Client struct is the core of whatsapp-rust, managing connections, encryption, state, and all protocol-level operations.
Overview
The Client handles:- WebSocket connection lifecycle and automatic reconnection
- Noise Protocol handshake and encryption
- Signal Protocol E2E encryption for messages
- App state synchronization
- Device state persistence
- Event dispatching
Most users should use the
Bot builder instead of creating a Client directly. The Bot provides a simplified API with sensible defaults.Creating a Client
Arc<dyn Runtime>
required
Async runtime for spawning tasks, sleeping, and blocking operations
Arc<PersistenceManager>
required
State manager for device credentials, sessions, and app state
Arc<dyn TransportFactory>
required
Factory for creating WebSocket connections
Arc<dyn HttpClient>
required
HTTP client for media operations and version fetching
Option<(u32, u32, u32)>
Optional WhatsApp version override (primary, secondary, tertiary)
(Arc<Client>, Receiver<MajorSyncTask>)
Returns the client Arc and a receiver for history/app state sync tasks
Creating with custom cache configuration
Connection Management
run
disconnect()orlogout()is called- Auto-reconnect is disabled and connection fails
- Client receives a fatal stream error (401 unauthorized, 409 conflict, or 516 device removed)
connect
TRANSPORT_CONNECT_TIMEOUT), matching WhatsApp Web’s MQTT and DGW connect timeout defaults. Without this, a dead network would block on the OS TCP SYN timeout (~60-75s).
The Noise handshake response also has a separate 20-second timeout (NOISE_HANDSHAKE_RESPONSE_TIMEOUT).
As of PR #1090,
connect() returns ConnectError instead of anyhow::Error. ClientError::AlreadyConnected was removed — that case is now ConnectError::AlreadyConnected.ConnectError):
AlreadyConnected- a connection is already up, or anotherconnect()attempt is already in flightNotActivated- construction never activated (only reachable with theclient-lifecyclefeature)Timeout { stage, timeout }- the version fetch or the transport open ran out of time, independently, each under the same 20s budget (ConnectStage::VersionFetch/Transport).connect()itself never reportsConnectStage::SocketorReady— those are only produced bywait_for_socket()/wait_for_connected()below.Version(anyhow::Error)/Transport(anyhow::Error)- app version resolution or transport open failed outrightHandshake(HandshakeError)- the Noise handshake failed after the transport was up; checkHandshakeError::is_transient()to decide whether a retry is worthwhile
ConnectError for the full variant reference.
logout
LoggedOut event.
As of PR #1090,
logout() is infallible ((), not Result<()>). The deregistration IQ is best-effort — it cannot be sent at all while offline — and the local teardown runs either way, so there was nothing for a caller to branch on. A failed IQ is logged at warn.- Disables auto-reconnect
- Sends a
RemoveCompanionDeviceSpecIQ to deregister the companion device (if connected); a failure here is logged, not returned - Disconnects the transport
- Emits
Event::LoggedOutwithreason: ConnectFailureReason::LoggedOut
disconnect
cleanup_connection_state(). That cleanup resets all connection-scoped state — invalidating per-chat message queues so stale workers exit, flushing then clearing the signal cache (so pending sender-key/identity writes are persisted, not lost), draining pending IQ waiters, and resetting offline sync state. The same cleanup_connection_state() also runs from run() after the message loop exits; it is idempotent and race-tolerant, so whichever path wins, connection-scoped state is reset once in effect. See disconnect cleanup for the full list of resources cleaned up.
signal_shutdown_sync
disconnect() for places where you can’t await. It flips expected_disconnect, clears is_running, fires the terminal shutdown_notifier, and notifies the per-connection shutdown so spawned tasks exit on their next poll. It does not flush, close the transport, or touch persistence — prefer disconnect() whenever you can await. Intended for Drop impls on FFI wrappers (e.g. the WASM client) that need to release the runtime without blocking.
reconnect
- Handling network changes (e.g., Wi-Fi to cellular)
- Forcing a fresh server session
- Testing offline message delivery
reconnect_immediately
reconnect(), this sets the expected disconnect flag so the run loop skips the backoff delay.
Example:
wait_for_socket
Duration
required
Maximum time to wait
Result<(), ConnectError>
Ok if socket ready,
ConnectError::Timeout { stage: ConnectStage::Socket, timeout } on timeoutwait_for_connected
Duration
required
Maximum time to wait
Result<(), ConnectError>
Ok once fully ready,
ConnectError::Timeout { stage: ConnectStage::Ready, timeout } on timeoutAs of PR #1090, both methods return
ConnectError instead of anyhow::Error.pair_with_code
PairCodeOptions
required
Configuration for pair code authentication:
phone_number— Phone number in international format (e.g.,"15551234567")show_push_notification— Whether to show a push notification on the phone (default:true)custom_code— Optional custom 8-character code using Crockford Base32 alphabetplatform_id—Option<CompanionWebClientType>override for<companion_platform_id>.Nonederives the wire id fromDevice.device_props.platform_type(typicallyChrome; AndroidPlatformTypes also map toChromebecause the server requires attestation for the Android letter codes). The matching<companion_platform_display>is always derived; web variants emit<Browser> (<OS>), and explicitAndroidPhone/AndroidTablet/AndroidAmbiguousoverrides emitAndroid (<OS>).
String
The 8-character pairing code to display to the user
PairError):
PairError::PairCode(PairCodeError) covers validation and crypto failures; PairError::RequestFailed(IqError) covers the IQ transport.
Example:
set_passkey_authenticator
PasskeyAuthenticator for passkey (SHORTCAKE_PASSKEY) linking. Once set, the client auto-drives the flow end-to-end: it calls get_assertion when the server requests one, sends the response, and auto-confirms a re-link whose skip_handoff_ux is true. Leave it unset to drive every step manually from the Event::PairPasskey* events.
Arc<dyn PasskeyAuthenticator>
required
Produces a WebAuthn assertion for the server’s challenge — typically backed by Android Credential Manager, hybrid/caBLE, or a software vault. Use
whatsapp_rust::passkey::CallbackAuthenticator::new(f) to wrap an async closure.send_passkey_response
<passkey_prologue> and opens the ephemeral-identity handshake. Call after an Event::PairPasskeyRequest. Returns PasskeyError::Flow if a passkey open is already in progress.
send_passkey_confirmation
<encrypted_pairing_request>, and commits the secret rotation. For a fresh link, call this only after the user confirms the code from an Event::PairPasskeyConfirmation — a proven re-link (skip_handoff_ux: true) can call it immediately, and the automatic driver does so itself. Returns PasskeyError::Flow if called before the confirmation stage or without an active session.
Errors (PasskeyError):
Connection State
is_connected
true if the Noise socket is established. This method uses an internal AtomicBool flag (with Acquire ordering) instead of probing the noise socket mutex, making it lock-free and immune to false negatives under mutex contention.
Prior to this design, connection checks used
try_lock() on the noise socket mutex. Under contention (e.g., during frame encryption), try_lock() would fail and incorrectly report the client as disconnected — silently dropping receipt acks. The AtomicBool approach eliminates this race condition entirely.is_logged_in
true if authenticated with WhatsApp servers.
Auto-Reconnection
The client includes automatic reconnection handling with Fibonacci backoff.How it works
- On disconnect: The client detects unexpected disconnections and automatically attempts to reconnect
- Fibonacci backoff: Each failed attempt increases the delay following the Fibonacci sequence (1s, 1s, 2s, 3s, 5s, 8s, 13s, 21s…) with a maximum of 900 seconds (15 minutes) and +/-10% jitter
- Expected disconnects: Protocol-expected disconnects (e.g., 515 stream error after pairing) trigger immediate reconnection without backoff
- Keepalive monitoring: A keepalive loop sends periodic pings (every 15-30s) and forces reconnection if the socket appears dead (no data received for 20s after a send)
Controlling auto-reconnect
client.stats().reconnect_errors instead of a public field.
Stream error handling
The client handles specific<stream:error> codes from the WhatsApp server:
Rate limiting (429)
When the server returns a 429 stream error, the client bumps the internal backoff counter by 5 Fibonacci steps before reconnecting. This means the reconnection delay jumps significantly (e.g., from ~1s to ~13s on the first rate limit) to respect the server’s throttling.General reconnection behavior
Messaging
send_message
Jid
required
Recipient JID (user@s.whatsapp.net or group@g.us)
wa::Message
required
Protobuf message content
Result<SendResult, SendError>
A
SendResult containing the message_id and destination to JIDsend_message_with_options
SendOptions
required
Configuration for message sending behavior. Supports
message_id (override the auto-generated ID), extra_stanza_nodes (custom XML nodes on the stanza), and ephemeral_expiration (disappearing message duration in seconds).edit_message
String
required
ID of the message to edit
wa::Message
required
New message content
edit_message_with_options
send_message_with_options. Accepts an EditOptions (built via EditOptions::default().with_stanza_id(id)) to pin the outer stanza id to an existing message’s id (best-effort — server/client dependent) instead of the fresh id edit_message generates.
See Send API reference for the full EditOptions type and its side-effect notes.
revoke_message
Sender to revoke your own message, or Admin to revoke another user’s message as group admin.
