Create & Update Contacts through the API
Create or update authorized contact records using international phone format, external IDs, tags, fields, source, and ownership.
STEPS
- Confirm the workspace and required scope.
- Normalize the customer number to international format such as +92 300 1234567.
- Use a stable external ID where supported.
- Send only authorized name, email, source, tags, fields, and ownership data.
- Handle create, update, duplicate, validation, and permission responses.
- Confirm the contact appears in the correct workspace.
- Do not use API import to bypass consent or suppression rules.
Who should use it
Authorized developers and technical workspace users.
Before you begin
- Use a server-side integration environment.
- Create separate test and production credentials.
- Use HTTPS and least privilege.
- Never expose a key or webhook secret in client-side code.
Main concepts and fields
| Concept / Field | Meaning or Use |
|---|---|
| REST API | Request-based integration. |
| Resource | Documented Wemblo object. |
| Authentication | API-key authorization. |
| JSON | Common request and response format. |
| Request ID | Reference used in logs. |
Test and verification
- Complete one successful path with fictional data.
- Complete one invalid, failure or permission path.
- Confirm the result appears in the correct workspace and module.
- Confirm the correct person or team can review and continue the work.
Common issues and solutions
| Issue | What to Check |
|---|---|
| 401 Unauthorized | Missing, invalid, revoked or wrong-workspace key. |
| 403 Forbidden | Scope or resource permission. |
| 422 Validation | Required field or data format. |
| 429 Rate Limit | Backoff, volume and plan/API capacity. |
| Webhook retries | Endpoint response, signature, timeout and processing speed. |
Security, privacy, consent, cost and provider notes
- Use only data the business is authorized to process.
- External provider charges, policies, approvals, limits and availability remain separate.
- Do not expose passwords, API keys, tokens, webhook secrets, payment credentials or private customer data.
- Use human review for sensitive, regulated, urgent, financial or final decisions.
Last reviewed:

