Seler Developers
Connect your system to Seler
Seler is a unified inbox for WhatsApp, Messenger and Instagram with an AI assistant that sells, books and answers for Iraqi businesses. These pages describe the four ways a business's own software — an ERP, a CRM, a store, a booking system — talks to it. Everything here is scoped to one workspace, authorised by something the workspace's owner creates in the dashboard, and revocable there in one click.
Which one do you need?
| REST API | your system → Seler | Read contacts and conversations; add contacts; send a plain message into an open thread, or an approved WhatsApp template to any number — “your order has shipped”. |
| Webhooks | Seler → your system | Be told the moment a customer writes, a thread is handed to a person, the assistant writes down a lead or places an order. Signed, retried, and logged. |
| Custom API contract | assistant → your system | Implement a handful of HTTPS routes and the assistant reads your catalogue, places orders, looks up a customer's record and books appointments — live, during the chat. |
| MCP server | assistant → your system | Expose any tools you like over the Model Context Protocol. Seler discovers them; the owner switches on the ones a customer may trigger from a chat. |
REST API
Keys, scopes, endpoints, rate limits.
Webhooks
Events, payloads, signature verification, retries.
Custom API contract
The routes your server implements. Version 2.
MCP servers
Requirements, discovery, confirmation, a minimal server.
How authorisation works
Nothing here uses a person's login. Each way in has its own credential, made by the workspace's owner under Settings › التكاملات in the dashboard, shown once, and stored by Seler only as a hash or ciphertext:
- The REST API takes a key:
Authorization: Bearer sk_live_…. A key opens only/v1routes, only with the scopes it was given, and never the dashboard. - Webhook deliveries carry a signature over the body, made with a secret you verify on your side.
- The custom API contract and MCP go the other way: Seler calls you, with a bearer secret (contract) or an authorization header you chose (MCP), over HTTPS to a public address.
Your first call
Make a key with the contacts:read scope and ask who you are:
curl https://api.seler.app/v1/me \
-H "Authorization: Bearer sk_live_…"{
"team": { "id": "cad8e8c6-…", "name": "متجر العطور" },
"key": { "id": "f9597076-…", "scopes": ["contacts:read"] }
}team is your workspace: the dashboard calls it a workspace, and the API keeps the name it was built with.
Rules that apply everywhere
- HTTPS on a public host. Addresses on private networks, loopback and link-local ranges are refused when you enter them and again when Seler resolves them at call time.
- Customers' data is the workspace's. Everything you read is scoped to the workspace behind the credential; there is no way to reach another workspace.
- The assistant never acts on a customer's behalf without asking. Any tool that changes something — an order, a booking, a write in your system — runs only after the customer has seen what will happen and said yes. This is enforced in code, not in a prompt.
- Everything is logged. The team can read every call the assistant made to your system and every webhook delivery, with the request, the answer code and the time it took.
Help
Something you need that is not here — another event, another route, a field on a payload — write to support@seler.app. The contracts on these pages only ever grow; nothing is renamed or removed without a new version and an entry in the changelog.