RevokeType
required
RevokeType::Sender (delete your own message) or RevokeType::Admin { original_sender: Jid } (admin revoke in groups)Feature APIs
The Client provides namespaced access to feature-specific operations:blocking
block(jid: &Jid)- Block a contactunblock(jid: &Jid)- Unblock a contactget_blocklist()- Get all blocked contactsis_blocked(jid: &Jid)- Check if contact is blocked
groups
query_info(jid: &Jid)- Get cached group infoget_metadata(jid: &Jid)- Fetch group metadata from serverget_participating()- List all groups you’re increate_group(options: GroupCreateOptions)- Create a new groupset_subject(jid: &Jid, subject: GroupSubject)- Change group nameset_description(jid: &Jid, desc: Option<GroupDescription>, prev: PreviousDescription<'_>)- Change description;previs an optimistic-concurrency token (PreviousDescription::Resolvereads the current one for you)leave(jid: &Jid)- Leave a groupadd_participants(jid: &Jid, participants: &[Jid])- Add membersremove_participants(jid: &Jid, participants: &[Jid])- Remove memberspromote_participants(jid: &Jid, participants: &[Jid])- Make members adminsdemote_participants(jid: &Jid, participants: &[Jid])- Remove admin statusget_invite_link(jid: &Jid, reset: bool)- Get/reset invite linkjoin_with_invite_code(code: &str)- Join a group via invite code or URLjoin_with_invite_v4(group_jid, code, expiration, admin_jid)- Accept a V4 invite messageget_invite_info(code: &str)- Preview group metadata from invite codeset_locked(jid: &Jid, locked: bool)- Lock/unlock group info editingset_announce(jid: &Jid, announce: bool)- Enable/disable announcement modeset_ephemeral(jid: &Jid, expiration: u32)- Set disappearing messages timerset_membership_approval(jid: &Jid, mode: MembershipApprovalMode)- Require admin approvalget_membership_requests(jid: &Jid)- Get pending membership requestsapprove_membership_requests(jid: &Jid, participants: &[Jid])- Approve pending requestsreject_membership_requests(jid: &Jid, participants: &[Jid])- Reject pending requestsset_member_add_mode(jid: &Jid, mode: MemberAddMode)- Set who can add membersset_no_frequently_forwarded(jid: &Jid, restrict: bool)- Restrict forwarding of frequently forwarded messagesset_allow_admin_reports(jid: &Jid, allow: bool)- Allow or disallow admin reportsset_group_history(jid: &Jid, enabled: bool)- Enable or disable group history for new membersset_member_link_mode(jid: &Jid, mode: MemberLinkMode)- Set member link modeset_member_share_history_mode(jid: &Jid, mode: MemberShareHistoryMode)- Set history sharing mode for new membersset_limit_sharing(jid: &Jid, enabled: bool)- Limit sharing within the groupcancel_membership_requests(jid: &Jid, participants: &[Jid])- Cancel pending membership requestsrevoke_request_code(jid: &Jid, participants: &[Jid])- Revoke request codes for participantsacknowledge(jid: &Jid)- Acknowledge a groupbatch_get_info(jids: Vec<Jid>)- Batch fetch group metadata for multiple groupsget_profile_pictures(group_jids: Vec<Jid>, picture_type: PictureType)- Batch fetch group profile pictures
presence
set(status: PresenceStatus)- Set presence statusset_available()- Set status to available/onlineset_unavailable()- Set status to unavailable/offlinesubscribe(jid: &Jid)- Subscribe to contact’s presence updatesunsubscribe(jid: &Jid)- Unsubscribe from contact’s presence updates
chatstate
send(to: &Jid, state: ChatStateType)- Send a chat state updatesend_composing(to: &Jid)- Send typing indicatorsend_recording(to: &Jid)- Send recording indicatorsend_paused(to: &Jid)- Send paused/stopped typing indicator
contacts
is_on_whatsapp(jids: &[Jid])- Check if JIDs are registered on WhatsApp (supports PN and LID JIDs)get_user_info(jids: &[Jid])- Get profile info for users by JIDget_profile_picture(jid: &Jid, preview: bool)- Get profile picture URL (preview or full size)
tc_token
issue_tokens(jids: &[Jid])- Request tokens for contactsprune_expired()- Remove expired tokensget(jid: &str)- Get a stored token by JIDget_all_jids()- List all JIDs with stored tokens
chat_actions
archive_chat(jid: &Jid, message_range: Option<SyncActionMessageRange>)- Archive a chatunarchive_chat(jid: &Jid, message_range: Option<SyncActionMessageRange>)- Unarchive a chatpin_chat(jid: &Jid)- Pin a chatunpin_chat(jid: &Jid)- Unpin a chatmute_chat(jid: &Jid)- Mute a chat indefinitelymute_chat_until(jid: &Jid, mute_end_timestamp_ms: i64)- Mute until a specific timeunmute_chat(jid: &Jid)- Unmute a chatstar_message(chat_jid: &Jid, participant_jid: Option<&Jid>, message_id: &str, from_me: bool)- Star a messageunstar_message(chat_jid: &Jid, participant_jid: Option<&Jid>, message_id: &str, from_me: bool)- Unstar a messagemark_chat_as_read(jid: &Jid, read: bool, message_range: Option<SyncActionMessageRange>)- Mark a chat as read or unread across devicesdelete_chat(jid: &Jid, delete_media: bool, message_range: Option<SyncActionMessageRange>)- Delete a chat from all linked devicesdelete_message_for_me(chat_jid: &Jid, participant_jid: Option<&Jid>, message_id: &str, from_me: bool, delete_media: bool, message_timestamp: Option<i64>)- Delete a message locally (not for the other party)
status
