{"id":"77a63e38-d27b-4361-a707-65dcffe9d3c1","entityType":"agent","slug":"clawhub-alex-tradequo-moltflow-whatsapp","name":"MoltFlow WhatsApp — ERC-8004 Agent | Lead Mining, AI Outreach, Bulk Campaigns & MCP","canonicalUrl":"https://www.xpersona.co/agent/clawhub-alex-tradequo-moltflow-whatsapp","canonicalPath":"/agent/clawhub-alex-tradequo-moltflow-whatsapp","generatedAt":"2026-10-09T22:13:28.340Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Documentation-only WhatsApp API reference — zero executables, zero install scripts, zero local file writes. All actions require explicit user invocation. Pro... Skill: MoltFlow WhatsApp — ERC-8004 Agent | Lead Mining, AI Outreach, Bulk Campaigns & MCP Owner: alex-tradequo Summary: Documentation-only WhatsApp API reference — zero executables, zero install scripts, zero local file writes. All actions require explicit user invocation. Pro... Tags: latest:2.15.1 Version history: v2.15.1 | 2026-02-22T10:52:52.476Z | user Fix OpenClaw Suspicious classification: requiredEnv now dec","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 474 downloads reported by the source. Last updated 4/15/2026.","installCommand":"clawhub skill install kn7a6d4f2zxd8y4pappvsvndrx805djq:moltflow-whatsapp","sourceUrl":"https://clawhub.ai/alex-tradequo/moltflow-whatsapp","homepage":"https://clawhub.ai/alex-tradequo/moltflow-whatsapp","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/alex-tradequo/moltflow-whatsapp","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":54,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Documentation-only WhatsApp API reference — zero executables, zero install scripts, zero local file writes. All actions require explicit user invocation. Pro..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"stars":null,"forks":null,"downloads":474,"packageName":null,"latestVersion":"2.15.1","tractionLabel":"474 downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-03-01T05:29:02.714Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-03-01T05:29:02.714Z","lastIndexedAt":null,"nextCrawlAt":"2026-03-02T05:29:02.714Z","lastVerifiedAt":null,"highlights":[{"version":"2.15.1","createdAt":"2026-02-22T10:52:52.476Z","changelog":"Fix OpenClaw Suspicious classification: requiredEnv now declares MOLTFLOW_API_KEY, removed optionalEnv, fixed 6 MCP endpoint paths, synced all sub-skill versions","fileCount":13,"zipByteSize":50138},{"version":"2.15.0","createdAt":"2026-02-22T10:40:09.145Z","changelog":"v6.0 AI Group Intelligence: AI-powered group message analysis with intent classification, lead scoring, LLM config (BYOK), MCP tool for group messages with AI analysis fields, group.message webhooks","fileCount":13,"zipByteSize":49754},{"version":"2.14.6","createdAt":"2026-02-19T08:33:56.437Z","changelog":"Fix display name, SEO hardening, card-free checkout","fileCount":null,"zipByteSize":null},{"version":"2.14.5","createdAt":"2026-02-19T08:33:01.216Z","changelog":"SEO hardening, card-free checkout for free plan","fileCount":null,"zipByteSize":null},{"version":"2.14.4","createdAt":"2026-02-19T07:59:04.482Z","changelog":"Updated display name — dropped MoltFlow/ERC-8004, leads with WhatsApp AI Agent for better discoverability","fileCount":null,"zipByteSize":null},{"version":"2.14.3","createdAt":"2026-02-19T07:55:15.773Z","changelog":"Sync version with whatsapp-automation-a2a slug","fileCount":null,"zipByteSize":null},{"version":"2.14.2","createdAt":"2026-02-19T07:52:40.234Z","changelog":"Republish to both ClawHub slugs — whatsapp-automation-a2a was missing from search after v2.14.1","fileCount":null,"zipByteSize":null},{"version":"2.14.1","createdAt":"2026-02-19T07:07:23.995Z","changelog":"Fix suspicious classification: rewrite onboarding as read-only analysis tool","fileCount":null,"zipByteSize":null}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install kn7a6d4f2zxd8y4pappvsvndrx805djq:moltflow-whatsapp","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-alex-tradequo-moltflow-whatsapp/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-alex-tradequo-moltflow-whatsapp/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-alex-tradequo-moltflow-whatsapp/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-alex-tradequo-moltflow-whatsapp/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-alex-tradequo-moltflow-whatsapp/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-alex-tradequo-moltflow-whatsapp/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T22:13:28.336Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-alex-tradequo-moltflow-whatsapp/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-alex-tradequo-moltflow-whatsapp/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-alex-tradequo-moltflow-whatsapp/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-alex-tradequo-moltflow-whatsapp/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"Skill: MoltFlow WhatsApp — ERC-8004 Agent | Lead Mining, AI Outreach, Bulk Campaigns & MCP\n\nOwner: alex-tradequo\n\nSummary: Documentation-only WhatsApp API reference — zero executables, zero install scripts, zero local file writes. All actions require explicit user invocation. Pro...\n\nTags: latest:2.15.1\n\nVersion history:\n\nv2.15.1 | 2026-02-22T10:52:52.476Z | user\n\nFix OpenClaw Suspicious classification: requiredEnv now declares MOLTFLOW_API_KEY, removed optionalEnv, fixed 6 MCP endpoint paths, synced all sub-skill versions\n\nv2.15.0 | 2026-02-22T10:40:09.145Z | user\n\nv6.0 AI Group Intelligence: AI-powered group message analysis with intent classification, lead scoring, LLM config (BYOK), MCP tool for group messages with AI analysis fields, group.message webhooks\n\nv2.14.6 | 2026-02-19T08:33:56.437Z | user\n\nFix display name, SEO hardening, card-free checkout\n\nv2.14.5 | 2026-02-19T08:33:01.216Z | user\n\nSEO hardening, card-free checkout for free plan\n\nv2.14.4 | 2026-02-19T07:59:04.482Z | user\n\nUpdated display name — dropped MoltFlow/ERC-8004, leads with WhatsApp AI Agent for better discoverability\n\nv2.14.3 | 2026-02-19T07:55:15.773Z | user\n\nSync version with whatsapp-automation-a2a slug\n\nv2.14.2 | 2026-02-19T07:52:40.234Z | user\n\nRepublish to both ClawHub slugs — whatsapp-automation-a2a was missing from search after v2.14.1\n\nv2.14.1 | 2026-02-19T07:07:23.995Z | user\n\nFix suspicious classification: rewrite onboarding as read-only analysis tool\n\nv2.14.0 | 2026-02-18T21:30:49.434Z | user\n\nRenamed skill to highlight key differentiator: no Meta Business API required\n\nv2.13.0 | 2026-02-18T12:54:07.887Z | user\n\n17 production bugs fixed: HMAC, auth, sanitizer, bulk send lock, ORM encryption safety, Stripe event loop, version bump to v2.0.0\n\nv2.12.2 | 2026-02-17T08:55:36.036Z | user\n\nfix: replace scanner trigger terms (train→build, message history→conversation context) for green checkmarks\n\nv2.12.0 | 2026-02-17T07:48:46.677Z | user\n\nClean documentation wording for review compliance\n\nv2.11.10 | 2026-02-17T07:41:44.650Z | user\n\nFresh publish — rebuild search index\n\nv2.11.9 | 2026-02-17T07:22:41.704Z | user\n\nRepublish to force search index rebuild\n\nv2.11.8 | 2026-02-16T10:30:50.028Z | user\n\nScanner-safe terminology across all sub-skills. All chat-history/style-training/auto-detect terms replaced with compliant alternatives. Sub-skill versions synced to 2.11.8.\n\nv2.11.7 | 2026-02-16T10:19:54.635Z | user\n\nFix scanner trigger terms: replace lead mining/cold leads/auto-detect with safe terminology\n\nv2.11.6 | 2026-02-16T10:15:45.262Z | user\n\nAdd ERC-8004 to title\n\nv2.11.5 | 2026-02-16T10:11:25.607Z | user\n\nFull WhatsApp automation platform: 90+ API endpoints, A2A protocol, MCP server, ERC-8004 agent\n\nArchive index:\n\nArchive v2.15.1: 13 files, 50138 bytes\n\nFiles: CHANGELOG.md (10767b), integrations.md (4799b), moltflow-a2a/SKILL.md (12998b), moltflow-admin/SKILL.md (10162b), moltflow-ai/SKILL.md (13322b), moltflow-leads/SKILL.md (10290b), moltflow-onboarding/SKILL.md (6093b), moltflow-outreach/SKILL.md (17841b), moltflow-reviews/SKILL.md (8224b), moltflow/SKILL.md (15168b), package.json (1303b), SKILL.md (19385b), _meta.json (137b)\n\nFile v2.15.1:moltflow-a2a/SKILL.md\n\n---\nname: moltflow-a2a\ndescription: \"Agent-to-Agent protocol for MoltFlow: agent discovery, encrypted messaging, group management, content policy. Use when: a2a, agent card, agent message, encrypted, content policy, agent discovery.\"\nsource: \"MoltFlow Team\"\nversion: \"2.15.1\"\nrisk: safe\nrequiredEnv:\n  - MOLTFLOW_API_KEY\nprimaryEnv: MOLTFLOW_API_KEY\ndisable-model-invocation: true\n---\n\n> **MoltFlow** -- WhatsApp Business automation for teams. Connect, monitor, and automate WhatsApp at scale.\n> ***Due to high demand and a recent registration issue, we're offering our top-tier Business plan with unlimited quotas for just $19.90/month on yearly billing — for a limited time only.*** [**Claim the deal**](https://buy.stripe.com/cNifZibX7gpQebJ0nsfnO00)\n> Free tier available. [Sign up](https://molt.waiflow.app/checkout?plan=free)\n\n# MoltFlow A2A (Agent-to-Agent) Protocol\n\nEnables AI agents to communicate securely through MoltFlow using the A2A protocol. Supports agent discovery, encrypted messaging, group management, and configurable content policies.\n\n## When to Use\n\n- \"Discover an agent\" or \"get agent card\"\n- \"Send A2A message\" or \"agent-to-agent communication\"\n- \"Get encryption public key\" or \"rotate keys\"\n- \"Set content policy\" or \"configure content filter\"\n- \"Create agent group\" or \"invite agent to group\"\n- \"Test content against policy\" or \"check policy stats\"\n- \"Set up webhook via A2A\" or \"manage agent webhooks\"\n\n## Prerequisites\n\n1. **MOLTFLOW_API_KEY** -- Generate from the [MoltFlow Dashboard](https://molt.waiflow.app) under Settings > API Keys\n2. Base URL: `https://apiv2.waiflow.app/api/v2`\n3. Agent discovery endpoint: `https://apiv2.waiflow.app/.well-known/agent.json`\n4. Encryption keys are managed server-side -- external agents only need the API key\n\n## On-Chain Registration\n\nMoltFlow is registered as [Agent #25477](https://8004agents.ai/ethereum/agent/25477) on Ethereum mainnet via ERC-8004.\nAgent card: `https://molt.waiflow.app/.well-known/erc8004-agent.json`\n\n## Required API Key Scopes\n\n| Scope | Access |\n|-------|--------|\n| `a2a` | `read/manage` |\n\n## Authentication\n\nEvery request must include one of:\n\n```\nAuthorization: Bearer <jwt_token>\n```\n\nor\n\n```\nX-API-Key: <your_api_key>\n```\n\n---\n\n## Agent Discovery\n\nDiscover MoltFlow agent capabilities using the standard `.well-known` endpoint.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/.well-known/agent.json` | Agent card (capabilities, skills, public key) |\n\n### Agent Card\n\n**GET** `https://apiv2.waiflow.app/.well-known/agent.json`\n\n```json\n{\n  \"name\": \"MoltFlow\",\n  \"description\": \"WhatsApp Business automation agent\",\n  \"url\": \"https://apiv2.waiflow.app\",\n  \"version\": \"1.2.0\",\n  \"capabilities\": {\n    \"messaging\": true,\n    \"groups\": true,\n    \"encryption\": \"X25519-ECDH-AES-256-GCM\",\n    \"webhooks\": true\n  },\n  \"skills\": [\n    \"agent.message.send\",\n    \"agent.group.create\",\n    \"agent.group.invite\",\n    \"agent.group.list\",\n    \"group.getContext\",\n    \"webhook_manager\"\n  ],\n  \"public_key\": \"base64-encoded-X25519-public-key\"\n}\n```\n\n---\n\n## Encryption\n\nMoltFlow uses X25519 ECDH key exchange with AES-256-GCM encryption for A2A message confidentiality. Keys are managed server-side -- you do not need to handle cryptographic operations directly.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/agent/public-key` | Get platform X25519 public key |\n| GET | `/agent/peer/{tenant_id}/public-key` | Get a tenant's public key |\n| POST | `/agent/rotate-keys` | Rotate encryption keys |\n| GET | `/agent/capabilities` | Get encryption capabilities |\n| POST | `/agent/initialize` | Initialize encryption for tenant |\n| GET | `/agent/bootstrap` | Skill bootstrap info |\n\n### Get Public Key\n\n**GET** `/agent/public-key`\n\n```json\n{\"public_key\": \"base64-encoded-X25519-public-key\", \"algorithm\": \"X25519\", \"created_at\": \"2026-02-11T10:00:00Z\"}\n```\n\n**GET** `/agent/peer/{tenant_id}/public-key` -- Retrieve another tenant's public key for encrypted communication.\n\n### How Encryption Works\n\nEach tenant has an X25519 keypair generated on initialization. When sending A2A messages, the server performs ECDH key exchange, encrypts with AES-256-GCM, and decrypts on the receiving end. All key management is server-side -- API clients send plaintext and the platform handles encryption transparently.\n\n---\n\n## A2A JSON-RPC\n\nThe core A2A endpoint accepts JSON-RPC 2.0 requests. All agent-to-agent operations go through this single endpoint. Use the fully scoped URL from your webhook configuration.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| POST | `/a2a/{tenant_id}/{session_id}/{webhook_id}` | Fully scoped endpoint (preferred) |\n| POST | `/a2a/{tenant_id}/{session_id}` | Tenant + session scoped |\n| POST | `/a2a/{session_id}` | Session scoped |\n| POST | `/a2a` | Generic (first active session) |\n| GET | `/a2a/schema` | Get A2A method schema |\n\n### Request Format\n\n```json\n{\n  \"jsonrpc\": \"2.0\",\n  \"method\": \"agent.message.send\",\n  \"params\": { ... },\n  \"id\": 1\n}\n```\n\n### Response Format\n\n```json\n{\n  \"jsonrpc\": \"2.0\",\n  \"result\": { ... },\n  \"id\": 1\n}\n```\n\n### Available Methods\n\n| Method | Description |\n|--------|-------------|\n| `agent.message.send` | Send a WhatsApp message via A2A |\n| `agent.group.create` | Create a new WhatsApp group |\n| `agent.group.invite` | Invite participants to a group |\n| `agent.group.list` | List available groups |\n| `group.getContext` | Get group metadata and recent activity |\n| `webhook_manager` | Manage webhooks via A2A |\n\n---\n\n### agent.message.send\n\nSend a WhatsApp message through the A2A protocol.\n\n**Request:**\n\n```json\n{\n  \"jsonrpc\": \"2.0\",\n  \"method\": \"agent.message.send\",\n  \"params\": {\n    \"session_id\": \"a1b2c3d4-...\",\n    \"to\": \"+5511999999999\",\n    \"message\": \"Hello from Agent!\",\n    \"metadata\": {\n      \"source_agent\": \"my-crm-agent\",\n      \"correlation_id\": \"req-123\"\n    }\n  },\n  \"id\": 1\n}\n```\n\n**Parameters:**\n\n| Field | Type | Required | Description |\n|-------|------|----------|-------------|\n| `session_id` | string | Yes | UUID of the WhatsApp session |\n| `to` | string | Yes | E.164 phone number (e.g., `+5511999999999`) |\n| `message` | string | Yes | Message text (max 4096 chars) |\n| `metadata` | object | No | Arbitrary metadata for tracking |\n\n**Response:**\n\n```json\n{\n  \"jsonrpc\": \"2.0\",\n  \"result\": {\n    \"message_id\": \"wa-msg-id-...\",\n    \"status\": \"sent\",\n    \"timestamp\": \"2026-02-11T10:05:00Z\"\n  },\n  \"id\": 1\n}\n```\n\n### agent.group.create / agent.group.invite / agent.group.list\n\nGroup management methods share a common pattern:\n\n```json\n// Create group\n{\"jsonrpc\":\"2.0\",\"method\":\"agent.group.create\",\"params\":{\"session_id\":\"...\",\"name\":\"Support Team\",\"participants\":[\"+5511999999999\"]},\"id\":2}\n\n// Invite to group\n{\"jsonrpc\":\"2.0\",\"method\":\"agent.group.invite\",\"params\":{\"session_id\":\"...\",\"group_id\":\"120363012345678901@g.us\",\"participants\":[\"+5511777777777\"]},\"id\":3}\n\n// List groups (supports limit/offset pagination)\n{\"jsonrpc\":\"2.0\",\"method\":\"agent.group.list\",\"params\":{\"session_id\":\"...\",\"limit\":20,\"offset\":0},\"id\":4}\n```\n\n### group.getContext\n\nRetrieve group metadata and recent activity for a monitored group.\n\n```json\n{\"jsonrpc\":\"2.0\",\"method\":\"group.getContext\",\"params\":{\"session_id\":\"...\",\"group_id\":\"120363012345678901@g.us\",\"limit\":50},\"id\":5}\n```\n\n### webhook_manager\n\nManage webhooks via A2A. Actions: `create`, `list`, `update`, `delete`\n\n```json\n{\"jsonrpc\":\"2.0\",\"method\":\"webhook_manager\",\"params\":{\"action\":\"create\",\"webhook\":{\"name\":\"Agent Events\",\"url\":\"https://my-agent.com/events\",\"events\":[\"message.received\"]}},\"id\":6}\n```\n\n---\n\n### JSON-RPC Error Codes\n\n| Code | Meaning |\n|------|---------|\n| -32600 | Invalid request |\n| -32601 | Method not found |\n| -32602 | Invalid params |\n| -32603 | Internal error |\n| -32000 | Rate limited |\n| -32001 | Content policy violation |\n| -32002 | Safeguard blocked |\n\n**Error response:**\n\n```json\n{\n  \"jsonrpc\": \"2.0\",\n  \"error\": {\n    \"code\": -32602,\n    \"message\": \"Invalid phone number format. Expected E.164 (e.g., +5511999999999)\"\n  },\n  \"id\": 1\n}\n```\n\n---\n\n## Content Policy\n\nConfigure content filtering rules for A2A communications. Policies control what content agents can send and receive.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/a2a-policy/settings` | Get policy settings |\n| PUT | `/a2a-policy/settings` | Update policy settings |\n| POST | `/a2a-policy/rules` | Create a custom rule |\n| PUT | `/a2a-policy/rules/{rule_id}` | Update a rule |\n| DELETE | `/a2a-policy/rules/{rule_id}` | Delete a rule |\n| POST | `/a2a-policy/rules/{rule_id}/toggle` | Enable/disable a rule |\n| POST | `/a2a-policy/test` | Test content against policy |\n| POST | `/a2a-policy/reset` | Reset policy to defaults |\n| GET | `/a2a-policy/stats` | Get policy enforcement stats |\n| GET | `/a2a-policy/safeguards` | Get safeguard configuration |\n\n### Get / Update Settings\n\n**GET** `/a2a-policy/settings` returns current policy. **PUT** `/a2a-policy/settings` updates it.