WhatsApp bot built with Express.js featuring dynamic command system, REST API, and clean architecture.
git clone https://github.com/nestorzamili/whatsapp-web-js.git
cd whatsapp-web-js
npm install
npm startScan QR code with WhatsApp to authenticate.
NODE_ENV=development
PORT=3000
API_KEY=your_api_key_hereGenerate API key:
node -e "console.log('samunu_' + require('crypto').randomBytes(32).toString('hex'))"All requests require x-api-key header.
# Text
curl -X POST http://localhost:3000/send-message \
-H "x-api-key: YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{"id": ["6281234567890@c.us"], "message": "Hello!"}'
# With file
curl -X POST http://localhost:3000/send-message \
-H "x-api-key: YOUR_KEY" \
-F "id[]=6281234567890@c.us" \
-F "message=Check this" \
-F "files=@photo.jpg"curl -H "x-api-key: YOUR_KEY" "http://localhost:3000/get-group-id?groupName=My%20Group"Configure commands in command-list.json (root folder). Changes auto-reload without restart.
# Copy the example file to create your command configuration
cp command-list.example.json command-list.jsonNote:
command-list.jsonis gitignored. If the file doesn't exist, the command system will be disabled but the REST API will continue to work normally.
{
"ping": {
"type": "simple",
"enabled": true,
"pattern": "!ping",
"description": "Check bot status",
"reply": "🏓 Pong!"
}
}{
"weather": {
"type": "script",
"enabled": true,
"pattern": "!weather:",
"description": "Get weather info",
"script": "python weather.py",
"cwd": "./scripts",
"param_placeholder": "<city>"
}
}Usage: !weather:Jakarta
{
"help": {
"type": "command_list",
"enabled": true,
"pattern": "!help",
"description": "Show available commands"
}
}| Field | Required | Description | Example |
|---|---|---|---|
type |
✅ | simple, script, or command_list |
"simple" |
enabled |
✅ | Enable/disable command | true |
pattern |
✅ | Trigger pattern (add : suffix for parameters) |
"!ping" or "!weather:" |
description |
Help text description | "Check bot status" |
|
reply |
✅* | Response for simple commands (*required for simple type) | "🏓 Pong!" |
script |
✅* | Executable command (*required for script type) | "python weather.py" |
cwd |
Working directory for script (default: current) | "./scripts" |
|
access |
personal, group, or both (default: both) |
"group" |
|
allowedGroups |
Restrict to specific group IDs | ["123456789@g.us"] |
|
caseSensitive |
Case sensitivity (default: true) |
false |
|
param_placeholder |
Parameter description for help text | "<city>" |
- Parameter sanitization (prevents command injection)
- Rate limiting (3 commands/minute per user)
- Script timeout (30 seconds)
- API key authentication
MIT License - see LICENSE file for details.
Built with ❤️ using modern JavaScript and clean architecture.