send_text(text, background_argb, font, recipients, options)- Post a text statussend_image(upload, thumbnail, caption, recipients, options)- Post an image statussend_video(upload, thumbnail, duration_seconds, caption, recipients, options)- Post a video statussend_raw(message, recipients, options)- Post any message type as a statusrevoke(message_id, recipients, options)- Delete a posted statussend_reaction(status_owner, server_id, reaction)- React to a status update
mex
query(request: MexRequest)- Execute a GraphQL querymutate(request: MexRequest)- Execute a GraphQL mutation
profile
set_push_name(name: &str)- Set display name (syncs across devices)set_status_text(text: &str)- Set profile “About” textset_profile_picture(image_data: Vec<u8>)- Set profile picture (JPEG, 640x640 recommended)remove_profile_picture()- Remove profile picture
newsletter
list_subscribed()- List all subscribed newslettersget_metadata(jid: &Jid)- Get newsletter metadataget_metadata_by_invite(invite: &str)- Get metadata via invite linkcreate(name, description)- Create a new newsletterjoin(jid: &Jid)- Join a newsletterleave(jid: &Jid)- Leave a newsletterupdate(jid, options)- Update newsletter settingssend_reaction(jid, msg_server_id, reaction)- React to a newsletter messageget_messages(jid, count, before)- Fetch newsletter messagessubscribe_live_updates(jid: &Jid)- Subscribe to real-time updates
Newsletter message sending is handled by the unified
client.send_message() method — pass a newsletter JID and the message is sent as plaintext automatically. See the Send API for details.community
create(options: CreateCommunityOptions)- Create a communitydeactivate(jid: &Jid)- Deactivate a communitylink_subgroups(jid: &Jid, subgroups: &[Jid])- Link groups to a communityunlink_subgroups(jid: &Jid, subgroups: &[Jid], remove_orphan_members: bool)- Unlink groups from a communityget_subgroups(jid: &Jid)- List community subgroupsget_subgroup_participant_counts(jid: &Jid)- Get participant counts per subgroupquery_linked_group(community_jid: &Jid, subgroup_jid: &Jid)- Query a linked group’s community metadatajoin_subgroup(community_jid: &Jid, subgroup_jid: &Jid)- Join a community subgroupget_linked_groups_participants(jid: &Jid)- Get participants across linked groups
polls
create(to: &Jid, name: &str, options: &[String], selectable_count: u32)- Create a poll (returns message ID and secret)vote(chat_jid, poll_msg_id, poll_creator_jid, message_secret, option_names)- Cast a vote on a polldecrypt_vote(enc_payload, enc_iv, message_secret, poll_msg_id, poll_creator_jid, voter_jid)- Decrypt a vote (static method)aggregate_votes(poll_options, votes, message_secret, poll_msg_id, poll_creator_jid)- Tally all votes (static method)
media_reupload
request(req: &MediaReuploadRequest)- Request the server to re-upload expired media
server-error receipt and waits up to 30 seconds for a mediaretry notification with an updated download path.
signal
encrypt_message(jid: &Jid, plaintext: &[u8])- Encrypt plaintext for a single recipientdecrypt_message(jid: &Jid, enc_type: EncType, ciphertext: &[u8])- Decrypt a Signal protocol messageencrypt_group_message(group_jid: &Jid, plaintext: &[u8])- Encrypt plaintext for a group using sender keysdecrypt_group_message(group_jid: &Jid, sender_jid: &Jid, ciphertext: &[u8])- Decrypt a group messagevalidate_session(jid: &Jid)- Check whether a Signal session existsdelete_sessions(jids: &[Jid])- Delete Signal sessions and identity keyscreate_participant_nodes(recipient_jids: &[Jid], message: &Message)- Create encrypted participant nodesassert_sessions(jids: &[Jid])- Ensure E2E sessions existget_user_devices(jids: &[Jid])- Get all device JIDs for users
query_usync
contacts() and signal().get_user_devices() under the hood. Use it for protocol combinations not covered by a specialized helper (bot profile lookup, username resolution, disappearing_mode/text_status, feature flags). This is a neutral operation: it only returns decoded wire data, with no cache or persistence side effects.
See USync API for the full UsyncQuery/UsyncResponse model and examples.
Public fields
http_client
enable_auto_reconnect
true. Set to false to disable auto-reconnect.
custom_enc_handlers
Bot::build and immutable afterward; read lock-free via .get(). Register handlers exclusively through BotBuilder::with_enc_handler() — direct mutation after build is not possible.
RECONNECT_BACKOFF_STEP
reconnect() is called, creating an approximately 5-second offline window before the next connection attempt. This prevents tight reconnect loops after intentional disconnects.
Client Profile
The noise-handshakeClientPayload.UserAgent identity that this client presents to WhatsApp servers. The default is ClientProfile::web(), which matches the legacy desktop-web payload (platform Web, device Desktop, OS version 0.1.0, and an attached web_info field).
This is independent of DeviceProps — device_props controls what is reported during companion registration (e.g., the entry shown under Linked Devices on the phone), while ClientProfile controls the user agent fields used during the Noise handshake on every connect.
set_client_profile
ClientPayload profile. The profile is held in-memory only (#[serde(skip)] on Device.client_profile), so you must call this before each connect() on a fresh process.
