Manychat API: which integration path do you need?
The Manychat API isn’t one door. Pick the path before you generate a key: each has its own permissions and failure modes.
ManySetter teamUpdated 9 min read
On this page
Chapter 01Start here
Pick one of three integration paths
Does your flow need to call your server, your server need to update a contact, or an app need scoped access? Those are three different paths.
Three paths at a glance
| Path | Who starts it | Access | Best for |
|---|---|---|---|
| External RequestWho starts it: Your flow, while it runsAccess: HTTPS URL, headers you setBest for: Short lookups that fill custom fields | Your flow, while it runs | HTTPS URL, headers you set | Short lookups that fill custom fields |
| Account APIWho starts it: Your server, from outside the builderAccess: Key from Settings → API, paid plansBest for: Updating contacts or sending from your system | Your server, from outside the builder | Key from Settings → API, paid plans | Updating contacts or sending from your system |
| App keyWho starts it: An installed appAccess: One key per installation, approved scopes onlyBest for: Apps used by many Manychat accounts | An installed app | One key per installation, approved scopes only | Apps used by many Manychat accounts |
One path, one token
Don’t share a key across paths. The access model is part of the design: request only the permissions you use.
Chapter 02External Request
Set up an External Request
Add the action to your automation
External Request is a Dev Tools action, available on paid plans.
Pick the method and the URL
POST, GET, PUT or DELETE, to an HTTPS URL only. Add headers if your endpoint needs them.
Send the minimum data
For POST or PUT, a JSON body with only the contact fields your endpoint needs.
Map the response
Enter JSON paths to save returned values into custom user fields.
Test on a real contact
Run the whole flow as a contact, not only the request editor.
- 01Flow stepExternal Request action
- 02Your endpointHTTPS only
- 03200 + JSONWithin 10 seconds
- 04Custom fieldsMapped by JSON path
- 05Next stepUses the saved values
Only a 200 OK gets mapped
Per Manychat’s External Request documentation (opens in a new tab), an error response can’t be mapped. Give the flow a useful fallback path.
Chapter 03Timeout
Design the request around the timeout
External Request stops after 10 seconds, and you can’t change it. A short lookup fits. AI generation, message buffering and retries don’t.
Synchronous or asynchronous?
| Pattern | How it works | Fits |
|---|---|---|
| Synchronous: External RequestHow it works: Your endpoint answers within 10 seconds; values map to custom fieldsFits: Lookups: a price, a slot, a status | Your endpoint answers within 10 seconds; values map to custom fields | Lookups: a price, a slot, a status |
| Asynchronous: acknowledge, then sendHow it works: Answer fast, work in a queue, send later from your serverFits: AI replies, message buffering, retries | Answer fast, work in a queue, send later from your server | AI replies, message buffering, retries |
- 01Acknowledge fastDurable ID, small reply
- 02QueueOrdered per contact
- 03GenerateState, then the reply
- 04SendThrough an authorized route
- Deduplicate repeated events before any work
- Keep one clear failure route per step
- Recheck the channel’s messaging window at send time
External Request isn’t a webhook
It’s a request your automation sends. Don’t assume every trigger reaches you as an event. Sending later? Check Manychat’s messaging windows (opens in a new tab).
Chapter 04Server side
Call the Manychat API from your server
The other two paths start on your side. Your system decides when to call Manychat, so they’re asynchronous by design.
Account API key
- 01Event on your sideCRM update, booking
- 02Your serverCalls with the account key
- 03ManychatContact updated or message
- 04Channel rulesMessaging window applies
App key
- 01App installedOn a Manychat account
- 02Installation keyOne per installation
- 03Approved scopesOnly what was granted
- 04Your app’s callsInside those scopes
Chapter 05Context
Pass the context, not only the message
An AI reply is only as good as what it knows. Four kinds of context should travel with each lead.
What to pass with each lead
| Context | Where it comes from | Why the reply needs it |
|---|---|---|
| SourceWhere it comes from: A custom field your flow sets at the triggerWhy the reply needs it: Answers what the lead came for | A custom field your flow sets at the trigger | Answers what the lead came for |
| OfferWhere it comes from: Facts stored on your side, per workspaceWhy the reply needs it: Price and fit without guessing | Facts stored on your side, per workspace | Price and fit without guessing |
| Lead stateWhere it comes from: Your database, per contactWhy the reply needs it: No question asked twice | Your database, per contact | No question asked twice |
| EventsWhere it comes from: Replies, handoffs, confirmed bookingsWhy the reply needs it: Follow-ups stop at the right time | Replies, handoffs, confirmed bookings | Follow-ups stop at the right time |
Before generating, the service should:
- Identify the workspace and the contact
- Drop duplicate events and merge rapid messages
- Load the lead stage and a recent summary
- Decide the next objective, then generate
Record why the stage changed, when a person took over and whether the calendar confirmed the booking. Keep identifiers and permissions separate per workspace. Stages to track: see AI lead qualification.
Chapter 06Errors
Errors, limits and permissions
The key is missing or was regenerated or deleted, which disables connected methods.
Check that it’s valid JSON, returns 200 and that the JSON path matches.
The endpoint does too much. Acknowledge fast and do the work asynchronously.
A send was retried blindly. Retry only idempotent operations, with backoff.
Limits apply per method; past them, Manychat may stop processing requests for 24 hours (API key and limits (opens in a new tab), checked September 28, 2026).
Check the installation’s approved scopes. An app key only reaches what was granted.
- Store keys server-side, never in a page or client bundle
- Rotate deliberately: a new key breaks the old connections
- Never log raw tokens or sensitive lead data
Chapter 07QA
Test before you turn on traffic
0 of 8 completed
Read Manychat’s logs and your own with the same test contact and timestamp. Booking calls? See Manychat + Calendly.
ManySetter
Your context, in every reply and follow-up.
Connect Manychat with your API key. ManySetter passes source, offer and lead context into each reply and follow-up.
- Connects with your API key
- Takes the entry points you pick
- Keeps each lead’s state
Build and test free · Manychat billed separately
Chapter 08Sources