2/messages/chat/{session_id}/{chat_id}
| Endpoint | Method | Description |
|---|
/messages/send | POST | Send text message |
/messages/chats/{session_id} | GET | List chats |
/messages/chat/{session_id}/{chat_id} | GET | Get messages in chat |
/messages/{message_id} | GET | Get single message |
3. Groups
curl -H "X-API-Key: $MOLTFLOW_API_KEY" \
https://apiv2.waiflow.app/api/v2/groups
curl -H "X-API-Key: $MOLTFLOW_API_KEY" \
https://apiv2.waiflow.app/api/v2/groups/available/{session_id}
curl -X POST -H "X-API-Key: $MOLTFLOW_API_KEY" \
-H "Content-Type: application/json" \
-d '{"session_id": "uuid", "wa_group_id": "123456@g.us", "monitor_mode": "first_message"}' \
https://apiv2.waiflow.app/api/v2/groups
curl -X PATCH -H "X-API-Key: $MOLTFLOW_API_KEY" \
-H "Content-Type: application/json" \
-d '{"monitor_mode": "keyword", "monitor_keywords": ["looking for", "need help"]}' \
https://apiv2.waiflow.app/api/v2/groups/{group_id}
| Endpoint | Method | Description |
|---|
/groups | GET | List monitored groups |
/groups/available/{session_id} | GET | List available WhatsApp groups |
/groups | POST | Add group to monitoring |
/groups/{id} | GET | Get group details |
/groups/{id} | PATCH | Update monitoring settings |
/groups/{id} | DELETE | Remove from monitoring |
4. Labels
curl -X POST -H "X-API-Key: $MOLTFLOW_API_KEY" \
-H "Content-Type: application/json" \
-d '{"name": "VIP", "color": "#00FF00"}' \
https://apiv2.waiflow.app/api/v2/labels
curl -X POST -H "X-API-Key: $MOLTFLOW_API_KEY" \
"https://apiv2.waiflow.app/api/v2/labels/{label_id}/sync?session_id={session_id}"
curl -X POST -H "X-API-Key: $MOLTFLOW_API_KEY" \
"https://apiv2.waiflow.app/api/v2/labels/sync-from-whatsapp?session_id={session_id}"
| Endpoint | Method | Description |
|---|
/labels | GET | List labels |
/labels | POST | Create label |
/labels/business-check | GET | Check WhatsApp Business status |
/labels/{id} | GET / PATCH / DELETE | Get, update, delete label |
/labels/{id}/sync | POST | Sync to WhatsApp Business |
/labels/sync-from-whatsapp | POST | Import from WhatsApp |
5. Anti-Spam Rules
curl -H "X-API-Key: $MOLTFLOW_API_KEY" \
https://apiv2.waiflow.app/api/v2/antispam/settings
curl -X PUT -H "X-API-Key: $MOLTFLOW_API_KEY" \
-H "Content-Type: application/json" \
-d '{"enabled": true, "rate_limit": 60, "rate_limit_window": 60, "block_duplicates": true, "auto_block_spammers": true, "max_violations": 5}' \
https://apiv2.waiflow.app/api/v2/antispam/settings
curl -X POST -H "X-API-Key: $MOLTFLOW_API_KEY" \
-H "Content-Type: application/json" \
-d '{"pattern": "buy now|limited offer", "action": "block", "enabled": true}' \
https://apiv2.waiflow.app/api/v2/antispam/rules
curl -X PUT -H "X-API-Key: $MOLTFLOW_API_KEY" \
-H "Content-Type: application/json" \
-d '{"pattern": "buy now|limited offer|act fast", "action": "flag", "enabled": true}' \
https://apiv2.waiflow.app/api/v2/antispam/rules/{rule_id}
curl -X DELETE -H "X-API-Key: $MOLTFLOW_API_KEY" \
https://apiv2.waiflow.app/api/v2/antispam/rules/{rule_id}
curl -H "X-API-Key: $MOLTFLOW_API_KEY" \
https://apiv2.waiflow.app/api/v2/antispam/stats
| Endpoint | Method | Description |
|---|
/antispam/settings | GET | Get anti-spam settings |
/antispam/settings | PUT | Update settings (rate limit, duplicate blocking, auto-block) |
/antispam/rules | POST | Create spam filter rule |
/antispam/rules/{id} | PUT | Update rule |
/antispam/rules/{id} | DELETE | Delete rule |
/antispam/stats | GET | Spam statistics (blocked, flagged, violations) |
Rule actions: block (drop message), flag (mark for review), delay (add cooldown)
Settings fields: enabled, rate_limit (msgs/window), rate_limit_window (seconds), block_duplicates, duplicate_window, auto_block_spammers, max_violations
6. Safeguards — Content Policy
curl -H "X-API-Key: $MOLTFLOW_API_KEY" \
https://apiv2.waiflow.app/api/v2/a2a-policy/settings
curl -X PUT -H "X-API-Key: $MOLTFLOW_API_KEY" \
-H "Content-Type: application/json" \
-d '{"block_api_keys": true, "block_credit_cards": true, "block_ssn": true, "block_emails": false, "max_message_length": 4096}' \
https://apiv2.waiflow.app/api/v2/a2a-policy/settings
curl -H "X-API-Key: $MOLTFLOW_API_KEY" \
https://apiv2.waiflow.app/api/v2/a2a-policy/safeguards
curl -X POST -H "X-API-Key: $MOLTFLOW_API_KEY" \
-H "Content-Type: application/json" \
-d '{"pattern": "sk-[a-zA-Z0-9]{48}", "description": "Block OpenAI API keys"}' \
https://apiv2.waiflow.app/api/v2/a2a-policy/rules
curl -X POST -H "X-API-Key: $MOLTFLOW_API_KEY" \
https://apiv2.waiflow.app/api/v2/a2a-policy/rules/{rule_id}/toggle
curl -X DELETE -H "X-API-Key: $MOLTFLOW_API_KEY" \
https://apiv2.waiflow.app/api/v2/a2a-policy/rules/{rule_id}
curl -X POST -H "X-API-Key: $MOLTFLOW_API_KEY" \
-H "Content-Type: application/json" \
-d '{"content": "My API key is sk-abc123"}' \
https://apiv2.waiflow.app/api/v2/a2a-policy/test