ClientProfile
required
The profile to apply. Use the constructors on
ClientProfile — web(), android(os_version), smb_android(os_version), ios(os_version), macos(os_version), windows(os_version).Native profiles (
android, smb_android, ios, macos, windows) automatically omit web_info from the ClientPayload. Only web() includes it.Device State
push_name
Renamed from
get_push_name — the get_ prefix was dropped to match the neighboring accessors.pn
None before pairing completes.
Renamed from
get_pn.lid
None before pairing completes.
Renamed from
get_lid.is_lid_migrated
to/<participants> namespace) — an unmigrated account keeps DMs on PN even when a LID mapping is cached, since the server rejects LID-addressed DMs from unmigrated accounts with ack error="400" (#941). Signal session addressing is unaffected either way.
Returns true if the persisted Device.lid_migrated flag is set, or (as a fallback for accounts paired before the flag existed) if the lid_one_on_one_migration_enabled ab prop is currently enabled. See Signal Protocol — DM wire namespace vs. Signal session addressing and Authentication — one-to-one LID migration state.
This is normally handled automatically by the send path — you don’t need to call it yourself before sending. It’s exposed for diagnostics/telemetry.
get_lid_pn_entry
@s.whatsapp.net) to look up its LID, or a LID JID (@lid) to look up its phone number. Returns None for non-user JIDs (groups, newsletters, etc.) or if no mapping is cached.
&Jid
required
The JID to look up — either a PN JID or a LID JID
Option<LidPnEntry>
Contains
lid (Arc<str>), phone_number (Arc<str>), created_at (i64 Unix timestamp), and learning_source (LearningSource). Use &*entry.lid for &str comparisons or pass directly to anything that accepts AsRef<str>.This replaces the previous
get_phone_number_from_lid method. The new API accepts a full Jid instead of a raw string and supports bidirectional lookup — pass either a PN or LID JID to resolve the mapping in either direction.LearningSource
TheLearningSource enum indicates how a LID-PN mapping was discovered. The source is not mere provenance — it also selects the write policy applied when the pair reaches the cache, mirroring WhatsApp Web’s createLidPnMappings (WAWebDBCreateLidPnMappings) switch (learningSource):
- Directed sources (
Usync,PeerPnMessage,PeerLidMessage,RecipientLatestLid,MigrationSyncLatest,MigrationSyncOld,BlocklistActive,BlocklistInactive) overwrite the cache on any change from what’s already stored. - Observational bulk sources (
Other,Pairing,DeviceNotification) only seed a LID that isn’t cached yet. If the pair conflicts with an already-known LID for that phone, the observational pair is not applied — the client instead fires one background live LID query (LidQuerySpec) and learns the authoritative result underUsync, which can never itself trigger another reconcile. - Known-stale sources (
MigrationSyncOld,BlocklistInactive) are additionally stamped withcreated_at = 0, so a fresher mapping for the same phone always outranks them in the cache’s most-recent-wins (PN→LID) resolution. This only guards the forward direction — the LID→PN reverse map always takes the latest write.
A pair that already matches the cache’s current mapping always re-affirms durability regardless of source — it is never treated as a conflict. This includes an exact match, and also a reverse-only match: the LID-PN cache is capacity-bounded (see
lid_pn_cache), so the PN→LID entry can be evicted while the LID→PN entry survives, and a re-learn of that surviving pair still counts as self-consistent.persistence_manager
History Sync
History sync transfers chat history from the phone to the linked device. The client processes history sync notifications through a RAM-optimized pipeline that minimizes peak memory usage.Processing pipeline
When a history sync notification arrives, the client:- Sends a
HistorySyncreceipt immediately (so the phone knows delivery succeeded) - Retrieves the data — either from an inline payload (moved via
.take(), not cloned) or by stream-decrypting an external blob in 8KB chunks - Extracts a
compressed_size_hintfrom the notification’sfile_lengthfield, which the decompressor uses with a 4x multiplier for better buffer pre-allocation (avoids repeatedVecreallocation) - Runs decompression and protobuf parsing on a blocking thread (
tokio::task::spawn_blocking) to avoid stalling the async runtime - Wraps the decompressed blob in a
LazyHistorySyncwith cheap metadata (sync type, chunk order, progress) and dispatches it asEvent::HistorySync(Box<LazyHistorySync>). Full protobuf decoding is deferred until the event handler calls.get()
process_sync_task
MajorSyncTask received from the sync channel returned by Client::new. This is the public entry point for handling history sync and app state sync tasks.
The method dispatches to the appropriate internal handler based on the task variant:
MajorSyncTask::HistorySync— downloads and processes history sync dataMajorSyncTask::AppStateSync— synchronizes app state (contacts, mutes, pins, etc.)
If you use the
Bot builder, sync task processing is handled automatically. You only need this method when building a custom client setup.set_skip_history_sync
skip_history_sync_enabled
true if history sync is currently being skipped.
set_wanted_pre_key_count
UPLOAD_KEYS_COUNT. Default: 812.
