What it supports
Not available through Channel Connect: Instagram Login (an Instagram account with no Facebook Page)
and WhatsApp Business app co-existence. Customers who need those connect from the DMLY dashboard.
How it works
1
Register your return URLs (once)
Tell DMLY where customers may be sent back to. Only these exact URLs are accepted.Up to 20 HTTPS URLs, with no query string, fragment or credentials. Matching is exact,
including the path and any trailing slash. The call replaces the whole list.
2
Start a connection from your backend
When your customer clicks Connect, your server creates a session for their sub-account.The response carries a
connect_url. Send it to the browser and nowhere else.3
Send your customer to the connect URL
Open
connect_url as a top-level navigation (a link or a redirect, not an iframe or a
background fetch). The customer sees your agency’s name, clicks Continue to Meta,
authorizes, and chooses the account to connect. They must finish in the same browser they
started in, within 30 minutes.4
Read the result when they come back
The browser returns to your When
return_url with connection_id and state in the query string.
Match state to the customer who started, then ask DMLY for the result. Never trust the
query string alone.status is connected, channel_id is the new channel. Read it with
GET /workspaces/{workspace}/channels/{channel}.Before you start
- Keep the agency key on your server. Create sessions from your backend only. An agency key can act on every sub-account you own, so your backend must check that the signed-in customer owns the workspace before it creates a session for it.
- Treat
connect_urlas a secret. Anyone holding it can start that connection. Don’t log it, put it in analytics, or send it by email. Only the create call returns it (and anIdempotency-Keyreplay of it while the session is stillpending); status reads never do. - Use
statefor correlation only. Up to 500 characters, returned unchanged on the return URL, in status responses and in webhooks. Don’t put secrets or personal data in it. - Retry safely with
Idempotency-Key. Repeating the same request with the same key returns the same session (200). The same key with a different body or sub-account returns409. Use a new key to start over.
Statuses
connected means the account was saved and its Meta webhook subscription succeeded. Messages still
depend on the account itself: a WhatsApp number must be able to send, a Page must allow messaging,
and Meta’s usual messaging rules apply.
To abandon a session, call POST /workspaces/{workspace}/channel-connections/{connection}/cancel.
It is safe to repeat and never disconnects a channel that already connected.
Reconnecting a channel
To refresh an existing channel (an expired token, a revoked permission), pass its id aschannel_id when you create the session. The customer must pick the same number, Page or
Instagram account; anything else fails with reconnection_target_mismatch. The channel keeps its
id, so nothing changes on your side.
Webhooks
Subscribe your agency webhook to any of:channel.connection.completedchannel.connection.failedchannel.connection.cancelledchannel.connection.expired
data is the connection as GET …/channel-connections/{connection} returns it, without
connect_url. Events are sent within about a minute of the session ending, at least once, so
deduplicate on the envelope id. They report how onboarding ended, not later problems such as
an expired token. Reading the status when the customer returns is still the quickest way to show
them the result.
Error codes
Meta’s error details and tokens are never returned to you.