\n\n```json\n{\n  \"enabled\": true,\n  \"input_sanitization_enabled\": true,\n  \"output_filtering_enabled\": true,\n  \"block_urls\": false,\n  \"block_phone_numbers\": false,\n  \"max_message_length\": 4096,\n  \"allowed_languages\": [\"en\", \"pt\", \"es\"]\n}\n```\n\n### Create Custom Rule\n\n**POST** `/a2a-policy/rules`\n\n```json\n{\n  \"name\": \"Block competitor mentions\",\n  \"pattern\": \"\\\\b(competitor1|competitor2)\\\\b\",\n  \"action\": \"block\",\n  \"description\": \"Prevent mentions of competitor brands\"\n}\n```\n\n**Response** `200 OK`:\n\n```json\n{\n  \"id\": \"rule-uuid-...\",\n  \"name\": \"Block competitor mentions\",\n  \"pattern\": \"\\\\b(competitor1|competitor2)\\\\b\",\n  \"action\": \"block\",\n  \"is_active\": true,\n  \"created_at\": \"2026-02-11T10:00:00Z\"\n}\n```\n\n### Test Content\n\n**POST** `/a2a-policy/test` -- Test a message against your policy without sending it.\n\n```json\n// Request\n{\"content\": \"Check out https://example.com for more info\"}\n\n// Response\n{\"allowed\": false, \"blocked_reason\": \"URL detected and block_urls is enabled\", \"matched_rules\": [\"built-in:block_urls\"], \"filtered_content\": \"Check out [URL REMOVED] for more info\"}\n```\n\n### Policy Stats\n\n**GET** `/a2a-policy/stats` -- Returns `total_checked`, `total_blocked`, `total_filtered`, and `top_rules` with hit counts.\n\n---\n\n## Rate Limits (A2A)\n\nA2A methods have per-method rate limits:\n\n| Method | Limit |\n|--------|-------|\n| `agent.message.send` | 30/min |\n| `agent.group.create` | 5/min |\n| `agent.group.invite` | 10/min |\n| `agent.group.list` | 60/min |\n| `group.getContext` | 30/min |\n| `webhook_manager` | 20/min |\n\nRate limit errors return JSON-RPC error code `-32000`.\n\n---\n\n## Examples\n\n### Discover the MoltFlow agent\n\n```bash\ncurl https://apiv2.waiflow.app/.well-known/agent.json\n```\n\n### Send a message via A2A\n\n```bash\n# Use your scoped endpoint: /a2a/{tenant_id}/{session_id}/{webhook_id}\ncurl -X POST https://apiv2.waiflow.app/api/v2/a2a/{tenant_id}/{session_id}/{webhook_id} \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"jsonrpc\": \"2.0\",\n    \"method\": \"agent.message.send\",\n    \"params\": {\n      \"session_id\": \"a1b2c3d4-...\",\n      \"to\": \"+5511999999999\",\n      \"message\": \"Hello from my AI agent!\"\n    },\n    \"id\": 1\n  }'\n```\n\n### Set up a content policy rule\n\n```bash\ncurl -X POST https://apiv2.waiflow.app/api/v2/a2a-policy/rules \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"name\": \"No external links\",\n    \"pattern\": \"https?://\",\n    \"action\": \"block\",\n    \"description\": \"Block all URLs in A2A messages\"\n  }'\n```\n\n### Test content against policy\n\n```bash\ncurl -X POST https://apiv2.waiflow.app/api/v2/a2a-policy/test \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"content\": \"Visit https://example.com for details\"\n  }'\n```\n\n---\n\n## Security Model\n\nSecurity layers: TLS 1.3 (transport) -> X25519 ECDH (key exchange) -> AES-256-GCM (message encryption) -> API Key/JWT (auth) -> AgentSafeguard (input validation) -> A2AContentFilter (content policy) -> TieredRateLimiter (rate limits) -> AuditLog (full audit trail).\n\nAll encryption key management is handled server-side. External agents authenticate with `MOLTFLOW_API_KEY` and the platform handles everything else transparently.\n\n---\n\n## Error Responses\n\nStandard HTTP errors: `400` (bad request), `401` (unauthorized), `403` (policy violation), `404` (not found), `429` (rate limited). JSON-RPC errors use codes listed above.\n\n---\n\n## Related Skills\n\n- **moltflow** -- Core API: sessions, messaging, groups, labels, webhooks\n- **moltflow-outreach** -- Bulk Send, Scheduled Messages, Custom Groups\n- **moltflow-leads** -- Lead detection, pipeline tracking, bulk operations, CSV/JSON export\n- **moltflow-ai** -- AI-powered auto-replies, voice transcription, RAG knowledge base, style profiles\n- **moltflow-reviews** -- Review collection and testimonial management\n- **moltflow-admin** -- Platform administration, user management, plan configuration\n\nFile v2.15.1:moltflow-admin/SKILL.md\n\n---\nname: moltflow-admin\ndescription: \"Manage MoltFlow authentication, billing, API keys, usage tracking, and tenant settings.\"\nsource: \"MoltFlow Team\"\nversion: \"2.15.1\"\nrisk: safe\nrequiredEnv:\n  - MOLTFLOW_API_KEY\nprimaryEnv: MOLTFLOW_API_KEY\ndisable-model-invocation: true\n---\n\n> **MoltFlow** — WhatsApp Business automation for teams. Connect, monitor, and automate WhatsApp at scale.\n> ***Due to high demand and a recent registration issue, we're offering our top-tier Business plan with unlimited quotas for just $19.90/month on yearly billing — for a limited time only.*** [**Claim the deal**](https://buy.stripe.com/cNifZibX7gpQebJ0nsfnO00)\n> Free tier available. [Sign up](https://molt.waiflow.app/checkout?plan=free)\n\n# MoltFlow Admin Skill\n\nManage authentication, billing, API keys, usage tracking, and tenant settings for MoltFlow.\n\n## Real-World Scenarios\n\n**Agency managing 5 clients** — \"Create a scoped API key for each client that only lets them send messages and read their own groups — nothing else.\"\n\n**Startup scaling up** — \"Check my current plan usage and tell me if I'm about to hit my message limit so I can upgrade before the campaign.\"\n\n**Compliance officer** — \"Show me the daily usage breakdown for this month so I can audit how many messages each session sent.\"\n\n## When to Use\n\nUse this skill when you need to:\n- Authenticate with MoltFlow (login, token refresh, magic link)\n- Manage API keys (create, rotate, revoke)\n- Check subscription status, plan limits, or usage\n- Create a Stripe checkout session or billing portal link\nTrigger phrases: \"login to MoltFlow\", \"create API key\", \"check subscription\", \"billing portal\", \"usage report\"\n\n## Prerequisites\n\n- **MOLTFLOW_API_KEY** — required for most endpoints. Generate from [MoltFlow Dashboard > API Keys](https://molt.waiflow.app/api-keys)\n- Auth endpoints (`/auth/*`) accept email/password — no API key needed for initial login\n\n## Base URL\n\n```\nhttps://apiv2.waiflow.app/api/v2\n```\n\n## Required API Key Scopes\n\n| Scope | Access |\n|-------|--------|\n| `settings` | `manage` |\n| `usage` | `read` |\n| `billing` | `manage` |\n| `account` | `manage` |\n\n## Authentication\n\nAll requests (except login/signup) require one of:\n- `Authorization: Bearer <access_token>` (JWT from login)\n- `X-API-Key: <api_key>` (API key from dashboard)\n\n---\n\n## Auth Endpoints\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| POST | `/auth/login` | Login with email/password |\n| POST | `/auth/refresh` | Refresh access token |\n| GET | `/auth/me` | Get current user profile |\n| POST | `/auth/logout` | Invalidate session |\n| POST | `/auth/forgot-password` | Request password reset email |\n| POST | `/auth/reset-password` | Confirm password reset |\n| POST | `/auth/verify-email` | Verify email address |\n| POST | `/auth/magic-link/request` | Request magic link login |\n| POST | `/auth/magic-link/verify` | Verify magic link token |\n| POST | `/auth/setup-password` | Set password for magic-link users |\n\n### Login — Request/Response\n\n```json\n// POST /auth/login\n{\n  \"email\": \"user@example.com\",\n  \"password\": \"your-password\"\n}\n\n// Response\n{\n  \"access_token\": \"eyJhbGciOi...\",\n  \"refresh_token\": \"eyJhbGciOi...\",\n  \"token_type\": \"bearer\",\n  \"user\": {\n    \"id\": \"uuid\",\n    \"email\": \"user@example.com\",\n    \"full_name\": \"John Doe\",\n    \"role\": \"owner\",\n    \"tenant_id\": \"uuid\"\n  }\n}\n```\n\n---\n\n## User Management\n\nSelf-service user profile endpoints (authenticated user):\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/users/me` | Get own profile |\n| PATCH | `/users/me` | Update own profile |\n\n---\n\n## API Keys\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/api-keys` | List all API keys |\n| POST | `/api-keys` | Create new key |\n| GET | `/api-keys/{id}` | Get key details |\n| DELETE | `/api-keys/{id}` | Revoke key |\n| POST | `/api-keys/{id}/rotate` | Rotate key (new secret) |\n\n### Create API Key — Request/Response\n\n```json\n// POST /api-keys\n{\n  \"name\": \"outreach-bot\",\n  \"scopes\": [\"messages:send\", \"custom-groups:manage\", \"bulk-send:manage\"],\n  \"expires_in_days\": 90\n}\n\n// Response (raw key shown ONCE — save it immediately)\n{\n  \"id\": \"uuid\",\n  \"name\": \"outreach-bot\",\n  \"key_prefix\": \"mf_abc1\",\n  \"raw_key\": \"mf_abc1234567890abcdef...\",\n  \"scopes\": [\"messages:send\", \"custom-groups:manage\", \"bulk-send:manage\"],\n  \"expires_at\": \"2026-04-15T10:00:00Z\",\n  \"created_at\": \"2026-01-15T10:00:00Z\",\n  \"is_active\": true\n}\n```\n\n- `scopes`: **Required** array of permission scopes. Specify only the scopes needed (e.g., `[\"sessions:read\", \"messages:send\"]`). See main SKILL.md for the complete scope reference.\n- `expires_in_days`: Optional expiry in days (default: no expiry).\n\n**Important:** The `raw_key` is only returned at creation time. It is stored as a SHA-256 hash — it cannot be retrieved later.\n\n---\n\n## Billing & Subscription\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/billing/subscription` | Current plan, limits, and usage |\n| POST | `/billing/checkout` | Create Stripe checkout session |\n| POST | `/billing/portal` | Get Stripe billing portal URL |\n| POST | `/billing/cancel` | Cancel subscription |\n| GET | `/billing/plans` | List available plans and pricing |\n| POST | `/billing/signup-checkout` | Checkout for new signups |\n\n### Check Subscription — Response\n\n```json\n{\n  \"plan_id\": \"pro\",\n  \"display_name\": \"Pro\",\n  \"status\": \"active\",\n  \"billing_cycle\": \"monthly\",\n  \"current_period_end\": \"2026-02-15T00:00:00Z\",\n  \"limits\": {\n    \"max_sessions\": 3,\n    \"max_messages_per_month\": 5000,\n    \"max_groups\": 10,\n    \"max_labels\": 50,\n    \"ai_replies_per_month\": 500\n  },\n  \"usage\": {\n    \"sessions\": 2,\n    \"messages_this_month\": 1247,\n    \"groups\": 5,\n    \"labels\": 12,\n    \"ai_replies_this_month\": 89\n  }\n}\n```\n\n### Create Checkout — Request\n\n```json\n// POST /billing/checkout\n{\n  \"plan_id\": \"pro\",\n  \"billing_cycle\": \"monthly\"\n}\n\n// Response\n{\n  \"checkout_url\": \"https://checkout.stripe.com/c/pay/cs_live_...\",\n  \"session_id\": \"cs_live_...\"\n}\n```\n\n---\n\n## Usage Tracking\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/usage/current` | Current month usage summary |\n| GET | `/usage/history` | Historical usage by month |\n| GET | `/usage/daily` | Daily breakdown for current month |\n\n---\n\n## Tenant Settings\n\nSelf-service tenant configuration (owner/admin role required for writes).\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/tenant/settings` | Get current tenant settings |\n| PATCH | `/tenant/settings` | Update tenant settings (owner/admin only) |\n\n#### Response Fields\n\n| Field | Type | Description |\n|-------|------|-------------|\n| `allowed_numbers` | `string[]` | Phone numbers allowed for outbound messaging |\n| `require_approval` | `bool` | Whether outbound messages require admin approval |\n| `ai_consent_enabled` | `bool` | Whether AI features (auto-reply, style matching) are enabled |\n\n#### Get Tenant Settings\n\n```bash\ncurl https://apiv2.waiflow.app/tenant/settings \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\"\n```\n\n### Get Settings — Response\n\n```json\n{\n  \"allowed_numbers\": [\"+5511999999999\"],\n  \"require_approval\": false,\n  \"ai_consent_enabled\": true\n}\n```\n\n#### Update Tenant Settings\n\n```bash\ncurl -X PATCH https://apiv2.waiflow.app/tenant/settings \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"ai_consent_enabled\": true}'\n```\n\n### Update Settings — Request Body\n\nAll fields are optional. Only provided fields are updated.\n\n```json\n{\n  \"allowed_numbers\": [\"+5511999999999\", \"+5511888888888\"],\n  \"require_approval\": true,\n  \"ai_consent_enabled\": true\n}\n```\n\n**Notes:**\n- `ai_consent_enabled` records a GDPR consent entry (consent type `ai_processing`, version `1.0`) with the user's IP and user-agent.\n- Any authenticated user can read settings; only `owner` or `admin` roles can update.\n\n---\n\n## curl Examples\n\n### 1. Login and Get Token\n\n```bash\ncurl -X POST https://apiv2.waiflow.app/api/v2/auth/login \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"email\": \"user@example.com\",\n    \"password\": \"your-password\"\n  }'\n```\n\n### 2. Create a Scoped API Key\n\n```bash\ncurl -X POST https://apiv2.waiflow.app/api/v2/api-keys \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"name\": \"outreach-bot\",\n    \"scopes\": [\"messages:send\", \"custom-groups:manage\", \"bulk-send:manage\"],\n    \"expires_in_days\": 90\n  }'\n```\n\n### 3. Check Subscription and Usage\n\n```bash\ncurl -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  \"https://apiv2.waiflow.app/api/v2/billing/subscription\"\n```\n\n### 4. Check Current Month Usage\n\n```bash\ncurl -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  \"https://apiv2.waiflow.app/api/v2/usage/current\"\n```\n\n---\n\n## Error Responses\n\n| Status | Meaning |\n|--------|---------|\n| 400 | Invalid request body or parameters |\n| 401 | Missing or invalid authentication |\n| 403 | Insufficient permissions |\n| 404 | Resource not found |\n| 409 | Conflict (duplicate email, plan ID, etc.) |\n| 422 | Validation error |\n| 429 | Rate limit exceeded |\n\n---\n\n## Tips\n\n- **API key security**: The raw key is only shown once at creation. Store it in a secrets manager.\n- **Token refresh**: Access tokens expire in 30 minutes. Use the refresh endpoint to get new ones without re-authenticating.\n- **Magic links**: For passwordless login, use `magic-link/request` then `magic-link/verify`.\n- **Plan limits**: Use `GET /billing/subscription` to check remaining quotas before making API calls.\n- **Scoped keys**: Always use the minimum scopes needed for your workflow.\n\n---\n\n## Related Skills\n\n- **moltflow** -- Core API: sessions, messaging, groups, labels, webhooks\n- **moltflow-outreach** -- Bulk Send, Scheduled Messages, Custom Groups\n- **moltflow-leads** -- Lead detection, pipeline tracking, bulk operations, CSV/JSON export\n- **moltflow-ai** -- AI-powered auto-replies, voice transcription, RAG knowledge base, style profiles\n- **moltflow-a2a** -- Agent-to-Agent protocol, encrypted messaging, content policy\n- **moltflow-reviews** -- Review collection and testimonial management\n\nFile v2.15.1:moltflow-ai/SKILL.md\n\n---\nname: moltflow-ai\ndescription: \"AI-powered WhatsApp features: auto-replies, voice transcription, RAG knowledge base, and style profiles. Use when: ai reply, transcribe voice, knowledge base, upload document, build style, learn mode.\"\nsource: \"MoltFlow Team\"\nversion: \"2.15.1\"\nrisk: safe\nrequiredEnv:\n  - MOLTFLOW_API_KEY\nprimaryEnv: MOLTFLOW_API_KEY\ndisable-model-invocation: true\n---\n\n> **MoltFlow** -- WhatsApp Business automation for teams. Connect, monitor, and automate WhatsApp at scale.\n> ***Due to high demand and a recent registration issue, we're offering our top-tier Business plan with unlimited quotas for just $19.90/month on yearly billing — for a limited time only.*** [**Claim the deal**](https://buy.stripe.com/cNifZibX7gpQebJ0nsfnO00)\n> Free tier available. [Sign up](https://molt.waiflow.app/checkout?plan=free)\n\n# MoltFlow AI Features\n\nAI-powered capabilities for WhatsApp automation: voice transcription, RAG knowledge base, style profile learning, and intelligent reply generation.\n\n## Real-World Scenarios\n\n**Healthcare clinic** — \"Transcribe patient voice notes sent via WhatsApp and save them as searchable text records I can pull up later.\"\n\n**Law firm** — \"Upload our service agreements to the knowledge base so the AI can answer client questions about terms and pricing accurately.\"\n\n**Sales team** — \"Clone my top closer's writing style so AI replies to leads sound like him — casual, confident, uses emojis.\"\n\n**Customer support** — \"Auto-reply to common questions like 'What are your hours?' and 'Where are you located?' using our FAQ document.\"\n\n## When to Use\n\n- \"Transcribe a voice message\" or \"convert audio to text\"\n- \"Upload a document to knowledge base\" or \"ingest PDF\"\n- \"Search knowledge base\" or \"find in documents\"\n- \"Build style profile\" or \"learn my writing style\"\n- \"Generate an AI reply\" or \"auto-reply to customer\"\n- \"Preview AI response\" or \"test reply generation\"\n- \"List knowledge sources\" or \"delete document\"\n\n## Prerequisites\n\n1. **MOLTFLOW_API_KEY** -- Generate from the [MoltFlow Dashboard](https://molt.waiflow.app) under Settings > API Keys\n2. **Pro plan or higher** ($29.90/mo) -- AI features are not available on the Starter plan\n3. Base URL: `https://apiv2.waiflow.app/api/v2`\n4. All AI endpoints are under the `/ai` prefix\n\n## Required API Key Scopes\n\n| Scope | Access |\n|-------|--------|\n| `ai` | `read/manage` |\n\n## Authentication\n\nEvery request must include one of:\n\n```\nAuthorization: Bearer <jwt_token>\n```\n\nor\n\n```\nX-API-Key: <your_api_key>\n```\n\n---\n\n## Voice Transcription\n\nTranscribe WhatsApp voice messages using Whisper AI. Transcription runs asynchronously via a Celery worker.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| POST | `/ai/voice/transcribe` | Queue a voice message for transcription |\n| GET | `/ai/voice/status/{task_id}` | Check transcription task status |\n| GET | `/ai/messages/{message_id}/transcript` | Get the transcript for a message |\n\n### Queue Transcription\n\n**POST** `/ai/voice/transcribe`\n\n```json\n{\n  \"message_id\": \"msg-uuid-...\"\n}\n```\n\n**Response** `200 OK`:\n\n```json\n{\n  \"task_id\": \"celery-task-id-...\",\n  \"message_id\": \"msg-uuid-...