Intended for consumers that construct Client directly (rather than via Bot::builder().with_wanted_pre_key_count(...)). Set this before calling connect(). The value is clamped at upload time to 5..=65_535; out-of-range values log a warn!.
usize
required
Pre-keys per upload batch. Clamped to
5..=65_535.wanted_pre_key_count
set_force_active_delivery_receipts
delivery_receipt_active setting. v0.6 added this knob so consumers can opt every incoming message into active receipts during a known foreground session.
When active is true, the client emits <receipt> stanzas without the silent flag for every successful decrypt. When false (default), behavior follows the existing per-chat heuristic. The setting is mirrored across offline-resume so the post-resume ack pattern matches the live one.
send_history_sync_server_error_receipt
<receipt type="server-error" category="peer"> to the companion device carrying an encrypted retry payload, mirroring WA Web’s WAWebSendHistSyncServerErrorReceiptJob.
Parameters:
message_id— theMessageInfo::idof the failed history-sync notificationmedia_key— the 32-byte key carried by the original<historysync mediaKey="…">element
Event::HistorySync (or upstream download) error path, once you’ve determined the blob can’t be recovered locally. The phone will then retry the upload, producing a fresh HistorySync notification.
Offline sync
The client automatically manages offline message sync when reconnecting. During sync, message processing is restricted to sequential mode (1 concurrent task) to preserve ordering.Semaphore transition safety
When offline sync completes, the concurrency semaphore is swapped from 1 permit to 64 permits. Tasks that were already waiting on the old semaphore use a generation-checked re-acquire loop to safely transition — they detect the swap via an atomic generation counter, drop the stale permit, and re-acquire from the new semaphore. This preventspkmsg messages (which carry SKDM for group decryption) from being silently dropped during the transition. See Concurrency gating for details.
Timeout fallback
If the server advertises offline messages but never completes delivery, a 60-second timeout ensures startup is not blocked indefinitely. On timeout:- A warning is logged with the number of processed vs. expected items
- Offline sync is marked complete
OfflineSyncCompletedevent is emitted- Message processing switches from sequential to parallel (64 concurrent tasks)
State reset on reconnect
All offline sync state (counters, timing, concurrency semaphore) is fully reset on reconnect so stale state does not carry over to the next connection. Related events:OfflineSyncPreview, OfflineSyncCompleted
App State
fetch_props
AbPropsCache.
When a stored props hash exists and the cache has been seeded (at least one full fetch has occurred), the request includes the hash for a delta update — the server only returns changed props. Otherwise, a full fetch is performed and all cached props are replaced.
After the response is applied to the cache, the new hash (if present) is persisted for future delta requests.
Features like group privacy token attachment query the AbPropsCache to check whether specific experiment flags are enabled. See AB props cache for details.
AB props cache
The client maintains an in-memoryAbPropsCache that stores server-side A/B experiment properties. The cache is populated each time fetch_props() runs (automatically on connect) and is not persisted — props are re-fetched on every connection.
Features query the cache by passing a typed AbProp constant from the vendored wacore::iq::abprops registry. A bool prop is considered enabled when its value is "1", "true", or "enabled" (case-insensitive), falling back to the registry default when the server didn’t send it.
Watching additional flags
Only flags in the cache’s interest set are retained when props come in — every other server prop is discarded to avoid allocating for the ~2,000+ flags WhatsApp ships. The interest set is pre-seeded with the flags the library itself reads (seewacore::iq::props::WATCHED). If you need to gate your own code on a flag the library doesn’t already watch, register it before the first fetch_props():
code, value_type, and default straight from the WA Web bundle, so behavior tracks WhatsApp Web without hand-maintained config tables.
The AB props cache is internal to the client. You don’t need to interact with it directly — the library automatically checks relevant flags when performing group operations like
create_group and add_participants.fetch_privacy_settings
set_privacy_setting
PrivacyCategory
required
Privacy category enum:
Last, Online, Profile, Status, GroupAdd, ReadReceipts, CallAdd, Messages, or DefenseModePrivacyValue
required
Privacy value enum:
All, Contacts, None, ContactBlacklist, MatchLastSeen, Known, Off, or OnStandardset_privacy_disallowed_list
Last, Profile, Status, and GroupAdd.
See Privacy API for details and examples.
set_default_disappearing_mode
u32
required
Timer duration in seconds. Common values:
86400 (24 hours), 604800 (7 days), 7776000 (90 days). Pass 0 to disable.get_business_profile
None if the account is not a business account or has no business profile.
&Jid
required
JID of the business account to query
clean_dirty_bits
DirtyBit struct contains a dirty_type (e.g., AccountSync, Groups, SyncdAppState, NewsletterMetadata) and an optional timestamp.
Protocol Operations
send_node
Node
required
Binary protocol node to send
ClientError::NotConnected- Not connectedClientError::EncryptSend- Encryption/send failure
send_raw_bytes
wacore_binary::marshal::marshal_to). Sending malformed data will cause the server to close the connection.