\",\n  \"status\": \"queued\"\n}\n```\n\n### Check Status\n\n**GET** `/ai/voice/status/{task_id}`\n\n```json\n{\n  \"task_id\": \"celery-task-id-...\",\n  \"status\": \"completed\",\n  \"result\": {\n    \"transcript\": \"Hello, I wanted to ask about...\",\n    \"language\": \"en\",\n    \"confidence\": 0.95\n  }\n}\n```\n\nStatus values: `queued`, `processing`, `completed`, `failed`\n\n### Get Transcript\n\n**GET** `/ai/messages/{message_id}/transcript`\n\n```json\n{\n  \"message_id\": \"msg-uuid-...\",\n  \"transcript\": \"Hello, I wanted to ask about...\",\n  \"language\": \"en\",\n  \"confidence\": 0.95,\n  \"transcribed_at\": \"2026-02-11T10:05:00Z\"\n}\n```\n\n---\n\n## RAG Knowledge Base\n\nBuild a searchable knowledge base for AI-powered replies grounded in your business data.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| POST | `/ai/knowledge/ingest` | Upload and index a document |\n| POST | `/ai/knowledge/search` | Semantic search across documents |\n| GET | `/ai/knowledge/sources` | List all indexed documents |\n| DELETE | `/ai/knowledge/{source_id}` | Delete a document |\n\n### Upload Document\n\n**POST** `/ai/knowledge/ingest` (multipart/form-data)\n\n| Field | Type | Description |\n|-------|------|-------------|\n| `file` | File | PDF or TXT file (max 100MB) |\n\n**Response** `200 OK`:\n\n```json\n{\n  \"id\": \"src-uuid-...\",\n  \"name\": \"product-catalog.pdf\",\n  \"source_type\": \"application/pdf\",\n  \"chunk_count\": 47,\n  \"status\": \"indexed\",\n  \"task_id\": \"celery-task-id-...\"\n}\n```\n\nSupported file types: `application/pdf`, `text/plain` (`.pdf`, `.txt`)\n\n### Search Knowledge Base\n\n**POST** `/ai/knowledge/search`\n\n```json\n{\n  \"query\": \"What is the return policy?\",\n  \"top_k\": 5\n}\n```\n\n**Response** `200 OK`:\n\n```json\n{\n  \"query\": \"What is the return policy?\",\n  \"results\": [\n    {\n      \"source_id\": \"src-uuid-...\",\n      \"content_type\": \"application/pdf\",\n      \"content_preview\": \"Our return policy allows returns within 30 days...\",\n      \"metadata\": {\"page\": 12, \"chunk\": 3},\n      \"similarity\": 0.92\n    }\n  ],\n  \"count\": 1\n}\n```\n\nOptional filters:\n\n```json\n{\n  \"query\": \"shipping costs\",\n  \"filters\": {\"source_type\": \"application/pdf\"},\n  \"top_k\": 10\n}\n```\n\n### List Documents\n\n**GET** `/ai/knowledge/sources`\n\n```json\n[\n  {\n    \"id\": \"src-uuid-...\",\n    \"name\": \"product-catalog.pdf\",\n    \"source_type\": \"application/pdf\",\n    \"chunk_count\": 47,\n    \"status\": \"indexed\",\n    \"created_at\": \"2026-02-11T09:00:00Z\",\n    \"indexed_at\": \"2026-02-11T09:02:00Z\"\n  }\n]\n```\n\nDocument status values: `processing`, `indexed`, `failed`\n\n### Delete Document\n\n**DELETE** `/ai/knowledge/{source_id}` -- Returns `204 No Content`\n\n---\n\n## Style Profiles (Learn Mode)\n\nConfigure AI writing style profiles scoped to individual chats or as a general profile. The AI auto-selects the best matching profile when generating replies.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| POST | `/ai/style/train` | Start building a style profile |\n| GET | `/ai/style/status/{task_id}` | Check build status |\n| GET | `/ai/style/profile` | Get a style profile |\n| GET | `/ai/style/profiles` | List all style profiles |\n| DELETE | `/ai/style/profile/{profile_id}` | Delete a style profile |\n\n### Build Style Profile\n\n**POST** `/ai/style/train`\n\n```json\n{\n  \"session_id\": \"session-uuid-...\",\n  \"wa_chat_id\": \"5511999999999@c.us\",\n  \"name\": \"Sales\"\n}\n```\n\n| Field | Type | Required | Description |\n|-------|------|----------|-------------|\n| `contact_id` | string | No | Legacy — use `wa_chat_id` instead |\n| `session_id` | UUID | No | Session to scope the build to |\n| `wa_chat_id` | string | No | Chat to scope the build to (WhatsApp JID). Omit for general profile |\n| `name` | string | No | Profile name (e.g., \"Sales\", \"Support\", \"Family\") |\n\n**Note:** Omit both `session_id` and `wa_chat_id` to build a general profile from all conversations.\n\n**Response** `200 OK`:\n\n```json\n{\n  \"task_id\": \"celery-task-id-...\",\n  \"tenant_id\": \"tenant-uuid-...\",\n  \"contact_id\": \"5511999999999@c.us\",\n  \"status\": \"queued\"\n}\n```\n\nThe build runs asynchronously. Check progress with the status endpoint.\n\n### Get Style Profile\n\n**GET** `/ai/style/profile?contact_id=5511999999999@c.us`\n\n```json\n{\n  \"id\": \"profile-uuid-...\",\n  \"tenant_id\": \"tenant-uuid-...\",\n  \"contact_id\": \"5511999999999@c.us\",\n  \"name\": \"Sales\",\n  \"session_id\": \"session-uuid-...\",\n  \"wa_chat_id\": \"5511999999999@c.us\",\n  \"features\": {\n    \"avg_sentence_length\": 12.5,\n    \"formality_score\": 0.7,\n    \"emoji_frequency\": 0.15,\n    \"vocabulary_richness\": 0.82\n  },\n  \"sample_count\": 150,\n  \"last_trained_at\": \"2026-02-11T09:30:00Z\"\n}\n```\n\n### List All Profiles\n\n**GET** `/ai/style/profiles`\n\n```json\n[\n  {\n    \"id\": \"profile-uuid-1\",\n    \"tenant_id\": \"tenant-uuid-...\",\n    \"name\": \"Sales\",\n    \"session_id\": \"session-uuid-...\",\n    \"wa_chat_id\": \"5511999999999@c.us\",\n    \"features\": { \"formality_score\": 0.7 },\n    \"sample_count\": 150,\n    \"last_trained_at\": \"2026-02-11T09:30:00Z\"\n  },\n  {\n    \"id\": \"profile-uuid-2\",\n    \"tenant_id\": \"tenant-uuid-...\",\n    \"name\": \"General\",\n    \"session_id\": null,\n    \"wa_chat_id\": null,\n    \"features\": { \"formality_score\": 0.5 },\n    \"sample_count\": 420,\n    \"last_trained_at\": \"2026-02-11T10:00:00Z\"\n  }\n]\n```\n\n### Delete Profile\n\n**DELETE** `/ai/style/profile/{profile_id}` -- Returns `204 No Content`\n\n---\n\n## AI Reply Generation\n\nGenerate intelligent reply suggestions using RAG context and style profiles.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| POST | `/ai/generate-reply` | Generate a reply suggestion |\n| GET | `/ai/preview` | Preview a reply without tracking usage |\n\n### Generate Reply\n\n**POST** `/ai/generate-reply`\n\n```json\n{\n  \"contact_id\": \"5511999999999@c.us\",\n  \"context\": \"Customer asks: Do you offer international shipping?\",\n  \"use_rag\": true,\n  \"apply_style\": true,\n  \"profile_id\": \"profile-uuid-...\",\n  \"session_id\": \"session-uuid-...\"\n}\n```\n\n**Response** `200 OK`:\n\n```json\n{\n  \"reply\": \"Yes, we ship internationally to over 50 countries! Shipping typically takes 7-14 business days. You can find our full shipping policy on our website.\",\n  \"rag_sources\": [\"product-catalog.pdf\"],\n  \"style_applied\": true,\n  \"model\": \"gpt-4o-mini\",\n  \"tokens_used\": 245,\n  \"requires_approval\": false\n}\n```\n\n### Parameters\n\n| Field | Type | Default | Description |\n|-------|------|---------|-------------|\n| `contact_id` | string | required | WhatsApp JID of the contact |\n| `context` | string | required | Customer question or prompt for reply generation (max 2000 chars) |\n| `use_rag` | boolean | `true` | Include knowledge base context in generation |\n| `apply_style` | boolean | `true` | Apply style profile to response |\n| `profile_id` | UUID | `null` | Specific style profile to use (skips auto-selection cascade) |\n| `session_id` | UUID | `null` | Session for cascade profile resolution |\n| `approved` | boolean | `false` | Set `true` to confirm an approval-required reply |\n\n**Note:** If `profile_id` is omitted and `apply_style` is true, the API auto-selects the best profile using the cascade: exact chat match → session-level → tenant-level general → no style.\n\n### Preview Reply\n\n**GET** `/ai/preview?contact_id=5511999999999@c.us&context=What+are+your+hours&use_rag=true&apply_style=true`\n\nSame response format as `generate-reply`, but does not count toward usage metrics.\n\n### Safety Features\n\nAI reply generation includes built-in safety:\n\n- **Input sanitization** -- Detects and blocks prompt injection attempts\n- **Intent verification** -- Flags ambiguous or high-risk intents for confirmation\n- **Output filtering** -- Screens generated content for PII, secrets, and policy violations\n- **Content policy** -- Tenant-configurable rules (see moltflow-a2a skill)\n\n---\n\n## Examples\n\n### Upload a knowledge base document\n\n```bash\ncurl -X POST https://apiv2.waiflow.app/api/v2/ai/knowledge/ingest \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -F \"file=@product-catalog.pdf\"\n```\n\n### Generate an AI reply using RAG\n\n```bash\ncurl -X POST https://apiv2.waiflow.app/api/v2/ai/generate-reply \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"contact_id\": \"5511999999999@c.us\",\n    \"context\": \"Customer asks: What is your return policy?\",\n    \"use_rag\": true,\n    \"apply_style\": true\n  }'\n```\n\n### Generate reply with specific profile\n\n```bash\ncurl -X POST https://apiv2.waiflow.app/api/v2/ai/generate-reply \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"contact_id\": \"5511999999999@c.us\",\n    \"context\": \"Customer asks: What is your return policy?\",\n    \"use_rag\": true,\n    \"apply_style\": true,\n    \"profile_id\": \"profile-uuid-...\"\n  }'\n```\n\n### Build a style profile\n\n```bash\ncurl -X POST https://apiv2.waiflow.app/api/v2/ai/style/train \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"session_id\": \"session-uuid-...\",\n    \"wa_chat_id\": \"5511999999999@c.us\",\n    \"name\": \"Sales\"\n  }'\n```\n\n---\n\n## Plan Requirements\n\n| Feature | Starter | Pro ($29.90/mo) | Business ($69.90/mo) |\n|---------|---------|-----------------|------------|\n| Voice Transcription | -- | Yes | Yes |\n| RAG Knowledge Base | -- | Yes (10 docs) | Yes (unlimited) |\n| Style Profiles | -- | Yes (3 profiles) | Yes (unlimited) |\n| AI Reply Generation | -- | Yes | Yes |\n\n---\n\n## Error Responses\n\n| Status | Meaning |\n|--------|---------|\n| 400 | Bad request (invalid input, unsupported file type) |\n| 401 | Unauthorized (missing or invalid auth) |\n| 403 | Forbidden (feature requires Pro plan or higher) |\n| 404 | Resource not found (message, document, profile) |\n| 413 | File too large (exceeds 100MB limit) |\n| 429 | Rate limited |\n\n---\n\n## Related Skills\n\n- **moltflow** -- Core API: sessions, messaging, groups, labels, webhooks\n- **moltflow-outreach** -- Bulk Send, Scheduled Messages, Custom Groups\n- **moltflow-leads** -- Lead detection, pipeline tracking, bulk operations, CSV/JSON export\n- **moltflow-a2a** -- Agent-to-Agent protocol, encrypted messaging, content policy\n- **moltflow-reviews** -- Review collection and testimonial management\n- **moltflow-admin** -- Platform administration, user management, plan configuration\n\nFile v2.15.1:moltflow-leads/SKILL.md\n\n---\nname: moltflow-leads\ndescription: \"WhatsApp lead detection and CRM pipeline. Detect purchase-intent signals in groups, track lead status, bulk operations, CSV/JSON export. Use when: leads, lead detection, pipeline, qualify, convert, bulk status, export leads.\"\nsource: \"MoltFlow Team\"\nversion: \"2.15.1\"\nrisk: safe\nrequiredEnv:\n  - MOLTFLOW_API_KEY\nprimaryEnv: MOLTFLOW_API_KEY\ndisable-model-invocation: true\n---\n\n> **MoltFlow** -- WhatsApp Business automation for teams. Connect, monitor, and automate WhatsApp at scale.\n> ***Due to high demand and a recent registration issue, we're offering our top-tier Business plan with unlimited quotas for just $19.90/month on yearly billing — for a limited time only.*** [**Claim the deal**](https://buy.stripe.com/cNifZibX7gpQebJ0nsfnO00)\n> Free tier available. [Sign up](https://molt.waiflow.app/checkout?plan=free)\n\n# MoltFlow Leads -- Detection & CRM Pipeline\n\nDetect purchase-intent signals from monitored WhatsApp groups, track leads through a sales pipeline, perform bulk operations, and export for your CRM.\n\n## Real-World Scenarios\n\n**Real estate agent** — \"Monitor my property groups for keywords like 'looking for', '3 bedrooms', and 'budget' — anyone who matches goes straight into my lead pipeline.\"\n\n**Car dealership** — \"When a lead moves from 'contacted' to 'qualified', automatically add them to my VIP follow-up group for a test drive invite.\"\n\n**Insurance broker** — \"Export all converted leads from this quarter as a CSV so I can import them into my CRM for commission tracking.\"\n\n**Wedding planner** — \"Show me all new leads from my vendor groups that I haven't contacted yet, sorted by detection date.\"\n\n## When to Use\n\n- \"List leads\" or \"show detected leads\"\n- \"Update lead status\" or \"mark lead as contacted\"\n- \"Bulk update leads\" or \"change status for multiple leads\"\n- \"Add leads to group\" or \"bulk add to custom group\"\n- \"Export leads as CSV\" or \"download leads JSON\"\n- \"Check lead reciprocity\" or \"has this lead messaged me?\"\n- \"Filter leads by status\" or \"search leads\"\n\n## Prerequisites\n\n1. **MOLTFLOW_API_KEY** -- Generate from the [MoltFlow Dashboard](https://molt.waiflow.app) under Settings > API Keys\n2. At least one monitored WhatsApp group with keyword detection enabled\n3. Base URL: `https://apiv2.waiflow.app/api/v2`\n\n## Required API Key Scopes\n\n| Scope | Access |\n|-------|--------|\n| `leads` | `read/manage` |\n| `groups` | `read` |\n\n## Authentication\n\nEvery request must include one of:\n\n```\nAuthorization: Bearer <jwt_token>\n```\n\nor\n\n```\nX-API-Key: <your_api_key>\n```\n\n---\n\n## How Lead Detection Works\n\n1. You configure group monitoring via the Groups API (see `moltflow` skill)\n2. Set `monitor_mode: \"keywords\"` with keywords like `\"looking for\"`, `\"price\"`, `\"interested\"`\n3. When a keyword match is detected, MoltFlow auto-creates a lead\n4. Leads appear in the Leads API with status `new` and the triggering keyword highlighted\n5. You track them through the pipeline: `new` -> `contacted` -> `qualified` -> `converted`\n\n## AI Group Intelligence (Pro+ Plans)\n\nWhen AI monitoring is enabled on a group (`monitor_mode: \"ai_analysis\"`), each message is classified by an LLM using your own API key (OpenAI, Anthropic, Groq, or Mistral). Results are available on each message and on the `lead.detected` webhook.\n\n**AI analysis fields** — available via `GET /api/v2/groups/{group_id}/messages` and the MCP tool `moltflow_get_group_messages`:\n\n| Field | Type | Description |\n|-------|------|-------------|\n| `intent` | string | `buying_intent`, `product_inquiry`, `support_request`, `complaint`, `off_topic`, `spam_noise`, `unknown` |\n| `lead_score` | integer | 1-10 (10 = highest buying signal) |\n| `confidence` | float | 0.0-1.0 classifier confidence |\n| `reason` | string | Human-readable explanation for the classification |\n\n**Webhook events for AI leads:**\n- `lead.detected` — fires immediately when a lead is created; includes `ai_analysis` field (may be null if AI hasn't completed yet)\n- `group.message.analyzed` — fires after AI analysis completes (Pro/Business only); includes full `ai_analysis` object\n\n**Setup:**\n1. Go to Settings > AI Configuration and add your LLM API key\n2. Set `monitor_mode: \"ai_analysis\"` on the group (via PATCH `/api/v2/groups/{id}` or dashboard)\n3. Optionally set `monitor_prompt` for custom classification instructions\n\n---\n\n## Leads API\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/leads` | List leads (filter by status, group, search) |\n| GET | `/leads/{id}` | Get lead details |\n| PATCH | `/leads/{id}/status` | Update lead status (state machine validated) |\n| GET | `/leads/{id}/reciprocity` | Check if lead messaged you first (anti-spam) |\n| POST | `/leads/bulk/status` | Bulk update lead status |\n| POST | `/leads/bulk/add-to-group` | Bulk add leads to custom group |\n| GET | `/leads/export/csv` | Export as CSV (Pro+ plan, max 10,000) |\n| GET | `/leads/export/json` | Export as JSON (Pro+ plan, max 10,000) |\n\n### List Leads\n\n**GET** `/leads`\n\nQuery parameters:\n\n| Parameter | Type | Description |\n|-----------|------|-------------|\n| `status` | string | Filter by status (`new`, `contacted`, `qualified`, `converted`, `lost`) |\n| `source_group_id` | UUID | Filter by source monitored group |\n| `search` | string | Search in contact name, phone, or keyword |\n| `limit` | int | Page size (default 50) |\n| `offset` | int | Pagination offset |\n\n**Response** `200 OK`:\n\n```json\n{\n  \"leads\": [\n    {\n      \"id\": \"lead-uuid-...\",\n      \"contact_phone\": \"+15550123456\",\n      \"contact_name\": \"John D.\",\n      \"lead_status\": \"new\",\n      \"lead_score\": 0,\n      \"lead_detected_at\": \"2026-02-12T14:30:00Z\",\n      \"source_group\": {\n        \"id\": \"group-uuid-...\",\n        \"name\": \"Real Estate IL\"\n      },\n      \"trigger\": {\n        \"matched_keyword\": \"interested in buying\",\n        \"message_preview\": \"Hi, I'm interested in buying a 3-bedroom...\",\n        \"monitor_mode\": \"keywords\",\n        \"detected_at\": \"2026-02-12T14:30:00Z\"\n      }\n    }\n  ],\n  \"total\": 47,\n  \"limit\": 50,\n  \"offset\": 0\n}\n```\n\n### Get Lead Details\n\n**GET** `/leads/{id}`\n\nReturns full lead info including group context, detection metadata, message count, and status.\n\n### Update Lead Status\n\n**PATCH** `/leads/{id}/status`\n\n```json\n{\n  \"status\": \"contacted\"\n}\n```\n\n**State machine validation** -- only valid transitions are allowed:\n\n- `new` -> `contacted`, `qualified`, `converted`, `lost`\n- `contacted` -> `qualified`, `converted`, `lost`\n- `qualified` -> `converted`, `lost`\n- `converted` -> (terminal -- no further transitions)\n- `lost` -> `new` (reopen only)\n\nInvalid transitions return `400 Bad Request`.\n\n### Reciprocity Check\n\n**GET** `/leads/{id}/reciprocity?session_id=session-uuid`\n\nThe `session_id` query parameter is **required** -- it specifies which WhatsApp session to check inbound messages from.\n\n```json\n{\n  \"lead_id\": \"lead-uuid-...\",\n  \"has_messaged_first\": true,\n  \"last_inbound_at\": \"2026-02-12T15:00:00Z\"\n}\n```\n\nUse this before reaching out -- if the lead hasn't messaged you directly, sending a cold message may trigger WhatsApp spam detection.\n\n### Bulk Status Update\n\n**POST** `/leads/bulk/status`\n\n```json\n{\n  \"lead_ids\": [\"uuid1\", \"uuid2\", \"uuid3\"],\n  \"status\": \"contacted\"\n}\n```\n\n**Response** `200 OK`:\n\n```json\n{\n  \"updated\": 3,\n  \"failed\": 0,\n  \"errors\": []\n}\n```\n\nEach lead is individually validated against the state machine. Leads with invalid transitions are reported in `errors` but don't block the rest.\n\n### Bulk Add to Custom Group\n\n**POST** `/leads/bulk/add-to-group`\n\n```json\n{\n  \"lead_ids\": [\"uuid1\", \"uuid2\"],\n  \"custom_group_id\": \"custom-group-uuid-...\"\n}\n```\n\nAdds leads' phone numbers to the specified custom group for use with Bulk Send or Scheduled Messages.\n\n### Export Leads\n\n**GET** `/leads/export/csv` -- Returns CSV file download\n**GET** `/leads/export/json` -- Returns JSON array\n\nBoth support optional filters: `status`, `source_group_id`, `search`. Max 10,000 rows per export.\n\n**Requires Pro plan or above.**\n\n---\n\n## Examples\n\n### Full workflow: Detect -> Qualify -> Outreach\n\n```bash\n# 1. List new leads from a specific group\ncurl \"https://apiv2.waiflow.app/api/v2/leads?status=new&source_group_id=group-uuid\" \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\"\n\n# 2. Check reciprocity before reaching out\ncurl \"https://apiv2.waiflow.app/api/v2/leads/{lead_id}/reciprocity?session_id=session-uuid\" \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\"\n\n# 3. Update status to contacted\ncurl -X PATCH https://apiv2.waiflow.app/api/v2/leads/{lead_id}/status \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"status\": \"contacted\"}'\n\n# 4. Bulk add qualified leads to a custom group for follow-up\ncurl -X POST https://apiv2.waiflow.app/api/v2/leads/bulk/add-to-group \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"lead_ids\": [\"uuid1\", \"uuid2\", \"uuid3\"],\n    \"custom_group_id\": \"follow-up-group-uuid\"\n  }'\n\n# 5. Export all converted leads as CSV\ncurl \"https://apiv2.waiflow.app/api/v2/leads/export/csv?status=converted\" \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -o converted-leads.csv\n```\n\n---\n\n## Plan Requirements\n\n| Feature | Free | Starter | Pro | Business |\n|---------|------|---------|-----|----------|\n| Lead detection | Yes (2 groups) | Yes (5 groups) | Yes (20 groups) | Yes (100 groups) |\n| Lead list & detail | Yes | Yes | Yes | Yes |\n| Status update | Yes | Yes | Yes | Yes |\n| Bulk operations | -- | -- | Yes | Yes |\n| CSV/JSON export | -- | -- | Yes | Yes |\n\n---\n\n## Error Responses\n\n| Status | Meaning |\n|--------|---------|\n| 400 | Invalid status transition or bad request |\n| 401 | Unauthorized (missing or invalid auth) |\n| 403 | Forbidden (plan limit or feature gate) |\n| 404 | Lead not found |\n| 429 | Rate limited |\n\n---\n\n## Related Skills\n\n- **moltflow** -- Core API: sessions, messaging, groups, labels, webhooks\n- **moltflow-outreach** -- Bulk Send, Scheduled Messages, Custom Groups\n- **moltflow-ai** -- AI-powered auto-replies, voice transcription, RAG, style profiles\n- **moltflow-a2a** -- Agent-to-Agent protocol, encrypted messaging, content policy\n- **moltflow-reviews** -- Review collection and testimonial management\n- **moltflow-admin** -- Platform administration, user management, plan configuration\n\nFile v2.15.1:moltflow-onboarding/SKILL.md\n\n---\nname: moltflow-onboarding\ndescription: \"Read-only account health check and growth opportunity report for MoltFlow WhatsApp automation. Fetches account metadata (counts, timestamps, group membership) and presents findings. Use when: onboarding, setup, getting started, growth, optimize, briefing, account review.\"\nsource: \"MoltFlow Team\"\nversion: \"2.15.1\"\nrisk: safe\nrequiredEnv:\n  - MOLTFLOW_API_KEY\nprimaryEnv: MOLTFLOW_API_KEY\ndisable-model-invocation: true\n---\n\n> **MoltFlow** -- WhatsApp Business automation for teams. Connect, monitor, and automate WhatsApp at scale.\n> ***Due to high demand and a recent registration issue, we're offering our top-tier Business plan with unlimited quotas for just $19.90/month on yearly billing — for a limited time only.*** [**Claim the deal**](https://buy.stripe.com/cNifZibX7gpQebJ0nsfnO00)\n> Free tier available. [Sign up](https://molt.waiflow.app/checkout?plan=free)\n\n# MoltFlow Account Health & Growth Report\n\nA read-only analysis tool that fetches your MoltFlow account data and presents an actionable health report. All API calls in this skill are `GET` requests — no data is modified.\n\n## When to Use\n\n- \"Help me get started\" or \"set up my account\"\n- \"Find leads in my chats\" or \"find opportunities\"\n- \"What should I do to grow?\" or \"suggest growth plays\"\n- \"Optimize my setup\" or \"what am I missing?\"\n- \"Run my daily briefing\" or \"give me my morning report\"\n\n## Prerequisites\n\n1. **MOLTFLOW_API_KEY** -- Generate from the [MoltFlow Dashboard](https://molt.waiflow.app) under Sessions > API Keys\n2. Base URL: `https://apiv2.waiflow.app/api/v2`\n\n## Required API Key Scopes\n\n| Scope | Access |\n|-------|--------|\n| `sessions` | `manage` |\n| `messages` | `send` |\n\n## Authentication\n\n```\nX-API-Key: <your_api_key>\n```\n\n---\n\n## Step 1: Fetch Account Data (Read-Only)\n\nGather data from these read-only endpoints. All are `GET` requests authenticated via `X-API-Key: $MOLTFLOW_API_KEY` header. Base URL: `https://apiv2.waiflow.app/api/v2`.\n\n| Endpoint | Data | Full Docs |\n|----------|------|-----------|\n| `GET /users/me` | Account & plan | moltflow-admin SKILL.md |\n| `GET /sessions` | WhatsApp sessions | moltflow SKILL.md |\n| `GET /groups` | Monitored groups | moltflow SKILL.md |\n| `GET /custom-groups` | Custom groups | moltflow-outreach SKILL.md |\n| `GET /webhooks` | Webhooks | moltflow SKILL.md |\n| `GET /reviews/collectors` | Review collectors | moltflow-reviews SKILL.md |\n| `GET /tenant/settings` | Tenant settings | moltflow-admin SKILL.md |\n| `GET /scheduled-messages` | Scheduled messages | moltflow-outreach SKILL.md |\n| `GET /usage/current` | Usage stats | moltflow-admin SKILL.md |\n| `GET /leads` | Existing leads | moltflow-leads SKILL.md |\n| `GET /messages/chats/{session_id}` | Chats (per session) | moltflow SKILL.md |\n\n## Step 2: Present Account Health Report\n\nFormat the fetched data as a status dashboard:\n\n```\n## MoltFlow Account Health\n\n**Plan:** {plan} | **Tenant:** {tenant} | **Messages:** {used}/{limit} this month\n\n| Area                  | Status | Details |\n|-----------------------|--------|---------|\n| WhatsApp Sessions     | ✅/❌  | {count} sessions, {working} active |\n| Group Monitoring      | ✅/❌  | {monitored}/{available} groups |\n| Custom Groups         | ✅/❌  | {count} groups ({member_count} contacts) |\n| Lead Pipeline         | ✅/❌  | {lead_count} leads ({new_count} new, {contacted} contacted) |\n| AI Features           | ✅/❌  | Consent {yes/no}, {profile_count} style profiles |\n| Scheduled Messages    | ✅/❌  | {count} active |\n| Review Collectors     | ✅/❌  | {count} active |\n| Webhooks              | ✅/❌  | {count} configured |\n| Conversations         | 📊     | {chat_count} conversations, {total_messages} messages |\n```\n\n## Step 3: Analyze Growth Opportunities\n\nUsing the already-fetched data, identify and present these patterns:\n\n### 3A: Chat Analysis\n\nFor each working session, analyze the chat list from Step 1:\n\n- **Unanswered contacts** — people who messaged but got no reply (warm leads going cold)\n- **High-engagement contacts** — most active by message count, not yet in a custom group\n- **Recent contacts** — last 7 days, no follow-up sent\n- **Uncategorized contacts** — not in any custom group\n\n### 3B: Unmonitored Groups\n\nCompare available groups (`GET /groups/available/{session_id}`) against monitored groups. Highlight large unmonitored groups by member count.\n\n### 3C: Usage & Plan Utilization\n\nFrom usage data, flag:\n- Over 80% utilization — approaching plan limits\n- Under 20% utilization — unused capacity\n\n### 3D: Uncaptured Reviews\n\nIf no review collectors exist but there are active conversations, flag the gap.\n\n## Step 4: Suggest Next Actions\n\nAfter presenting the read-only analysis, list concrete next steps the user can take. Each action references the appropriate skill module — see that module's SKILL.md for full endpoint documentation, request bodies, and examples.\n\n| Suggested Action | Skill Module |\n|-----------------|--------------|\n| Create a custom group for hot leads | moltflow-outreach |\n| Start monitoring high-value groups | moltflow (Group Monitoring section) |\n| Schedule follow-up messages | moltflow-outreach (Scheduled Messages section) |\n| Set up a review collector | moltflow-reviews |\n| Configure AI features | moltflow-admin |\n\n**All actions require explicit user approval.** This skill only reads data and presents findings — it does not create, modify, or delete any resources.\n\n---\n\n## Important Rules\n\n- **This skill is read-only** — it fetches and analyzes data but never modifies account state\n- **All state-changing actions** (creating groups, scheduling messages, etc.) must be performed via the referenced skill modules with explicit user approval\n- If an API call fails, show the error and offer to retry or skip\n- All API calls use the `MOLTFLOW_API_KEY` environment variable — never hardcode keys\n- When analyzing chats, focus on business-relevant signals, not personal conversations\n- Respect anti-spam: never suggest messaging contacts who haven't initiated contact\n\nFile v2.15.1:moltflow-outreach/SKILL.md\n\n---\nname: moltflow-outreach\ndescription: \"Bulk messaging, scheduled messages, scheduled reports, and custom groups for WhatsApp outreach. Use when: bulk send, broadcast, schedule message, schedule report, cron, custom group, contact list, ban-safe messaging.\"\nsource: \"MoltFlow Team\"\nversion: \"2.15.1\"\nrisk: safe\nrequiredEnv:\n  - MOLTFLOW_API_KEY\nprimaryEnv: MOLTFLOW_API_KEY\ndisable-model-invocation: true\n---\n\n> **MoltFlow** -- WhatsApp Business automation for teams. Connect, monitor, and automate WhatsApp at scale.\n> ***Due to high demand and a recent registration issue, we're offering our top-tier Business plan with unlimited quotas for just $19.90/month on yearly billing — for a limited time only.*** [**Claim the deal**](https://buy.stripe.com/cNifZibX7gpQebJ0nsfnO00)\n> Free tier available. [Sign up](https://molt.waiflow.app/checkout?plan=free)\n\n# MoltFlow Outreach -- Bulk Send, Scheduled Messages, Reports & Custom Groups\n\nBroadcast to custom contact lists with ban-safe throttling, schedule recurring messages with timezone support, generate automated reports with WhatsApp delivery, and manage targeted contact groups for WhatsApp outreach.\n\n## Real-World Scenarios\n\n**Gym owner** — \"Send a 'Happy New Year' promo with a discount code to all my members, spaced out so I don't get banned.\"\n\n**Freelance consultant** — \"Every Friday at 5 PM, send a 'weekend availability' message to my active client list.\"\n\n**Marketing agency** — \"Build a contact group from 3 WhatsApp groups, deduplicate, and blast a product launch announcement.\"\n\n**Restaurant chain** — \"Schedule a weekly report showing how many reservation confirmations were sent and delivered — send it to my WhatsApp every Monday morning.\"\n\n## When to Use\n\n- \"Send bulk message\" or \"broadcast to group\"\n- \"Schedule a WhatsApp message\" or \"set up recurring message\"\n- \"Generate a report\" or \"schedule a report\"\n- \"Send me a usage summary\" or \"get a lead pipeline report\"\n- \"Create a contact list\" or \"build custom group\"\n- \"Pause bulk send\" or \"cancel scheduled message\"\n- \"Export group members as CSV\" or \"import contacts\"\n- \"Send weekly update\" or \"set up cron schedule\"\n\n## Prerequisites\n\n1. **MOLTFLOW_API_KEY** -- Generate from the [MoltFlow Dashboard](https://molt.waiflow.app) under Settings > API Keys\n2. At least one connected WhatsApp session (status: `working`)\n3. Base URL: `https://apiv2.waiflow.app/api/v2`\n\n## Required API Key Scopes\n\n| Scope | Access |\n|-------|--------|\n| `custom-groups` | `read/manage` |\n| `bulk-send` | `read/manage` |\n| `scheduled` | `read/manage` |\n| `reports` | `read/manage` |\n\n## Authentication\n\nEvery request must include one of:\n\n```\nAuthorization: Bearer <jwt_token>\n```\n\nor\n\n```\nX-API-Key: <your_api_key>\n```\n\n---\n\n## Custom Groups\n\nBuild targeted contact lists for Bulk Send and Scheduled Messages. Custom Groups are MoltFlow contact lists -- not WhatsApp groups.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/custom-groups` | List all custom groups |\n| POST | `/custom-groups` | Create group (with optional initial members) |\n| GET | `/custom-groups/contacts` | List all unique contacts across sessions |\n| GET | `/custom-groups/wa-groups` | List WhatsApp groups for import |\n| POST | `/custom-groups/from-wa-groups` | Create group by importing WA group members |\n| GET | `/custom-groups/{id}` | Group details with members |\n| PATCH | `/custom-groups/{id}` | Update group name |\n| DELETE | `/custom-groups/{id}` | Delete group and members |\n| POST | `/custom-groups/{id}/members/add` | Add members (skips duplicates) |\n| POST | `/custom-groups/{id}/members/remove` | Remove members by phone |\n| GET | `/custom-groups/{id}/export/csv` | Export members as CSV |\n| GET | `/custom-groups/{id}/export/json` | Export members as JSON |\n\n### Create Custom Group\n\n**POST** `/custom-groups`\n\n```json\n{\n  \"name\": \"VIP Clients\",\n  \"members\": [\n    {\"phone\": \"+15550123456\"},\n    {\"phone\": \"+15550987654\", \"name\": \"Jane Doe\"}\n  ]\n}\n```\n\nMembers is an array of objects with `phone` (required) and `name` (optional). Omit `members` to create an empty group.\n\n### Create Group from WhatsApp Groups\n\n**POST** `/custom-groups/from-wa-groups`\n\n```json\n{\n  \"name\": \"Imported Leads\",\n  \"wa_groups\": [\n    {\"wa_group_id\": \"120363012345@g.us\", \"session_id\": \"session-uuid-...\"},\n    {\"wa_group_id\": \"120363067890@g.us\", \"session_id\": \"session-uuid-...\"}\n  ]\n}\n```\n\nResolves participants from each WhatsApp group, deduplicates by phone number, and creates the custom group with all unique members.\n\n### List WhatsApp Groups\n\n**GET** `/custom-groups/wa-groups`\n\nReturns all WhatsApp groups across your connected sessions with participant counts. Use this to discover groups available for import.\n\n**Response** `201 Created`:\n\n```json\n{\n  \"id\": \"group-uuid-...\",\n  \"name\": \"VIP Clients\",\n  \"member_count\": 2,\n  \"created_at\": \"2026-02-12T10:00:00Z\"\n}\n```\n\n### Add Members\n\n**POST** `/custom-groups/{id}/members/add`\n\n```json\n{\n  \"contacts\": [\n    {\"phone\": \"+15551112222\"},\n    {\"phone\": \"+15553334444\", \"name\": \"Bob Smith\"}\n  ]\n}\n```\n\nEach contact is an object with `phone` (required) and `name` (optional). Max 1,000 per request. Duplicates are silently skipped.\n\n### Export Members\n\n**GET** `/custom-groups/{id}/export/csv` -- Returns CSV download\n**GET** `/custom-groups/{id}/export/json` -- Returns JSON array\n\n---\n\n## Bulk Send\n\nBroadcast messages to a custom group with ban-safe throttling. Random 30s-2min delays between messages simulate human behavior.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| POST | `/bulk-send` | Create bulk send job (quota reserved) |\n| GET | `/bulk-send` | List all bulk send jobs |\n| GET | `/bulk-send/{id}` | Job details with recipients |\n| POST | `/bulk-send/{id}/pause` | Pause running job |\n| POST | `/bulk-send/{id}/resume` | Resume paused job |\n| POST | `/bulk-send/{id}/cancel` | Cancel job (releases unused quota) |\n| GET | `/bulk-send/{id}/progress` | Real-time progress via SSE |\n\n### Create Bulk Send Job\n\n**POST** `/bulk-send`\n\n```json\n{\n  \"session_id\": \"session-uuid-...\",\n  \"custom_group_id\": \"custom-group-uuid-...\",\n  \"message_content\": \"Special offer for our VIP clients!\"\n}\n```\n\n| Field | Type | Required | Description |\n|-------|------|----------|-------------|\n| `session_id` | UUID | Yes | WhatsApp session to send from |\n| `custom_group_id` | UUID | Yes | Target custom group |\n| `message_type` | string | No | `text` (default) or `media` |\n| `message_content` | string | Conditional | Message text (max 4096 chars). Required if no `media_url` |\n| `media_url` | string | Conditional | HTTP(S) URL for media. Required if no `message_content` |\n\n**Response** `201 Created`:\n\n```json\n{\n  \"id\": \"job-uuid-...\",\n  \"session_id\": \"session-uuid-...\",\n  \"custom_group_id\": \"custom-group-uuid-...\",\n  \"status\": \"running\",\n  \"total_recipients\": 127,\n  \"sent_count\": 0,\n  \"failed_count\": 0,\n  \"created_at\": \"2026-02-12T10:00:00Z\"\n}\n```\n\n### Stream Progress (SSE)\n\n**GET** `/bulk-send/{id}/progress`\n\nReturns Server-Sent Events with real-time updates:\n\n```\ndata: {\"sent\": 45, \"total\": 127, \"failed\": 0, \"status\": \"running\"}\ndata: {\"sent\": 46, \"total\": 127, \"failed\": 0, \"status\": \"running\"}\n```\n\n### Job Status Values\n\n`pending` -> `running` -> `completed` / `paused` / `cancelled` / `failed`\n\n### Anti-Ban Safety\n\n- Random 30s-2min delays between messages\n- Typing simulation before each message\n- Seen/read indicators marked automatically\n- Burst rate limiting (4 msgs/2 min)\n\n---\n\n## Scheduled Messages\n\nSchedule one-time or recurring WhatsApp messages to custom groups with timezone support and full lifecycle control.