Vec<u8>
required
WABinary-marshaled stanza bytes
ClientError::NotConnected- Not connectedClientError::EncryptSend- Encryption/send failure
flush_pending_signal_state
As of PR #1090, this returns
SignalMaintenanceError instead of anyhow::Error (a Storage failure keeps the typed backend cause reachable via source()).SessionRecord’s sender-chain counter lease for DMs, SenderKeyRecord’s chain iteration lease for group/status), so they only schedule the coalesced write-behind; only the roughly-1-in-64 send that exhausts the current lease flushes synchronously — and because the pre-wire flush check is global, a pending flush on an unrelated session or sender key can force a synchronous flush too. Status reactions are the DM-branch exception and follow the DM lease behavior instead of the group/status one. The live receive path always schedules a coalesced flush, on a ~25ms window (see flush scheduling).
A successful call to flush_pending_signal_state() closes that gap deterministically: everything dirty as of the call is persisted by the time it returns Ok. The call has no hard wall-clock bound — it can wait on locks, or on slow or failing storage, and a backend outage extends it until the retry loop succeeds. Check the returned Result: a failure means the flush did not complete, and state is still pending, not persisted.
Example:
generate_message_id
This is intended for advanced users who need to build custom protocol interactions or manage message IDs manually. Most users should use
send_message which handles ID generation automatically.send_iq
InfoQuery
required
IQ query containing stanza type, namespace, content, and optional timeout
execute
S: IqSpec
required
A typed IQ specification that defines the request structure and response parsing
wait_for_node
NodeFilter
required
Filter specifying which node to wait for (by tag and attributes)
Register the waiter before performing the action that triggers the expected node. When no waiters are active, this has zero cost (single atomic load per incoming node).
NodeFilter
Builder for matching incoming protocol nodes:wait_for_sent_node
wait_for_node.
NodeFilter
required
Filter specifying which outgoing node to intercept (by tag and attributes)
Register the waiter before performing the action that produces the outgoing node. When no sent-node waiters are active, this has zero cost (single atomic load per outgoing node). Useful for testing whether
<tctoken> or <cstoken> was attached to a sent stanza.register_handler
Arc<dyn EventHandler>
required
Handler implementing the EventHandler trait
ChannelEventHandler:
register_chatstate_handler
Arc for thread-safe sharing across the event dispatching system.
set_raw_node_forwarding
Event::RawNode is emitted for every decoded stanza before the stanza router dispatches it. Disabled by default to avoid overhead.
bool
required
Whether to emit
Event::RawNode for every incoming stanzaCall management
reject_call
<call><reject> stanza to the WhatsApp server.
&str
required
The ID of the incoming call to reject. Must not be empty.
&Jid
required
The JID of the caller.
Spam Reporting
send_spam_report
SpamReportRequest
required
The spam report request containing:
message_id- ID of the message being reportedmessage_timestamp- Timestamp of the messagespam_flow- Context where report was initiated (MessageMenu, GroupInfoReport, etc.)from_jid- Optional sender JIDgroup_jid- Optional group JID for group spamgroup_subject- Optional group name/subject for group reportsparticipant_jid- Optional participant JID in group contextraw_message- Optional raw message bytesmedia_type- Optional media type if reporting medialocal_message_type- Optional local message type
SpamReportResult indicating success or failure
Example:
MessageMenu- Reported from message context menuGroupInfoReport- Reported from group info screenGroupSpamBannerReport- Reported from group spam bannerContactInfo- Reported from contact info screenStatusReport- Reported from status view
Passive Mode
set_passive
false (active), the server starts sending offline messages.
Prekeys
refresh_pre_keys
InMemoryBackend) and the server may still hold pre-key IDs whose private key material you cannot reconstruct.
Any pkmsg referencing those old IDs will fail permanently with InvalidPreKeyId. Calling refresh_pre_keys() uploads a fresh batch that the caller does have locally, and old unmatched IDs drain as peers consume them.
Behavior:
- Acquires the internal
prekey_upload_lockso this force-upload cannot race with the count-based and digest-repair upload paths - Uploads a full batch of
Client::wanted_pre_key_count()pre-keys (default 812, configurable viaBotBuilder::with_wanted_pre_key_countorset_wanted_pre_key_count) with Fibonacci retry backoff (1s, 2s, 3s, 5s, 8s, … capped at 610s) - Retries until success or the connection is lost
send_digest_key_bundle
WAWebDigestKeyJob.digestKey() flow.
Behavior:
- Queries the server for the current key bundle digest (identity key, signed pre-key, pre-key IDs, and a SHA-1 hash)
- If the server returns 404 (no record), triggers a full pre-key re-upload
- On success, loads local keys, computes the same SHA-1 digest, and compares
- Hash mismatches or missing keys are logged but do not trigger re-upload — only 404 does
Signed pre-key rotation
Rotation itself runs automatically: once per connection, after the post-login pre-key upload, the client checks whether the signed pre-key is due for rotation (weekly by default) and, if so, generates a fresh one, uploads it via anencrypt/<rotate> IQ, and retains the previous key so in-flight prekey messages still decrypt. Automatic rotation failures are logged and retried on a later connect — they never fail login.
rotate_signed_pre_key() is a public method — callers can force an out-of-cadence rotation directly instead of waiting for the weekly check. It shares a lock with the automatic path (so a manual call can’t race a background rotation) and, unlike the automatic path, propagates failures to the caller as SignalMaintenanceError instead of only logging them. As of PR #1090 this replaces bare anyhow::Error.
See Signal Protocol - Signed pre-key rotation (RotateKeyJob) for the full sequence, wire format, and error handling.
Diagnostics
Three on-Client surfaces answer “what does this session cost?” without any feature flag: always-on wire I/O counters via stats(), an on-demand client-only memory breakdown via memory_report(), and an on-demand unified estimate — client plus storage, transport, and HTTP — via resource_report(). All three are dependency-free and safe to call once per client even when running many clients in one process. For CPU/custom attribution (e.g. per-session allocator tracking), see BotBuilder::with_task_instrument and BotBuilder::with_alloc_meter.
stats
StatsSnapshot fields (#[non_exhaustive]):
Most counters are monotonic over the client’s lifetime and survive reconnects.
last_data_received_ms is the exception: it resets on connection teardown. reconnect_errors also resets, to 0 on every successful reconnect (it counts consecutive failures, not a lifetime total).
Breaking:
last_data_sent_ms was removed — nothing internal ever read it, and stamping it cost a clock read on every frame written (the client’s hottest path, and a call out of the module on wasm32/embedded targets). frames_sent answers “is it still sending?”; there is no drop-in replacement for “when did I last write?” — an embedder that needs that timestamp should stamp it at its own send call site rather than have the wire path pay for it.memory_report
bytes: 0, since their entries don’t live in this process’s memory.
MemoryReport fields (#[non_exhaustive]):
CollectionStats carries both entries: u64 and bytes: u64. MemoryReport::total_estimated_bytes(&self) -> u64 sums .bytes across every byte-carrying field. MemoryReport implements Display for a pretty-printed, human-readable breakdown. This output includes an --- In-flight history sync --- section with the two peak fields above.
Example:
Client::stats(), MemoryReport, CollectionStats, and StatsSnapshot were introduced to replace the old debug-diagnostics-gated memory_diagnostics() / MemoryDiagnostics, which have been removed. CollectionStats, MemoryReport, and StatsSnapshot are re-exported from the whatsapp_rust crate root.resource_report
memory_report()’s client-only collections plus the components that live outside the Client and dominate real per-session RAM — the storage backend’s page cache, the transport’s buffers and TLS/noise state, and the HTTP client’s connection pool. When an AllocMeter is installed via BotBuilder::with_alloc_meter, the report also folds in an allocation-churn snapshot.
On-demand only, no hot-path cost. Each out-of-client figure is best-effort — a component reports only what it can introspect, so absent (None) means “not reported”, not “zero”. resource_report()’s future is Send, so multi-session consumers can await it off a worker task (e.g. from an axum handler).
ResourceReport fields (#[non_exhaustive]):
StorageResourceReport fields: memory_bytes: Option<u64> (retained bytes; Some(0) for remote/store-backed backends whose data isn’t process memory), pages: Option<u64> (backing page/entry count), io_read_bytes / io_write_bytes: Option<u64> (cumulative I/O, when counted).
TransportResourceReport fields: read_buffer_bytes, write_buffer_bytes, tls_state_bytes — all Option<u64>.
HttpResourceReport fields: pool_connections: Option<u64>, pool_buffer_bytes: Option<u64>, inflight_bytes: Option<u64>.
ResourceReport::total_estimated_bytes(&self) -> u64 sums the retained components (client + storage + transport + HTTP). Treat it as a best-effort retained estimate, not a strict lower bound: unreported fields (None) are treated as 0, so components that cannot fully introspect their footprint are silently undercounted — but the storage figure is itself a min(cache cap, db size) upper bound on the SQLite page cache, and can overstate actual heap residency when mmap_size is enabled (see the caveat there), so the total can run either high or low depending on configuration. alloc (churn) is deliberately excluded. ResourceReport implements Display for a pretty-printed breakdown alongside memory_report()’s.
Example:
Storage, transport, and HTTP reports are supplied by the trait implementations behind
Client — see DeviceStore::resource_report, Transport::resource_report, and HttpClient::resource_report. AllocSnapshot, StorageResourceReport, TransportResourceReport, and HttpResourceReport are re-exported from wacore::stats; all four are also re-exported from the whatsapp_rust crate root.Error Types
As of PR #1090,
connect()/wait_for_socket()/wait_for_connected() return ConnectError (ClientError::AlreadyConnected was removed in favor of ConnectError::AlreadyConnected), and rotate_signed_pre_key()/flush_pending_signal_state() return SignalMaintenanceError. See Error Types for the full reference across the crate.See Also
- Bot - High-level builder with event handlers
- Events - Event system and types
- Sending Messages - Sending and receiving messages
- Group Management - Working with groups