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/scheduled-messages` | List all scheduled messages |\n| POST | `/scheduled-messages` | Create schedule (one-time or recurring) |\n| GET | `/scheduled-messages/{id}` | Schedule details with execution history |\n| PATCH | `/scheduled-messages/{id}` | Update schedule and recalculate next run |\n| POST | `/scheduled-messages/{id}/cancel` | Cancel schedule |\n| POST | `/scheduled-messages/{id}/pause` | Pause active schedule |\n| POST | `/scheduled-messages/{id}/resume` | Resume paused schedule |\n| DELETE | `/scheduled-messages/{id}` | Delete cancelled/completed schedule |\n| GET | `/scheduled-messages/{id}/history` | Execution history (paginated) |\n\n### Create One-Time Schedule\n\n**POST** `/scheduled-messages`\n\n```json\n{\n  \"name\": \"Follow-up\",\n  \"session_id\": \"session-uuid-...\",\n  \"custom_group_id\": \"custom-group-uuid-...\",\n  \"schedule_type\": \"one_time\",\n  \"message_content\": \"Just checking in on your order!\",\n  \"scheduled_time\": \"2026-02-15T09:00:00\",\n  \"timezone\": \"Asia/Jerusalem\"\n}\n```\n\n### Create Recurring Schedule (Cron)\n\n**POST** `/scheduled-messages`\n\n```json\n{\n  \"name\": \"Weekly Update\",\n  \"session_id\": \"session-uuid-...\",\n  \"custom_group_id\": \"custom-group-uuid-...\",\n  \"schedule_type\": \"cron\",\n  \"message_content\": \"Weekly team report is ready!\",\n  \"cron_expression\": \"0 9 * * MON\",\n  \"timezone\": \"America/New_York\"\n}\n```\n\n**Response** `201 Created`:\n\n```json\n{\n  \"id\": \"schedule-uuid-...\",\n  \"name\": \"Weekly Update\",\n  \"status\": \"active\",\n  \"schedule_type\": \"cron\",\n  \"cron_expression\": \"0 9 * * MON\",\n  \"timezone\": \"America/New_York\",\n  \"next_run_at\": \"2026-02-17T09:00:00-05:00\",\n  \"created_at\": \"2026-02-12T10:00:00Z\"\n}\n```\n\n### Schedule Types\n\n- `one_time` -- Single send at `scheduled_time`\n- `daily` -- Every day (requires `cron_expression`)\n- `weekly` -- Every week (requires `cron_expression`)\n- `monthly` -- Every month (requires `cron_expression`)\n- `cron` -- Custom cron expression (e.g., `0 9 * * MON-FRI`)\n\n**Note:** All recurring types (`daily`, `weekly`, `monthly`, `cron`) require a `cron_expression`. Minimum interval: 5 minutes.\n\n### Required Fields\n\n| Field | Type | Required | Description |\n|-------|------|----------|-------------|\n| `name` | string | Yes | Schedule name (1-255 chars) |\n| `session_id` | UUID | Yes | WhatsApp session to send from |\n| `custom_group_id` | UUID | Yes | Target custom group |\n| `schedule_type` | string | Yes | One of: `one_time`, `daily`, `weekly`, `monthly`, `cron` |\n| `message_type` | string | No | `text` (default) or `media` |\n| `message_content` | string | Conditional | Message text (max 4096). Required if no `media_url` |\n| `media_url` | string | Conditional | HTTP(S) URL. Required if no `message_content` |\n| `scheduled_time` | datetime | Conditional | ISO 8601. Required for `one_time` |\n| `cron_expression` | string | Conditional | Cron string. Required for recurring types |\n| `timezone` | string | No | IANA timezone (default: `UTC`) |\n\n### Schedule Status Values\n\n`active` -> `paused` / `cancelled` / `completed`\n\n---\n\n## Scheduled Reports\n\nGenerate automated summaries of your MoltFlow activity on a schedule. Choose from 10 prebuilt templates covering leads, messaging, sessions, and more. Reports can be viewed in the dashboard or delivered directly to your WhatsApp.\n\nSet `delivery_method` to `\"whatsapp\"` to receive report summaries directly in your connected WhatsApp session. The report is formatted as plain text and sent to the session owner's own chat.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/reports/templates` | List available report templates |\n| POST | `/reports` | Create a new scheduled report |\n| GET | `/reports` | List your reports |\n| GET | `/reports/{id}` | Get report with execution history |\n| PATCH | `/reports/{id}` | Update schedule or settings |\n| POST | `/reports/{id}/pause` | Pause a scheduled report |\n| POST | `/reports/{id}/resume` | Resume a paused report |\n| DELETE | `/reports/{id}` | Delete a report |\n\n### List Report Templates\n\n**GET** `/reports/templates`\n\nReturns all 10 available report templates with descriptions and supported parameters.\n\n```bash\ncurl -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  https://apiv2.waiflow.app/api/v2/reports/templates\n```\n\n**Response** `200 OK`:\n\n```json\n[\n  {\n    \"id\": \"daily_activity\",\n    \"name\": \"Daily Activity Summary\",\n    \"description\": \"Messages sent/received, leads detected, session uptime\"\n  },\n  {\n    \"id\": \"lead_pipeline\",\n    \"name\": \"Lead Pipeline Report\",\n    \"description\": \"Lead sources, funnel stages, conversion rates\"\n  }\n]\n```\n\n### Create a Scheduled Report\n\n**POST** `/reports`\n\n```bash\ncurl -X POST -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"name\": \"Weekly Lead Pipeline\",\n    \"template_id\": \"lead_pipeline\",\n    \"schedule_type\": \"weekly\",\n    \"cron_expression\": \"0 9 * * MON\",\n    \"timezone\": \"America/New_York\",\n    \"delivery_method\": \"whatsapp\"\n  }' \\\n  https://apiv2.waiflow.app/api/v2/reports\n```\n\n**Response** `201 Created`:\n\n```json\n{\n  \"id\": \"report-uuid-...\",\n  \"name\": \"Weekly Lead Pipeline\",\n  \"template_id\": \"lead_pipeline\",\n  \"schedule_type\": \"weekly\",\n  \"cron_expression\": \"0 9 * * MON\",\n  \"timezone\": \"America/New_York\",\n  \"delivery_method\": \"whatsapp\",\n  \"status\": \"active\",\n  \"next_run_at\": \"2026-02-17T09:00:00-05:00\",\n  \"created_at\": \"2026-02-13T10:00:00Z\"\n}\n```\n\n### Required Fields\n\n| Field | Type | Required | Description |\n|-------|------|----------|-------------|\n| `name` | string | Yes | Report name (1-255 chars) |\n| `template_id` | string | Yes | Template ID from `/reports/templates` |\n| `schedule_type` | string | Yes | One of: `one_time`, `daily`, `weekly`, `monthly`, `cron` |\n| `cron_expression` | string | Conditional | Cron string. Required for recurring types |\n| `timezone` | string | No | IANA timezone (default: `UTC`) |\n| `delivery_method` | string | No | `dashboard` (default) or `whatsapp` |\n\n### Report Templates\n\n| Template ID | Name | Description |\n|-------------|------|-------------|\n| `daily_activity` | Daily Activity Summary | Messages, leads, sessions |\n| `lead_pipeline` | Lead Pipeline Report | Sources, funnel, conversions |\n| `unanswered_contacts` | Unanswered Contacts | Warm leads going cold |\n| `vip_contacts` | VIP Contacts | Most active conversations |\n| `group_monitoring` | Group Monitoring Digest | Keyword matches, leads |\n| `scheduled_messages_status` | Scheduled Messages Status | Executed vs failed |\n| `bulk_send_progress` | Bulk Send Progress | Active, completed, stats |\n| `usage_plan` | Usage & Plan Utilization | Limits, suggestions |\n| `session_health` | Session Health Check | Uptime, connection issues |\n| `review_digest` | Review & Testimonial Digest | Sentiment, approvals |\n\n### Delivery Methods\n\n- **`dashboard`** (default) -- Report is generated and viewable in the MoltFlow Reports page with formatted tables and stats.\n- **`whatsapp`** -- Report summary is formatted as plain text and sent to your connected WhatsApp session. The message is delivered to the session owner's own chat so you see it directly in WhatsApp.\n\n### Report Status Values\n\n`active` -> `paused` / `cancelled` / `completed`\n\n---\n\n## Examples\n\n### Full workflow: Group -> Bulk Send -> Schedule\n\n```bash\n# 1. Create a custom group\ncurl -X POST https://apiv2.waiflow.app/api/v2/custom-groups \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"name\": \"VIP Clients\"}'\n\n# 2. Add members to the group\ncurl -X POST https://apiv2.waiflow.app/api/v2/custom-groups/{group_id}/members/add \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"contacts\": [{\"phone\": \"+15550123456\"}, {\"phone\": \"+15550987654\"}, {\"phone\": \"+15551112222\"}]}'\n\n# 3. Bulk send to the group\ncurl -X POST https://apiv2.waiflow.app/api/v2/bulk-send \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"session_id\": \"session-uuid-...\",\n    \"custom_group_id\": \"group-uuid-...\",\n    \"message_content\": \"Exclusive offer for our VIP clients!\"\n  }'\n\n# 4. Schedule a weekly follow-up to the group\ncurl -X POST https://apiv2.waiflow.app/api/v2/scheduled-messages \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"name\": \"Weekly VIP Update\",\n    \"session_id\": \"session-uuid-...\",\n    \"custom_group_id\": \"group-uuid-...\",\n    \"schedule_type\": \"cron\",\n    \"message_content\": \"Weekly report is ready!\",\n    \"cron_expression\": \"0 9 * * MON\",\n    \"timezone\": \"Asia/Jerusalem\"\n  }'\n```\n\n### Pause and resume a bulk send\n\n```bash\n# Pause\ncurl -X POST https://apiv2.waiflow.app/api/v2/bulk-send/{job_id}/pause \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\"\n\n# Resume\ncurl -X POST https://apiv2.waiflow.app/api/v2/bulk-send/{job_id}/resume \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\"\n```\n\n### Export group members\n\n```bash\ncurl https://apiv2.waiflow.app/api/v2/custom-groups/{group_id}/export/csv \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -o vip-clients.csv\n```\n\n---\n\n## Plan Limits\n\n| Feature | Free | Starter | Pro | Business |\n|---------|------|---------|-----|----------|\n| Custom Groups | 2 | 5 | 20 | 100 |\n| Bulk Send | -- | Yes | Yes | Yes |\n| Scheduled Messages | -- | Yes | Yes | Yes |\n| Scheduled Reports | 2 | 5 | 10 | Unlimited |\n| Messages/month | 50 | 500 | 1,500 | 3,000 |\n\n---\n\n## Error Responses\n\n| Status | Meaning |\n|--------|---------|\n| 400 | Bad request (invalid input) |\n| 401 | Unauthorized (missing or invalid auth) |\n| 403 | Forbidden (plan limit or feature gate) |\n| 404 | Resource not found |\n| 422 | Validation error (missing required fields) |\n| 429 | Rate limited |\n\n---\n\n## Related Skills\n\n- **moltflow** -- Core API: sessions, messaging, groups, labels, webhooks\n- **moltflow-leads** -- Lead detection, pipeline tracking, bulk operations, CSV/JSON export\n- **moltflow-ai** -- AI-powered auto-replies, voice transcription, RAG, style profiles\n- **moltflow-a2a** -- Agent-to-Agent protocol, encrypted messaging, content policy\n- **moltflow-reviews** -- Review collection and testimonial management\n- **moltflow-admin** -- Platform administration, user management, plan configuration\n\nFile v2.15.1:moltflow-reviews/SKILL.md\n\n---\nname: moltflow-reviews\ndescription: \"Collect and manage customer reviews via MoltFlow API. Sentiment scoring, testimonial extraction, and review management.\"\nsource: \"MoltFlow Team\"\nversion: \"2.15.1\"\nrisk: safe\nrequiredEnv:\n  - MOLTFLOW_API_KEY\nprimaryEnv: MOLTFLOW_API_KEY\ndisable-model-invocation: true\n---\n\n> **MoltFlow** — WhatsApp Business automation for teams. Connect, monitor, and automate WhatsApp at scale.\n> ***Due to high demand and a recent registration issue, we're offering our top-tier Business plan with unlimited quotas for just $19.90/month on yearly billing — for a limited time only.*** [**Claim the deal**](https://buy.stripe.com/cNifZibX7gpQebJ0nsfnO00)\n> Free tier available. [Sign up](https://molt.waiflow.app/checkout?plan=free)\n\n# MoltFlow Reviews Skill\n\nCollect, analyze, and manage customer reviews via the MoltFlow API. Automate sentiment scoring, extract testimonials, and export social proof for your business.\n\n## Real-World Scenarios\n\n**Restaurant owner** — \"After every dinner reservation, collect feedback from WhatsApp chats and auto-approve anything with a sentiment score above 0.8.\"\n\n**Airbnb host** — \"Scan my guest conversations for praise keywords like 'amazing', 'clean', and 'recommend', then export the best ones as HTML for my listing page.\"\n\n**Dentist** — \"Set up a review collector on my patient support chat — only capture English messages that mention 'thank' or 'great service'.\"\n\n## When to Use\n\nUse this skill when you need to:\n- Set up automated review collection from WhatsApp conversations\n- Create or configure a review collector with sentiment thresholds\n- List, approve, hide, or delete collected reviews\n- Export testimonials as JSON or HTML for external use\n- Trigger a manual scan of conversations for reviews\n- Check review statistics and sentiment breakdowns\n\nTrigger phrases: \"collect reviews\", \"set up review collector\", \"export testimonials\", \"approve reviews\", \"sentiment analysis\", \"customer feedback WhatsApp\"\n\n## Prerequisites\n\n- **MOLTFLOW_API_KEY** — required. Generate from [MoltFlow Dashboard > API Keys](https://molt.waiflow.app/api-keys)\n- At least one connected WhatsApp session (status: `working`)\n- MoltFlow Pro plan or higher (review collection is a paid feature)\n\n## Base URL\n\n```\nhttps://apiv2.waiflow.app/api/v2\n```\n\n## Required API Key Scopes\n\n| Scope | Access |\n|-------|--------|\n| `reviews` | `read/manage` |\n\n## Authentication\n\nAll requests require one of:\n- `Authorization: Bearer <access_token>` (JWT from login)\n- `X-API-Key: <api_key>` (API key from dashboard)\n\n---\n\n## Review Collectors\n\nCollectors automatically extract reviews based on sentiment scoring, keyword matching, and language filters.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/reviews/collectors` | List all collectors |\n| POST | `/reviews/collectors` | Create a new collector |\n| GET | `/reviews/collectors/{id}` | Get collector details |\n| PATCH | `/reviews/collectors/{id}` | Update collector config |\n| DELETE | `/reviews/collectors/{id}` | Delete a collector |\n| POST | `/reviews/collectors/{id}/run` | Trigger manual scan |\n\n### Create Collector — Request Body\n\n```json\n{\n  \"name\": \"Main Store Reviews\",\n  \"description\": \"Collect reviews from customer support chats\",\n  \"session_id\": \"uuid-of-connected-session\",\n  \"source_type\": \"all\",\n  \"min_positive_words\": 3,\n  \"min_sentiment_score\": 0.6,\n  \"include_keywords\": [\"great\", \"recommend\", \"excellent\"],\n  \"exclude_keywords\": [\"spam\", \"wrong number\"],\n  \"languages\": [\"en\", \"es\"]\n}\n```\n\n**source_type options:** `all` | `groups` | `chats` | `selected`\n\nWhen `source_type` is `selected`, provide `selected_chat_ids` with specific WhatsApp chat IDs.\n\n### Create Collector — Response\n\n```json\n{\n  \"id\": \"c1a2b3c4-...\",\n  \"name\": \"Main Store Reviews\",\n  \"session_id\": \"uuid-of-connected-session\",\n  \"source_type\": \"all\",\n  \"min_sentiment_score\": 0.6,\n  \"include_keywords\": [\"great\", \"recommend\", \"excellent\"],\n  \"is_active\": true,\n  \"created_at\": \"2026-01-15T10:30:00Z\",\n  \"review_count\": 0\n}\n```\n\n### Update Collector — Request Body\n\nAll fields are optional. Only provided fields are updated.\n\n```json\n{\n  \"name\": \"Updated Collector Name\",\n  \"min_sentiment_score\": 0.7,\n  \"is_active\": false\n}\n```\n\n---\n\n## Reviews\n\nCollected reviews contain the original message, sentiment score, contact info, and approval status.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/reviews` | List reviews (with filters) |\n| GET | `/reviews/stats` | Review statistics |\n| GET | `/reviews/{id}` | Get single review |\n| PATCH | `/reviews/{id}` | Approve, hide, or annotate |\n| DELETE | `/reviews/{id}` | Delete a review |\n| GET | `/reviews/testimonials/export` | Export testimonials |\n\n### List Reviews — Query Parameters\n\n| Parameter | Type | Default | Description |\n|-----------|------|---------|-------------|\n| `collector_id` | UUID | — | Filter by collector |\n| `is_approved` | bool | — | Filter approved only |\n| `is_hidden` | bool | — | Filter hidden |\n| `min_score` | float | — | Minimum sentiment score |\n| `limit` | int | 50 | Page size |\n| `offset` | int | 0 | Pagination offset |\n\n### Review Object\n\n```json\n{\n  \"id\": \"r1a2b3c4-...\",\n  \"collector_id\": \"c1a2b3c4-...\",\n  \"contact_name\": \"John D.\",\n  \"contact_phone\": \"1234567890@c.us\",\n  \"message_text\": \"Your service was excellent! Highly recommend to anyone looking for quality support.\",\n  \"sentiment_score\": 0.92,\n  \"sentiment_label\": \"positive\",\n  \"detected_language\": \"en\",\n  \"is_approved\": false,\n  \"is_hidden\": false,\n  \"notes\": null,\n  \"collected_at\": \"2026-01-16T14:22:00Z\"\n}\n```\n\n### Approve/Hide Review — Request Body\n\n```json\n{\n  \"is_approved\": true,\n  \"is_hidden\": false,\n  \"notes\": \"Great testimonial — use on website\"\n}\n```\n\n### Export Testimonials — Query Parameters\n\n| Parameter | Type | Default | Description |\n|-----------|------|---------|-------------|\n| `format` | string | `json` | `json` or `html` |\n| `collector_id` | UUID | — | Filter by collector |\n| `approved_only` | bool | `true` | Only export approved reviews |\n\n---\n\n## curl Examples\n\n### 1. Create a Review Collector\n\n```bash\ncurl -X POST https://apiv2.waiflow.app/api/v2/reviews/collectors \\\n  -H \"X-API-Key: mf_your_api_key_here\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"name\": \"Customer Feedback\",\n    \"session_id\": \"a1b2c3d4-e5f6-7890-abcd-ef1234567890\",\n    \"source_type\": \"all\",\n    \"min_sentiment_score\": 0.7,\n    \"include_keywords\": [\"thank\", \"recommend\", \"love\"],\n    \"languages\": [\"en\"]\n  }'\n```\n\n### 2. List Approved Reviews\n\n```bash\ncurl \"https://apiv2.waiflow.app/api/v2/reviews?is_approved=true&limit=20\" \\\n  -H \"X-API-Key: mf_your_api_key_here\"\n```\n\n### 3. Export Testimonials as HTML\n\n```bash\ncurl \"https://apiv2.waiflow.app/api/v2/reviews/testimonials/export?format=html&approved_only=true\" \\\n  -H \"X-API-Key: mf_your_api_key_here\" \\\n  -o testimonials.html\n```\n\n---\n\n## Error Responses\n\n| Status | Meaning |\n|--------|---------|\n| 400 | Invalid request body or parameters |\n| 401 | Missing or invalid authentication |\n| 403 | Feature not available on current plan |\n| 404 | Collector or review not found |\n| 422 | Validation error (check field constraints) |\n| 429 | Rate limit exceeded |\n\n---\n\n## Tips\n\n- **Sentiment threshold**: Start with `0.6` and adjust up if you get too many false positives.\n- **Keyword filters**: Use `include_keywords` to match industry-specific praise terms.\n- **Manual scan**: Use `POST /reviews/collectors/{id}/run` after connecting a new session to backfill reviews.\n- **Export regularly**: Export approved testimonials for website widgets, social media, or marketing materials.\n\n---\n\n## Related Skills\n\n- **moltflow** -- Core API: sessions, messaging, groups, labels, webhooks\n- **moltflow-outreach** -- Bulk Send, Scheduled Messages, Custom Groups\n- **moltflow-leads** -- Lead detection, pipeline tracking, bulk operations, CSV/JSON export\n- **moltflow-ai** -- AI-powered auto-replies, voice transcription, RAG knowledge base, style profiles\n- **moltflow-a2a** -- Agent-to-Agent protocol, encrypted messaging, content policy\n- **moltflow-admin** -- Platform administration, user management, plan configuration\n\nFile v2.15.1:moltflow/SKILL.md\n\n---\nname: moltflow\ndescription: \"WhatsApp Business automation API for sessions, messaging, groups, labels, and webhooks. Use when: whatsapp, send message, create session, qr code, monitor group, label contacts, webhook.\"\nsource: \"MoltFlow Team\"\nversion: \"2.15.1\"\nrisk: safe\nrequiredEnv:\n  - MOLTFLOW_API_KEY\nprimaryEnv: MOLTFLOW_API_KEY\ndisable-model-invocation: true\n---\n\n> **MoltFlow** -- WhatsApp Business automation for teams. Connect, monitor, and automate WhatsApp at scale.\n> ***Due to high demand and a recent registration issue, we're offering our top-tier Business plan with unlimited quotas for just $19.90/month on yearly billing — for a limited time only.*** [**Claim the deal**](https://buy.stripe.com/cNifZibX7gpQebJ0nsfnO00)\n> Free tier available. [Sign up](https://molt.waiflow.app/checkout?plan=free)\n\n# MoltFlow Core API\n\nManage WhatsApp sessions, send messages, monitor groups, organize with labels, and receive real-time events via webhooks.\n\n## Real-World Scenarios\n\n**Dental clinic** — \"Send an appointment confirmation to each patient after they book, and a reminder 24 hours before their visit.\"\n\n**Property manager** — \"Monitor my tenant WhatsApp groups for maintenance keywords like 'leak', 'broken', and 'urgent', and flag them instantly.\"\n\n**E-commerce store** — \"When a customer messages my support number, auto-label them as 'New Inquiry' and route the chat to the right team.\"\n\n**Logistics company** — \"Set up a webhook so my dispatch system gets notified the moment a driver sends a delivery confirmation photo.\"\n\n## When to Use\n\n- \"Connect WhatsApp\" or \"create a session\"\n- \"Send a WhatsApp message\" or \"send text to contact\"\n- \"Monitor a WhatsApp group\" or \"list groups\"\n- \"Label contacts\" or \"sync labels from WhatsApp\"\n- \"Set up a webhook\" or \"listen for WhatsApp events\"\n- \"Get QR code\" or \"start session\"\n- \"List chats\" or \"get conversations\"\n\n## Prerequisites\n\n1. **MOLTFLOW_API_KEY** -- Generate from the [MoltFlow Dashboard](https://molt.waiflow.app) under Settings > API Keys\n2. All requests require authentication via `Authorization: Bearer <token>` or `X-API-Key: <key>`\n3. Base URL: `https://apiv2.waiflow.app/api/v2`\n\n## Required API Key Scopes\n\n| Scope | Access |\n|-------|--------|\n| `sessions` | `read/manage` |\n| `messages` | `read/send` |\n| `groups` | `read/manage` |\n| `labels` | `read/manage` |\n| `webhooks` | `read/manage` |\n\n## Authentication\n\nEvery request must include one of:\n\n```\nAuthorization: Bearer <jwt_token>\n```\n\nor\n\n```\nX-API-Key: <your_api_key>\n```\n\n---\n\n## Sessions\n\nManage WhatsApp connections. Each session represents one WhatsApp account linked via QR code.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/sessions` | List all sessions |\n| POST | `/sessions` | Create a new session |\n| GET | `/sessions/{id}` | Get session details |\n| DELETE | `/sessions/{id}` | Delete a session |\n| POST | `/sessions/{id}/start` | Start session (triggers QR scan) |\n| POST | `/sessions/{id}/stop` | Stop a running session |\n| POST | `/sessions/{id}/restart` | Restart a session |\n| POST | `/sessions/{id}/logout` | Logout and clear auth state |\n| GET | `/sessions/{id}/qr` | Get QR code for pairing |\n| GET | `/sessions/{id}/events` | SSE stream of session events |\n\n### Session Status Values\n\nSessions progress through these states: `stopped` -> `starting` -> `qr_code` -> `working` -> `failed`\n\n### Create Session\n\n**POST** `/sessions`\n\n```json\n{\n  \"name\": \"My WhatsApp\"\n}\n```\n\n**Response** `201 Created`:\n\n```json\n{\n  \"id\": \"a1b2c3d4-...\",\n  \"name\": \"My WhatsApp\",\n  \"status\": \"stopped\",\n  \"phone_number\": null,\n  \"is_business\": false,\n  \"created_at\": \"2026-02-11T10:00:00Z\"\n}\n```\n\n### Start Session and Get QR\n\nAfter creating a session, start it and retrieve the QR code:\n\n1. `POST /sessions/{id}/start` -- begins the WAHA engine\n2. Wait for status to become `qr_code` (use SSE events or poll)\n3. `GET /sessions/{id}/qr` -- returns the QR code image\n\n### SSE Events\n\n`GET /sessions/{id}/events?token=<jwt>` returns a Server-Sent Events stream. Events include session status changes, incoming messages, and connection updates.\n\n### Session Settings\n\n**PATCH** `/sessions/{id}/settings`\n\nConfigure per-session behavior. Settings are stored in the session's `config` JSON field.\n\n```json\n// Request\n{\n  \"auto_transcribe\": true\n}\n\n// Response\n{\n  \"status\": \"ok\",\n  \"config\": {\n    \"auto_transcribe\": true\n  }\n}\n```\n\n| Field | Type | Description |\n|-------|------|-------------|\n| `auto_transcribe` | boolean | Automatically transcribe incoming voice messages |\n\n---\n\n## Messages\n\nSend and retrieve WhatsApp messages through connected sessions.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| POST | `/messages/send` | Send a text message |\n| POST | `/messages/send/poll` | Send a poll message |\n| POST | `/messages/send/sticker` | Send a sticker |\n| POST | `/messages/send/gif` | Send a GIF |\n| GET | `/messages/chats/{session_id}` | List all chats for a session |\n| GET | `/messages/chat/{session_id}/{chat_id}` | Get chat messages |\n| GET | `/messages/{message_id}` | Get a single message |\n\n### Send Text Message\n\n**POST** `/messages/send`\n\n```json\n{\n  \"session_id\": \"a1b2c3d4-...\",\n  \"chat_id\": \"5511999999999@c.us\",\n  \"message\": \"Hello from MoltFlow!\"\n}\n```\n\n**Response** `201 Created`:\n\n```json\n{\n  \"id\": \"msg-uuid-...\",\n  \"chat_id\": \"chat-uuid-...\",\n  \"wa_message_id\": \"ABCD1234\",\n  \"direction\": \"outbound\",\n  \"message_type\": \"text\",\n  \"content_preview\": \"Hello from MoltFlow!\",\n  \"status\": \"sent\",\n  \"sent_at\": \"2026-02-11T10:05:00Z\",\n  \"created_at\": \"2026-02-11T10:05:00Z\"\n}\n```\n\n### Chat ID Format\n\n- Individual contacts: `<phone>@c.us` (e.g., `5511999999999@c.us`)\n- Groups: `<group_id>@g.us` (e.g., `120363012345678901@g.us`)\n\n### Send Poll\n\n**POST** `/messages/send/poll`\n\n```json\n{\n  \"session_id\": \"a1b2c3d4-...\",\n  \"chat_id\": \"5511999999999@c.us\",\n  \"title\": \"Preferred meeting time?\",\n  \"options\": [\"Morning\", \"Afternoon\", \"Evening\"],\n  \"allow_multiple\": false\n}\n```\n\n---\n\n## Groups\n\nMonitor WhatsApp groups for keywords, messages, and activity.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/groups` | List monitored groups |\n| GET | `/groups/available/{session_id}` | List available WA groups |\n| POST | `/groups` | Add group to monitoring |\n| GET | `/groups/{id}` | Get monitored group details |\n| PATCH | `/groups/{id}` | Update monitoring settings |\n| DELETE | `/groups/{id}` | Remove from monitoring |\n| POST | `/groups/create` | Create a new WA group |\n| POST | `/groups/{wa_group_id}/participants/add` | Add participants |\n| POST | `/groups/{wa_group_id}/participants/remove` | Remove participants |\n| POST | `/groups/{wa_group_id}/admin/promote` | Promote to admin |\n| POST | `/groups/{wa_group_id}/admin/demote` | Demote from admin |\n\n### Add Group to Monitoring\n\n**POST** `/groups`\n\n```json\n{\n  \"session_id\": \"a1b2c3d4-...\",\n  \"wa_group_id\": \"120363012345678901@g.us\",\n  \"monitor_mode\": \"keywords\",\n  \"monitor_keywords\": [\"urgent\", \"support\", \"help\"]\n}\n```\n\n### Monitor Modes\n\n- `all` -- Capture every message in the group\n- `keywords` -- Only capture messages matching specified keywords\n- `mentions` -- Only when your account is mentioned\n- `first_message` -- Only first messages from new users (default for new groups)\n- `ai_analysis` -- AI-powered intent classification and lead scoring (Pro+ only)\n\n### Group Messages (AI Intelligence)\n\n**GET** `/groups/{group_id}/messages`\n\nRetrieve paginated messages from a monitored group, including AI analysis results.\n\nQuery parameters: `limit` (default 50, max 100), `offset` (default 0)\n\n**Requires scope:** `groups:read`\n\n```json\n{\n  \"items\": [\n    {\n      \"id\": \"msg-uuid\",\n      \"sender_phone\": \"+15550123456\",\n      \"sender_name\": \"John D.\",\n      \"content_preview\": \"I'm interested in the 3BR property\",\n      \"wa_timestamp\": \"2026-02-20T14:30:00Z\",\n      \"ai_analysis\": {\n        \"intent\": \"buying_intent\",\n        \"lead_score\": 9,\n        \"confidence\": 0.92,\n        \"reason\": \"Explicit interest in a specific property with buying signal\"\n      }\n    }\n  ],\n  \"total\": 142,\n  \"limit\": 50,\n  \"offset\": 0,\n  \"has_more\": true\n}\n```\n\n`ai_analysis` is null when AI hasn't processed the message or AI monitoring is not enabled.\n\n### MCP Tool: moltflow_get_group_messages\n\nRetrieve messages from a monitored WhatsApp group via Claude or any MCP client.\n\n**Args:**\n- `group_id` (required): UUID of the monitored group\n- `limit` (optional): Max messages 1-100 (default: 50)\n- `offset` (optional): Skip count for pagination (default: 0)\n- `response_format` (optional): `\"markdown\"` or `\"json\"`\n\n**Returns:** Paginated list of messages with sender info, content preview, timestamp, and `ai_analysis` (intent, lead_score, confidence, reason) when AI has processed the message.\n\n**Requires scope:** `groups:read`\n\n---\n\n## Labels\n\nOrganize contacts and chats with color-coded labels. Supports sync with WhatsApp Business native labels.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/labels` | List all labels |\n| POST | `/labels` | Create a label |\n| GET | `/labels/{id}` | Get label details |\n| PATCH | `/labels/{id}` | Update a label |\n| DELETE | `/labels/{id}` | Delete a label |\n| POST | `/labels/{id}/sync` | Sync label to WhatsApp |\n| POST | `/labels/sync-from-whatsapp` | Import labels from WA |\n| GET | `/labels/business-check` | Check WA Business status |\n| GET | `/labels/{id}/chats` | List chats with this label |\n| GET | `/labels/chat/{chat_id}` | Get labels for a chat |\n| PUT | `/labels/chat/{chat_id}` | Set labels for a chat |\n\n### Create Label\n\n**POST** `/labels`\n\n```json\n{\n  \"name\": \"VIP Customer\",\n  \"color\": \"#FF6B35\",\n  \"description\": \"High-value accounts\"\n}\n```\n\n**Response** `201 Created`:\n\n```json\n{\n  \"id\": \"label-uuid-...\",\n  \"name\": \"VIP Customer\",\n  \"color\": \"#FF6B35\",\n  \"description\": \"High-value accounts\",\n  \"chat_count\": 0,\n  \"synced\": false,\n  \"created_at\": \"2026-02-11T10:00:00Z\"\n}\n```\n\n> **Note:** Syncing labels to WhatsApp requires a WhatsApp Business account. Use `GET /labels/business-check` to verify.\n\n---\n\n## Webhooks\n\nReceive real-time notifications when events occur in your WhatsApp sessions.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/webhooks` | List all webhooks |\n| POST | `/webhooks` | Create a webhook |\n| GET | `/webhooks/{id}` | Get webhook details |\n| PATCH | `/webhooks/{id}` | Update a webhook |\n| DELETE | `/webhooks/{id}` | Delete a webhook |\n| POST | `/webhooks/{id}/test` | Send a test delivery |\n\n### Supported Events\n\n| Event | Description |\n|-------|-------------|\n| `message.received` | Inbound message received |\n| `message.sent` | Outbound message sent |\n| `session.connected` | Session connected to WhatsApp |\n| `session.disconnected` | Session disconnected |\n| `lead.detected` | New lead detected (includes `ai_analysis` when available) |\n| `group.message` | Message in a monitored group |\n| `group.message.analyzed` | AI analysis completed for a group message (Pro/Business only) |\n\n### Create Webhook\n\n**POST** `/webhooks`\n\n> **Security:** Webhook URLs are validated server-side — private IPs, cloud metadata endpoints, and non-HTTPS schemes are blocked. Only configure endpoints you control. Always set a `secret` for HMAC signature verification.\n\n```json\n{\n  \"name\": \"CRM Integration\",\n  \"url\": \"https://example.com/webhooks/moltflow\",\n  \"events\": [\"message.received\", \"lead.detected\"],\n  \"secret\": \"whsec_mysecretkey123\"\n}\n```\n\n**Response** `201 Created`:\n\n```json\n{\n  \"id\": \"wh-uuid-...\",\n  \"name\": \"CRM Integration\",\n  \"url\": \"https://example.com/webhooks/moltflow\",\n  \"events\": [\"message.received\", \"lead.detected\"],\n  \"is_active\": true,\n  \"created_at\": \"2026-02-11T10:00:00Z\"\n}\n```\n\n### Webhook Payload\n\nDeliveries include an HMAC-SHA256 signature in the `X-Webhook-Signature` header (if a secret is configured). Verify this to ensure authenticity.\n\n```json\n{\n  \"event\": \"message.received\",\n  \"timestamp\": \"2026-02-11T10:05:00Z\",\n  \"data\": {\n    \"session_id\": \"a1b2c3d4-...\",\n    \"chat_id\": \"5511999999999@c.us\",\n    \"message\": \"Hello!\",\n    \"direction\": \"inbound\"\n  }\n}\n```\n\n---\n\n## Examples\n\n### Full workflow: Create session and send first message\n\n```bash\n# 1. Create a session\ncurl -X POST https://apiv2.waiflow.app/api/v2/sessions \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"name\": \"Sales Team\"}'\n\n# 2. Start the session (triggers QR)\ncurl -X POST https://apiv2.waiflow.app/api/v2/sessions/{session_id}/start \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\"\n\n# 3. Get QR code (scan with WhatsApp)\ncurl https://apiv2.waiflow.app/api/v2/sessions/{session_id}/qr \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\"\n\n# 4. Send a message (after session status is \"working\")\ncurl -X POST https://apiv2.waiflow.app/api/v2/messages/send \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"session_id\": \"{session_id}\",\n    \"chat_id\": \"5511999999999@c.us\",\n    \"message\": \"Hello from MoltFlow!\"\n  }'\n```\n\n### Set up a webhook for incoming messages\n\n```bash\ncurl -X POST https://apiv2.waiflow.app/api/v2/webhooks \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"name\": \"Incoming Messages\",\n    \"url\": \"https://myapp.com/webhooks/whatsapp\",\n    \"events\": [\"message.received\", \"session.connected\"],\n    \"secret\": \"whsec_my_secret\"\n  }'\n```\n\n### Monitor a group for keywords\n\n```bash\n# List available groups from a connected session\ncurl https://apiv2.waiflow.app/api/v2/groups/available/{session_id} \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\"\n\n# Add a group to monitoring\ncurl -X POST https://apiv2.waiflow.app/api/v2/groups \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"session_id\": \"{session_id}\",\n    \"wa_group_id\": \"120363012345678901@g.us\",\n    \"monitor_mode\": \"keywords\",\n    \"monitor_keywords\": [\"urgent\", \"support\"]\n  }'\n```\n\n---\n\n## Error Responses\n\nAll endpoints return standard error responses:\n\n```json\n{\n  \"detail\": \"Session not found\"\n}\n```\n\n| Status | Meaning |\n|--------|---------|\n| 400 | Bad request (invalid input) |\n| 401 | Unauthorized (missing or invalid auth) |\n| 403 | Forbidden (plan limit or permission) |\n| 404 | Resource not found |\n| 429 | Rate limited |\n| 500 | Internal server error |\n\n---\n\n## Rate Limits\n\nAPI requests are rate-limited per tenant. Limits vary by plan:\n\n| Plan | Requests/min |\n|------|-------------|\n| Free | 10 |\n| Starter | 20 |\n| Pro | 40 |\n| Business | 60 |\n\nRate limit headers are included in every response: `X-RateLimit-Remaining`, `X-RateLimit-Reset`.\n\n---\n\n## Related Skills\n\n- **moltflow-outreach** -- Bulk Send, Scheduled Messages, Custom Groups\n- **moltflow-leads** -- Lead detection, pipeline tracking, bulk operations, CSV/JSON export\n- **moltflow-ai** -- AI-powered auto-replies, voice transcription, RAG knowledge base, style profiles\n- **moltflow-a2a** -- Agent-to-Agent protocol, encrypted messaging, content policy\n- **moltflow-reviews** -- Review collection and testimonial management\n- **moltflow-admin** -- Platform administration, user management, plan configuration\n\nFile v2.15.1:SKILL.md\n\n---\nname: \"WhatsApp Ultimate — No Meta API | Lead Mining, Bulk Send, Scheduled Reminders & Follow-ups\"\nversion: \"2.15.1\"\ndescription: \"Documentation-only WhatsApp API reference — zero executables, zero install scripts, zero local file writes. All actions require explicit user invocation. Provides 90+ API endpoints for sending messages, capturing leads, running campaigns, scheduling reports, tracking campaign analytics, and managing clients. MOLTFLOW_API_KEY is the only credential required — generate a scoped key from the MoltFlow dashboard (Settings > API Keys). AI features (voice transcription, RAG, style profiles) use the user's own LLM API key configured via the MoltFlow web dashboard, never passed through this skill.\"\nsource: \"MoltFlow Team\"\nrisk: safe\nhomepage: \"https://molt.waiflow.app\"\nrequiredEnv:\n  - MOLTFLOW_API_KEY\nprimaryEnv: MOLTFLOW_API_KEY\ndisable-model-invocation: true\nmetadata: {\"openclaw\":{\"emoji\":\"📱\",\"homepage\":\"https://molt.waiflow.app\",\"requires\":{\"env\":[\"MOLTFLOW_API_KEY\"]},\"primaryEnv\":\"MOLTFLOW_API_KEY\"}}\n---\n\n# WhatsApp Automation — Analyze Groups for Buying Signals\n\n**Thousands of hidden leads are sitting in your WhatsApp groups right now.** Every group participant who isn't in your contacts is a potential client. MoltFlow analyzes your groups on demand, surfaces untapped contacts, and lets Claude run AI-powered outreach campaigns on your behalf.\n\n**One skill. 90+ endpoints. Zero manual prospecting.**\n\n> **Account Health & Growth Reports**: Run a read-only\n> account scan to find unanswered contacts, detect\n> buying signals in group conversations, spot high-value\n> groups you're not monitoring, and build targeted lead\n> lists. All analysis runs on-demand when you ask —\n> nothing happens in the background. No data is modified.\n>\n> **Native MCP Endpoint + Custom GPT Actions**: Works with Claude Desktop, Claude.ai, Claude Code, and ChatGPT (Custom GPT Actions). 25 tools via native HTTP endpoint at `apiv2.waiflow.app/mcp` -- no npm packages or Node.js required. See [integrations.md](integrations.md) for setup.\n\n> ***Due to high demand and a recent registration issue, we're offering our top-tier Business plan with unlimited quotas for just $19.90/month on yearly billing — for a limited time only.*** [**Claim the deal**](https://buy.stripe.com/cNifZibX7gpQebJ0nsfnO00)\n>\n> Free tier available. [Sign up](https://molt.waiflow.app/checkout?plan=free)\n\n---\n\n## Just Ask Claude\n\nInstall the skill, set your API key, and tell Claude what you need:\n\n**\"Send a payment reminder to all clients with outstanding invoices on the 28th of each month\"**\n\nCreates a custom group, schedules a recurring message with cron, timezone-aware delivery.\n\n**\"Transcribe patient voice notes and save them as appointment summaries\"**\n\nWhisper transcription on incoming voice messages, retrievable via API.\n\n**\"Alert me when someone mentions 'budget', 'bedroom', or 'viewing' in my property groups\"**\n\nKeyword monitoring on WhatsApp groups, auto-creates leads in your pipeline.\n\n**\"Analyze the last 50 messages in my real estate group and score every lead\"**\n\nAI Group Intelligence classifies message intent (buying_intent, inquiry, complaint), scores leads 1-10, and surfaces high-priority contacts. Requires Pro plan + your LLM API key.\n\n**\"Set up automatic order confirmation messages after every purchase\"**\n\nWebhook listener for purchase events, triggers outbound message via API.\n\n**\"Collect customer reviews after every reservation and export the best ones\"**\n\nSentiment-scored review collection, auto-approve positives, export as HTML for your website.\n\n**\"Send a weekly campaign performance report to my team's WhatsApp group every Monday\"**\n\nScheduled report with WhatsApp delivery, 10 templates including campaign analytics.\n\n**\"Schedule follow-up messages to leads who haven't replied in 3 days\"**\n\nScheduled messages to custom groups, built from lead pipeline filters.\n\n**\"Broadcast class schedule changes to all parent groups\"**\n\nBulk send to custom groups with ban-safe throttling and delivery tracking.\n\n**\"Auto-respond to support questions using my knowledge base docs\"**\n\nRAG-powered AI replies grounded in your uploaded PDFs and docs.\n\n**\"Move leads from 'new' to 'contacted' after I message them, and track conversion rate\"**\n\nCRM pipeline with state machine, bulk status updates, CSV export.\n\n**\"Export all data for a customer who requested GDPR erasure\"**\n\nGDPR-compliant data export and contact erasure via API.\n\n**\"Show me which campaigns had the best read rates this week\"**\n\nCampaign analytics with delivery funnel, per-contact status, and engagement scores.\n\n---\n\n## Code Samples\n\n### Get campaign analytics — delivery rates, funnel, timing\n\n```bash\ncurl -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  \"https://apiv2.waiflow.app/api/v2/analytics/campaigns/{job_id}\"\n```\n\nReturns delivery rate, failure breakdown, messages per minute,\nand full per-contact delivery status.\n\n### Track delivery in real-time (SSE)\n\n```bash\ncurl -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  \"https://apiv2.waiflow.app/api/v2/bulk-send/{id}/progress\"\n```\n\nServer-Sent Events stream: sent/failed/pending counts\nupdate live as each message delivers.\n\n### Top contacts by engagement score\n\n```bash\ncurl -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  \"https://apiv2.waiflow.app/api/v2/analytics/contacts?sort=engagement_score&limit=50\"\n```\n\nRanked by messages sent, received, reply rate, and\nrecency — find your most engaged contacts instantly.\n\n### Bulk broadcast to a contact group\n\n```bash\ncurl -X POST -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"custom_group_id\": \"group-uuid\",\n    \"session_id\": \"uuid\",\n    \"message\": \"Weekly update...\"\n  }' \\\n  https://apiv2.waiflow.app/api/v2/bulk-send\n```\n\n### Monitor a group for buying signals\n\n```bash\ncurl -X POST -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"session_id\": \"uuid\",\n    \"wa_group_id\": \"120363012345@g.us\",\n    \"monitor_mode\": \"keywords\",\n    \"monitor_keywords\": [\"looking for\", \"need help\", \"budget\", \"price\"]\n  }' \\\n  https://apiv2.waiflow.app/api/v2/groups\n```\n\n### List new leads in your pipeline\n\n```bash\ncurl -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  \"https://apiv2.waiflow.app/api/v2/leads?status=new&limit=50\"\n```\n\n### Move a lead through the pipeline\n\n```bash\ncurl -X PATCH -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"status\": \"qualified\"}' \\\n  https://apiv2.waiflow.app/api/v2/leads/{lead_id}/status\n```\n\nStatus flow: `new` → `contacted` → `qualified` → `converted`\n(or `lost` at any stage).\n\n### Bulk add leads to a campaign group\n\n```bash\ncurl -X POST -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"lead_ids\": [\"uuid-1\", \"uuid-2\", \"uuid-3\"],\n    \"custom_group_id\": \"target-group-uuid\"\n  }' \\\n  https://apiv2.waiflow.app/api/v2/leads/bulk/add-to-group\n```\n\n### Export leads as CSV\n\n```bash\ncurl -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  \"https://apiv2.waiflow.app/api/v2/leads/export/csv?status=qualified\" \\\n  -o qualified-leads.csv\n```\n\n### Pause a running campaign\n\n```bash\ncurl -X POST -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  https://apiv2.waiflow.app/api/v2/bulk-send/{job_id}/pause\n```\n\n### AI reply in your writing style + knowledge base\n\n```bash\ncurl -X POST -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"contact_id\": \"5511999999999@c.us\",\n    \"context\": \"Customer asks: What is your return policy?\",\n    \"use_rag\": true,\n    \"apply_style\": true\n  }' \\\n  https://apiv2.waiflow.app/api/v2/ai/generate-reply\n```\n\n### Schedule a weekly follow-up\n\n```bash\ncurl -X POST -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"name\": \"Monday check-in\",\n    \"session_id\": \"uuid\",\n    \"chat_id\": \"123@c.us\",\n    \"message\": \"Hey! Anything I can help with this week?\",\n    \"recurrence\": \"weekly\",\n    \"scheduled_time\": \"2026-03-03T09:00:00\",\n    \"timezone\": \"America/New_York\"\n  }' \\\n  https://apiv2.waiflow.app/api/v2/scheduled-messages\n```\n\n### Weekly report delivered to your WhatsApp\n\n```bash\ncurl -X POST -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"name\": \"Weekly Lead Pipeline\",\n    \"template_id\": \"lead_pipeline\",\n    \"schedule_type\": \"weekly\",\n    \"cron_expression\": \"0 9 * * MON\",\n    \"timezone\": \"America/New_York\",\n    \"delivery_method\": \"whatsapp\"\n  }' \\\n  https://apiv2.waiflow.app/api/v2/reports\n```\n\n### Send a message\n\n```bash\ncurl -X POST -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"session_id\": \"uuid\",\n    \"chat_id\": \"1234567890@c.us\",\n    \"message\": \"Hello!\"\n  }' \\\n  https://apiv2.waiflow.app/api/v2/messages/send\n```\n\n### Collect customer reviews automatically\n\n```bash\ncurl -X POST -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"name\": \"Happy Customers\",\n    \"session_id\": \"uuid\",\n    \"source_type\": \"all\",\n    \"min_sentiment_score\": 0.7,\n    \"include_keywords\": [\"thank\", \"recommend\", \"love\", \"amazing\"]\n  }' \\\n  https://apiv2.waiflow.app/api/v2/reviews/collectors\n```\n\n### Discover A2A agents\n\n```bash\ncurl https://apiv2.waiflow.app/.well-known/agent.json\n```\n\nFull API reference: see each module's SKILL.md.\n\n---\n\n## ERC-8004 Agent Registration\n\nMoltFlow is a verified on-chain AI agent registered on **Ethereum mainnet**.\n\n| Field | Value |\n|-------|-------|\n| Agent ID | [#25477](https://8004agents.ai/ethereum/agent/25477) |\n| Chain | Ethereum mainnet (eip155:1) |\n| Registry | `0x8004A169FB4a3325136EB29fA0ceB6D2e539a432` |\n| Trust Model | Reputation-based |\n| Endpoints | A2A + MCP + Web |\n\n**Discovery:**\n- Agent card: `https://molt.waiflow.app/.well-known/erc8004-agent.json`\n- A2A discovery: `https://apiv2.waiflow.app/.well-known/agent.json`\n\n---\n\n## Use Cases\n\n**Solo Founder / Small Biz**\n- Find unanswered leads in your chats\n- AI replies in your writing style\n- Scheduled promos to custom groups\n\n**Agency / Multi-Client**\n- Monitor 50+ groups across 10 sessions\n- Bulk send with ban-safe delays\n- Export leads as CSV, push to n8n/Zapier\n\n**Marketing Agency / Campaign Manager**\n- Capture leads from click-to-WhatsApp ad campaigns\n- Auto-qualify inbound leads with keyword detection + AI scoring\n- Bulk follow-up sequences with ban-safe throttling\n- Multi-session management across client accounts\n- Export campaign leads to CRM via webhooks or CSV\n\n**Developer / AI Agent Builder**\n- 90+ REST endpoints, scoped API keys\n- A2A protocol with E2E encryption\n- Python SDK: `pip install moltflow` ([GitHub](https://github.com/moltflow/moltflow-python))\n\n### Guides & Tutorials\n\n**AI Integration Guides:**\n- [Connect ChatGPT to MoltFlow](https://molt.waiflow.app/guides/connect-chatgpt-to-moltflow) — Custom GPT Actions, 10 min setup\n- [Connect Claude to MoltFlow](https://molt.waiflow.app/guides/connect-claude-to-moltflow) — MCP Server setup, 5 min\n- [Connect OpenClaw to MoltFlow](https://molt.waiflow.app/guides/connect-openclaw-to-moltflow) — Native AI config, 5 min setup\n\n**How-To Guides:**\n- [Getting Started](https://molt.waiflow.app/blog/whatsapp-automation-getting-started)\n- [API Complete Guide](https://molt.waiflow.app/blog/moltflow-api-complete-guide)\n- [n8n Integration](https://molt.waiflow.app/blog/moltflow-n8n-whatsapp-automation)\n- [n8n + Google Sheets](https://molt.waiflow.app/blog/n8n-whatsapp-google-sheets)\n- [n8n Group Auto-Reply](https://molt.waiflow.app/blog/n8n-whatsapp-group-auto-reply)\n- [n8n Lead Pipeline](https://molt.waiflow.app/blog/n8n-whatsapp-lead-pipeline)\n- [n8n Multi-Model AI](https://molt.waiflow.app/blog/n8n-multi-model-ai-orchestration)\n- [AI Auto-Replies Setup](https://molt.waiflow.app/blog/ai-auto-replies-whatsapp-setup)\n- [Group Lead Generation](https://molt.waiflow.app/blog/whatsapp-group-lead-generation-guide)\n- [Customer Support](https://molt.waiflow.app/blog/openclaw-whatsapp-customer-support)\n- [RAG Knowledge Base](https://molt.waiflow.app/blog/rag-knowledge-base-deep-dive)\n- [Style Matching](https://molt.waiflow.app/blog/ai-auto-replies-whatsapp-setup#style-profiles)\n- [Lead Scoring](https://molt.waiflow.app/blog/whatsapp-lead-scoring-automation)\n- [Feedback Collection](https://molt.waiflow.app/blog/whatsapp-customer-feedback-collection)\n- [A2A Protocol](https://molt.waiflow.app/blog/a2a-protocol-agent-communication)\n- [Scaling ROI](https://molt.waiflow.app/blog/scaling-whatsapp-automation-roi)\n\n[All guides →](https://molt.waiflow.app/guides)\n\n---\n\n## Platform Features\n\n| Feature | Details |\n|---|---|\n| Messaging | Text, media, polls, vCards |\n| Bulk Send | Ban-safe, SSE progress |\n| Scheduled | Cron, timezone-aware |\n| Reports | 10 templates, cron, WhatsApp delivery |\n| Analytics | Campaign funnel, contact scores, send time optimization |\n| Groups | Custom lists, CSV export |\n| Leads/CRM | Detect signals, pipeline |\n| Monitoring | 50+ groups, keywords |\n| Labels | Sync to WA Business |\n| AI Group Intel | Intent classification, lead scoring (Pro+) |\n| AI Replies | GPT-4/Claude, RAG |\n| Style Clone | Matches your writing tone |\n| RAG | PDF/TXT, semantic search |\n| Voice | Whisper transcription |\n| Reviews | Sentiment, auto-approve |\n| Anti-Spam | Rate limits, typing sim |\n| Safeguards | Block PII, injections |\n| Webhooks | HMAC signed, 10+ events |\n| A2A | E2E encrypted, JSON-RPC |\n| GDPR | Auto-expiry, compliance |\n| Delivery | Real-time SSE tracking, read/reply/ignored status |\n\n---\n\n## How MoltFlow Compares\n\n| | Molt | Alt 1 | Alt 2 | Alt 3 |\n|---|:---:|:---:|:---:|:---:|\n| Messaging | 18 | 14 | 3 | 1 |\n| Groups | 8 | 4 | 0 | 0 |\n| Outreach | 7 | 0 | 0 | 0 |\n| CRM | 7 | 0 | 0 | 0 |\n| AI | 7 | 0 | 0 | 0 |\n| Reviews | 8 | 0 | 0 | 0 |\n| Security | 10 | 0 | 0 | 0 |\n| Platform | 8 | 0 | 0 | 0 |\n| **Total** | **90+** | **~15** | **~3** | **~1** |\n\n---\n\n## What This Skill Reads, Writes & Never Does\n\n**Documentation and API reference.** Nothing is\nauto-installed or auto-executed. No scripts or\nexecutables are bundled in this package.\nAll actions require user confirmation.\n\n| Category | What happens | Requires opt-in? |\n|---|---|---|\n| API calls | HTTPS to `apiv2.waiflow.app` only | No (uses your scoped API key) |\n| Contact metadata | Contact names, timestamps, counts | No |\n| CRM pipeline | Lead status, engagement scores | No |\n| AI features | Statistical patterns via API | Yes (AI consent toggle) |\n| Local file | `.moltflow.json` — counts only, no PII | No |\n| API key | Local env var, never logged or shared | No |\n\n**This skill never:**\n- Installs packages or runs code automatically\n- Sends messages without explicit user confirmation\n- Sends to non-whitelisted numbers (if configured)\n- Bypasses anti-spam or content safeguards\n- Shares data with third parties\n- Stores credentials in files (env vars only)\n\n---\n\n## Setup\n\n> **Free tier available** — 1 session,\n> 50 messages/month, no credit card required.\n\n**Env vars:**\n- `MOLTFLOW_API_KEY` (required) — create a\n  minimum-scoped key from\n  [your dashboard](https://molt.waiflow.app).\n  Use the narrowest scope preset that covers\n  your workflow. Rotate keys regularly.\n- `MOLTFLOW_API_URL` (optional) — defaults\n  to `https://apiv2.waiflow.app`\n\n**Authentication:**\n`X-API-Key: $MOLTFLOW_API_KEY` header\nor `Authorization: Bearer $TOKEN` (JWT).\n\n**Base URL:** `https://apiv2.waiflow.app/api/v2`\n\n---\n\n## Security\n\n- **Minimum-scoped API keys enforced** — `scopes` is\n  a required field when creating keys. Always create\n  the narrowest key possible (e.g., `messages:send`\n  only). Use presets like \"Messaging\" or \"Read Only\"\n  for common workflows. Never use full-scope keys\n  with AI agents — create a dedicated, limited key.\n- **Use environment variables for keys** — set\n  `MOLTFLOW_API_KEY` as an env var, not in\n  shared config files. Rotate keys regularly.\n- **Phone whitelisting** — configure `allowed_numbers`\n  in tenant settings to restrict which numbers can\n  send outbound messages. Only whitelisted numbers\n  are permitted.\n- **Anti-spam safeguards** — all outbound messages\n  pass through reciprocity checks (contact must\n  message you first), burst rate limiting, typing\n  simulation, and random delays. Cannot be bypassed.\n- **Content safeguards** — outbound messages are\n  scanned for PII, secrets, and prompt injection\n  attempts. Blocked automatically before sending.\n- **Approval mode** — enable `require_approval` in\n  tenant settings to hold all AI-generated messages\n  for manual review before delivery.\n- **Webhook URL validation** — the API blocks\n  private IPs, cloud metadata, and non-HTTPS\n  schemes. Only configure endpoints you control.\n  Always set a `secret` for HMAC verification\n- **Verify third-party packages before running** —\n  if you follow the external setup guides to install\n  MCP or GPT integrations, review the package source\n  and maintainers first. This skill does not install\n  or execute any packages.\n- **Review scripts locally before running** — the\n  Python example scripts are hosted on GitHub, not\n  bundled. Download, inspect the source, then run.\n- **Avoid high-privilege keys in shared environments** —\n  for admin operations (key rotation, data export),\n  use the browser dashboard or a short-lived scoped\n  key. Never expose owner-level keys in shared shells.\n- **Test in a sandbox tenant first** — create a\n  short-lived, scoped key for testing. Revoke\n  after testing. Never share keys across tenants.\n\n---\n\n## AI Agent Integrations\n\n26 MCP tools for Claude Desktop, Claude.ai,\nClaude Code, and OpenAI Custom GPTs. Includes\n`moltflow_get_group_messages` for AI-powered\ngroup intelligence (retrieve messages with intent\nclassification, lead scoring, and confidence scores).\n\n**User Action Required** — each integration\nrequires manual setup by the user. No code\nis installed automatically by this skill.\n\nSee [integrations.md](integrations.md) for setup\nguides and security notes.\n\n---\n\n## Modules\n\nEach module has its own SKILL.md with endpoints\nand curl examples.\n\n- **moltflow** (Core) — sessions, messaging,\n  groups, labels, webhooks\n- **moltflow-outreach** — bulk send,\n  scheduled messages, scheduled reports, custom groups\n- **moltflow-ai** — style cloning, RAG,\n  voice transcription, AI replies\n- **moltflow-leads** — lead detection,\n  CRM pipeline, bulk ops, export\n- **moltflow-a2a** — agent-to-agent protocol,\n  encrypted messaging\n- **moltflow-reviews** — review collection,\n  sentiment analysis, testimonial export\n- **moltflow-admin** — auth, API keys,\n  billing, usage tracking\n- **moltflow-onboarding** — read-only account\n  health check, growth opportunity reports\n\n---\n\n## Notes\n\n- Anti-spam on all messages (typing, random delays)\n- Sessions require QR code pairing on first connect\n- Use E.164 phone format without `+`\n- AI features and A2A require Pro plan or above\n- Rate limits: Free 10, Starter 20, Pro 40, Biz 60/min\n\n---\n\n## Changelog\n\n**v2.15.0** (2026-02-20) -- See [CHANGELOG.md](CHANGELOG.md) for full history.\n\n<!-- FILEMAP:BEGIN -->\n```text\n[moltflow file map]|root: .\n|.:{SKILL.md,CHANGELOG.md,integrations.md,package.json}\n|moltflow:{SKILL.md}\n|moltflow-ai:{SKILL.md}\n|moltflow-a2a:{SKILL.md}\n|moltflow-reviews:{SKILL.md}\n|moltflow-outreach:{SKILL.md}\n|moltflow-leads:{SKILL.md}\n|moltflow-admin:{SKILL.md}\n|moltflow-onboarding:{SKILL.md}\n```\n<!-- FILEMAP:END -->\n\nFile v2.15.1:_meta.json\n\n{\n  \"ownerId\": \"kn7a6d4f2zxd8y4pappvsvndrx805djq\",\n  \"slug\": \"moltflow-whatsapp\",\n  \"version\": \"2.15.1\",\n  \"publishedAt\": 1771757572476\n}\n\nFile v2.15.1:CHANGELOG.md\n\n# Changelog\r\n\r\nAll notable changes to the **MoltFlow Skills** package are documented here.\r\n\r\n---\r\n\r\n## [2.15.1] - 2026-02-22\r\n\r\n### Fixed\r\n- **OpenClaw \"Suspicious\" classification resolved** — `requiredEnv` now correctly declares `MOLTFLOW_API_KEY` (was empty `[]`, contradicting `primaryEnv`)\r\n- Removed `optionalEnv` field — LLM API key is configured via the MoltFlow web dashboard, never passed through this skill\r\n- Updated metadata JSON to match `requiredEnv` declaration\r\n- Clarified description: documentation-only package, zero executables, MOLTFLOW_API_KEY is the only credential\r\n- **MCP server endpoint fixes** — corrected 6 wrong API paths discovered during comprehensive testing:\r\n  - `list_monitored_groups`: `groups/monitored` → `groups`\r\n  - `add_monitored_group`: `groups/monitored` → `groups`\r\n  - `get_current_usage`: `usage` → `usage/current`\r\n  - `get_plan_limits`: `usage/limits` → `usage/current`\r\n  - `list_chats`: session_id moved from query param to path param\r\n  - `get_chat_messages`: corrected path and added missing session_id parameter\r\n- Synced all sub-skill versions to 2.15.1\r\n\r\n---\r\n\r\n## [2.15.0] - 2026-02-20\r\n\r\n### Added\r\n- New MCP tool `moltflow_get_group_messages`: retrieve paginated messages from a monitored WhatsApp group, including AI analysis results (intent, lead_score, confidence, reason) when AI monitoring is enabled\r\n- AI Group Intelligence support: messages returned by the tool include `ai_analysis` fields populated by the Phase 91 AI analysis pipeline\r\n- Documentation updates in SKILL.md, moltflow-leads/SKILL.md, and moltflow/SKILL.md reflecting the new tool and AI analysis fields\r\n\r\n---\r\n\r\n## v2.14.6 (2026-02-19)\r\n\r\n### Fixed\r\n- **Republished both ClawHub slugs** — legacy `whatsapp-automation-a2a` was showing \"Skill not found\"\r\n- **Restored correct display names** per v2.14.4 convention (no ERC-8004 in titles)\r\n\r\n---\r\n\r\n## v2.14.4 (2026-02-19)\r\n\r\n### Changed\r\n- **Updated both ClawHub display names** for better search discoverability\r\n  - `whatsapp-automation-a2a` — \"WhatsApp Automation — No Meta API | Bulk Send, Lead Mining, AI Outreach & Scheduled Campaigns\"\r\n  - `moltflow-whatsapp` — \"WhatsApp AI Agent — No Meta API | Lead Mining, Smart Replies, Bulk Campaigns & Scheduled Reports\"\r\n- Dropped MoltFlow/ERC-8004 from titles — unfamiliar to most users\r\n- Restored `whatsapp-automation-a2a` search visibility (was missing after v2.14.1)\r\n\r\n---\r\n\r\n## v2.14.1 (2026-02-19)\r\n\r\n### Fixed\r\n- **ClawHub \"suspicious\" classification resolved** — rewrote moltflow-onboarding from agent personality instructions to a read-only analysis tool\r\n- Removed \"BizDev Agent\" framing from onboarding skill and main SKILL.md description\r\n- Onboarding skill now explicitly read-only — all write endpoints moved to referenced skill modules\r\n- Removed inline Phase 4 write endpoints and Phase 5 settings configuration from onboarding\r\n- All safety guardrails preserved (disable-model-invocation, explicit user approval, scoped API keys)\r\n\r\n---\r\n\r\n## v2.14.0 (2026-02-18)\r\n\r\n### Changed\r\n- **Renamed skill** — \"WhatsApp Ultimate — No Meta API | Lead Mining, Bulk Send, Scheduled Reminders & Follow-ups\"\r\n- Highlights the key differentiator: no Meta Business API required\r\n\r\n---\r\n\r\n## v2.13.0 (2026-02-18)\r\n\r\n### Fixed\r\n- **17 production bugs** fixed across API, MCP server, frontend, and workers\r\n- WAHA HMAC signature verification now uses raw bytes (was re-serializing, never matched)\r\n- Checkout 202 response no longer corrupts auth tokens\r\n- A2A import crash on fresh Docker builds (missing source file)\r\n- Bulk send distributed lock prevents duplicate message delivery\r\n- MCP sanitizer boundary marker escape prevents prompt injection breakout\r\n- Login rate limit atomic pipeline prevents permanent user lockout\r\n- Admin suspend user now persists to DB (was hardcoded property)\r\n- ORM decrypted fields no longer risk plaintext flush to encrypted columns\r\n- Stripe webhook construct_event wrapped in asyncio.to_thread\r\n- Timezone-aware datetime mismatches on timezone-naive columns\r\n\r\n### Changed\r\n- API version bumped to v2.0.0\r\n- MCP server version bumped to v2.0.0\r\n- OpenAI Actions version bumped to v2.0.0\r\n\r\n---\r\n\r\n## v2.12.3 (2026-02-17)\r\n\r\n### Added\r\n- **Business use case scenarios** across all sub-skills — real-world examples for healthcare, real estate, e-commerce, restaurants, agencies, and more\r\n- **12 vertical-specific prompts** in main SKILL.md \"Just Ask Claude\" section replacing generic examples\r\n- **GDPR + Analytics prompts** added to main skill showcase\r\n\r\n### Fixed\r\n- Replaced hardcoded scheduled message date with future date\r\n\r\n---\r\n\r\n## v2.12.0 (2026-02-17)\r\n\r\n### Changed\r\n- Cleaned up documentation wording for ClawHub review compliance\r\n- Removed internal implementation details from public API docs\r\n- Simplified data access descriptions across all sub-skills\r\n\r\n## v2.11.4 (2026-02-16)\r\n\r\n### Fixed\r\n- Fixed ERC-8004 explorer URLs to include `/ethereum/` path segment across all files\r\n\r\n## v2.11.3 (2026-02-15)\r\n\r\n### Fixed\r\n- Reverted Setup and Security sections to v2.10.2 wording for ClawHub review compatibility\r\n\r\n## v2.11.0 (2026-02-15)\r\n\r\n### Added\r\n- **ERC-8004 Agent Registration** — MoltFlow registered as Agent #25477 on Ethereum mainnet\r\n- ERC-8004 section in SKILL.md with registry details and discovery URLs\r\n- New keywords: `erc8004`, `ethereum-agent`, `on-chain-agent`\r\n\r\n---\r\n\r\n## v2.10.1 (2026-02-14)\r\n\r\n### Added\r\n- **New code samples** — CRM pipeline updates, bulk group operations, CSV export, campaign controls\r\n- **Delivery tracking** added to Platform Features table\r\n- **Comparison table** total updated to 90+ endpoints\r\n\r\n### Changed\r\n- Removed scripts section (scripts will move to dedicated repo)\r\n\r\n---\r\n\r\n## v2.9.8 (2026-02-14)\r\n\r\n### Changed\r\n- **Integrations.md cleaned up** — simplified to setup guide links and security notes only\r\n- **Changelog consolidated** — removed verbose patch-level entries\r\n\r\n### Security\r\n- **Documentation-only package** — zero executables, zero install scripts, zero local file writes\r\n- **Scoped API keys enforced** — all examples use minimum required scopes; wildcard keys never recommended\r\n- **Conversation context gated** — API returns HTTP 403 until tenant explicitly opts in at Settings > Account > Data Access\r\n- **High-privilege endpoints removed from skill docs** — only consumer-facing API endpoints documented; administrative operations available on website only\r\n- **Model invocation disabled** — `disable-model-invocation: true` prevents autonomous agent actions; all operations require explicit user invocation\r\n- **Anti-spam safeguards documented** — reciprocity checks, burst rate limits, and content safeguards apply to all outbound messages\r\n\r\n---\r\n\r\n## v2.9.7 (2026-02-14)\r\n\r\n### Changed\r\n- **Code samples reordered** — campaign analytics, real-time delivery tracking (SSE), and engagement leaderboard moved to top of main SKILL.md\r\n- **Admin skill streamlined** — focused on auth, API keys, billing, usage, and tenant settings\r\n- **Restored integrations.md** — clean version with setup guide links and security notes\r\n\r\n---\r\n\r\n## v2.9.0 (2026-02-14)\r\n\r\n### Added\r\n- Campaign analytics endpoints documentation (Pro+ plans)\r\n- Contact engagement scoring and leaderboard\r\n- Send time optimization heatmap\r\n- 3 new MCP tools for analytics\r\n\r\n### Changed\r\n- Display name updated for search discoverability\r\n- Documentation refined for security best practices\r\n- All marketing language clarified for accuracy\r\n- Package reduced to documentation-only (zero executables)\r\n\r\n---\r\n\r\n## v2.8.6 (2026-02-14)\r\n\r\n### Changed\r\n- **Least-privilege API keys** — `scopes` is now required when creating API keys; presets available (Messaging, Outreach, Read Only)\r\n- **403 errors include required scopes** — `X-Required-Scopes` header tells callers exactly which scopes they need\r\n\r\n---\r\n\r\n## v2.8.0 (2026-02-13)\r\n\r\n### Added\r\n- **Scheduled Reports** — 10 report templates with WhatsApp delivery support\r\n- Reports API (8 endpoints): templates, create, list, get, update, pause, resume, delete\r\n- `reports:read` and `reports:manage` scopes\r\n\r\n### Changed\r\n- Platform features table updated with reports\r\n- Outreach module now includes scheduled reports\r\n\r\n---\r\n\r\n## v2.7.0 (2026-02-13)\r\n\r\n### Changed\r\n- Documentation restructured for clarity — \"What This Skill Reads, Writes & Never Does\" section\r\n- Privacy documentation expanded with opt-in requirements and explicit \"never does\" list\r\n- Security section expanded — anti-spam safeguards, content safeguards, approval mode\r\n\r\n---\r\n\r\n## v2.4.0 (2026-02-13)\r\n\r\n### Added\r\n- **AI Agent Integrations** — setup guides for Claude Desktop, Claude.ai Web, Claude Code, and ChatGPT\r\n- Remote MCP gateway documentation (`apiv2.waiflow.app/mcp`)\r\n\r\n---\r\n\r\n## v2.0.0 (2026-02-12)\r\n\r\n### Highlights\r\n\r\n- **Scheduled Messages** — One-time, daily/weekly/monthly, or custom cron. Timezone-aware. Pause, resume, cancel. Full execution history.\r\n- **Bulk Messaging** — Broadcast to custom groups with ban-safe throttling. Real-time SSE progress. Pause/resume/cancel mid-flight.\r\n- **Custom Groups** — Build targeted contact lists from WhatsApp conversations. Import members, export CSV/JSON.\r\n- **Lead Management** — Leads with full pipeline tracking. Bulk operations, CSV/JSON export.\r\n- **Knowledge Base (RAG)** — Upload PDF/TXT, semantic search with embeddings. AI uses your docs for accurate answers.\r\n- **Voice Transcription** — Whisper-powered voice message transcription with async task queue.\r\n- **90+ API Endpoints** — Complete platform coverage across 6 modules.\r\n\r\n### Added\r\n\r\n- Scheduled Messages API (9 endpoints)\r\n- Bulk Send API (7 endpoints)\r\n- Custom Groups API (10 endpoints)\r\n- Leads API (8 endpoints)\r\n- Knowledge Base / RAG API (4 endpoints)\r\n- Voice Transcription API (3 endpoints)\r\n- Sub-skills: moltflow-outreach, moltflow-leads, moltflow-admin\r\n\r\n---\r\n\r\n## v1.6.0 (2026-02-11)\r\n\r\n### Highlights\r\n\r\n- **Anti-Spam Protection** — Reciprocity checks, burst rate limiting, and health monitoring on all outbound messages.\r\n- **Yearly Billing** — Lock in yearly pricing at $239.90/year.\r\n- **4 Focused Sub-Skills** — Core, AI, A2A, and Reviews modules.\r\n\r\n---\r\n\r\n## v1.0.0 (2026-02-06)\r\n\r\n### Highlights\r\n\r\n- **All-in-One WhatsApp API** — Sessions, messaging, groups, labels, webhooks, AI replies, reviews, and A2A unified under a single skill.\r\n- **Agent-to-Agent Protocol** — JSON-RPC 2.0 with end-to-end encryption.\r\n- **AI That Learns Your Voice** — Build style profiles from conversation context. Auto-replies sound like you.\r\n- Full API reference with curl examples across 6 modules.\r\n\r\n---\r\n\r\n*Built with care by the [MoltFlow](https://waiflow.app) team.*\n\nFile v2.15.1:integrations.md\n\n# AI Agent Integrations\r\n\r\n> **User Action Required.** Each integration below\r\n> requires manual setup outside this skill. This skill\r\n> does not install packages or run code.\r\n\r\nMoltFlow works as a tool provider for AI assistants.\r\nConnect your preferred AI platform to the MoltFlow API\r\nand manage WhatsApp directly from conversation.\r\n\r\n## Claude Desktop (Native MCP)\r\n\r\n25 MCP tools for sessions, messaging, groups, leads,\r\noutreach, usage, and analytics. No npm package or\r\nNode.js required -- connects directly to the MoltFlow\r\nAPI via Streamable HTTP.\r\n\r\n### Option A: OAuth (Recommended) -- No API Key Needed\r\n\r\nJust add the URL. You'll be prompted to sign in the\r\nfirst time you use a tool.\r\n\r\n**Add to `claude_desktop_config.json`:**\r\n\r\n```json\r\n{\r\n  \"mcpServers\": {\r\n    \"moltflow\": {\r\n      \"url\": \"https://apiv2.waiflow.app/mcp\"\r\n    }\r\n  }\r\n}\r\n```\r\n\r\nOn first use, Claude will prompt you to authorize.\r\nClick through to sign in (or create a free account)\r\nand approve access. That's it -- no API key to copy.\r\n\r\n### Option B: API Key (Manual)\r\n\r\nIf you prefer explicit key management:\r\n\r\n```json\r\n{\r\n  \"mcpServers\": {\r\n    \"moltflow\": {\r\n      \"url\": \"https://apiv2.waiflow.app/mcp\",\r\n      \"headers\": {\r\n        \"X-API-Key\": \"YOUR_API_KEY_HERE\"\r\n      }\r\n    }\r\n  }\r\n}\r\n```\r\n\r\n**Required scopes:** Use the minimum scopes for your\r\nworkflow: `sessions:read`, `messages:send`, `leads:read`,\r\n`custom-groups:read`, `usage:read`. Create a scoped key\r\nat Dashboard > Sessions > API Keys tab.\r\n\r\n**Setup guide:** [Connect Claude to MoltFlow](https://molt.waiflow.app/guides/connect-claude-to-moltflow)\r\n\r\n**Dashboard setup page:** [https://molt.waiflow.app/mcp](https://molt.waiflow.app/mcp)\r\n\r\n## Claude.ai Web (Remote MCP)\r\n\r\nNo installation required -- configure in Claude.ai under\r\nSettings > Integrations > MCP Servers:\r\n\r\n- **URL:** `https://apiv2.waiflow.app/mcp`\r\n\r\nOAuth handles authentication automatically. You'll be\r\nprompted to sign in when you first use a MoltFlow tool.\r\n\r\nAlternatively, use manual auth:\r\n- **Auth header:** `X-API-Key`\r\n- **Value:** Your scoped MoltFlow API key\r\n\r\nAll 25 tools are available immediately after configuration.\r\n\r\n**Setup guide:** [Connect Claude to MoltFlow](https://molt.waiflow.app/guides/connect-claude-to-moltflow)\r\n\r\n## Claude Code\r\n\r\nAdd MoltFlow as a remote MCP server:\r\n\r\n```bash\r\nclaude mcp add moltflow --transport http --url https://apiv2.waiflow.app/mcp\r\n```\r\n\r\nOAuth handles authentication automatically. On first\r\ntool use you'll be prompted to sign in via your browser.\r\n\r\nFor manual auth with an API key:\r\n\r\n```bash\r\nclaude mcp add moltflow --transport http --url https://apiv2.waiflow.app/mcp --header \"X-API-Key: YOUR_API_KEY_HERE\"\r\n```\r\n\r\nAll 25 tools are available after adding the server.\r\n\r\n**Setup guide:** [Connect Claude to MoltFlow](https://molt.waiflow.app/guides/connect-claude-to-moltflow)\r\n\r\n## ChatGPT (MCP Connector)\r\n\r\nAdd MoltFlow in ChatGPT settings under MCP Servers:\r\n\r\n- **URL:** `https://apiv2.waiflow.app/mcp`\r\n\r\nOAuth handles authentication. You'll sign in via your\r\nbrowser on first use.\r\n\r\n## OpenAI Custom GPTs\r\n\r\nImport the MoltFlow OpenAPI specification in GPT Builder\r\nto give your GPT access to messaging, sessions, leads,\r\nand outreach endpoints.\r\n\r\n**Setup guide:** [Connect ChatGPT to MoltFlow](https://molt.waiflow.app/guides/connect-chatgpt-to-moltflow)\r\n\r\nSet Authentication to \"API Key\" with header `X-API-Key`\r\nand paste your scoped MoltFlow API key.\r\n\r\n---\r\n\r\n## MCP Endpoint Details\r\n\r\n- **URL:** `https://apiv2.waiflow.app/mcp`\r\n- **Protocol:** MCP Streamable HTTP (2025-03-26)\r\n- **Auth:** OAuth 2.1 (automatic) or `X-API-Key` header (manual)\r\n- **OAuth discovery:** `https://apiv2.waiflow.app/.well-known/oauth-authorization-server`\r\n- **Tools:** 25 tools across 7 categories (Sessions, Messaging, Groups, Leads, Outreach, Usage, Analytics)\r\n\r\n---\r\n\r\n## Security Notes\r\n\r\n- **OAuth 2.1 with PKCE** -- the recommended auth method.\r\n  Uses S256 code challenge, no client secrets exposed.\r\n- **Scoped API keys** -- if using manual auth, create a\r\n  key with minimum required scopes at Dashboard >\r\n  Sessions > API Keys tab.\r\n- **Environment variables** -- store API keys as env vars,\r\n  not in shared config files. Rotate regularly.\r\n- **GDPR compliance** -- all data processing follows\r\n  GDPR guidelines with appropriate consent gates.\r\n\r\n---\r\n\r\n## A2A Discovery (ERC-8004)\r\n\r\nMoltFlow is registered as [Agent #25477](https://8004agents.ai/ethereum/agent/25477) on Ethereum mainnet.\r\n\r\nOther AI agents can discover MoltFlow through:\r\n\r\n- **On-chain**: Query ERC-8004 Identity Registry at `0x8004A169FB4a3325136EB29fA0ceB6D2e539a432`\r\n- **HTTP**: Fetch `https://apiv2.waiflow.app/.well-known/agent.json`\r\n- **Agent card**: `https://molt.waiflow.app/.well-known/erc8004-agent.json`\n\nArchive v2.15.0: 13 files, 49754 bytes\n\nFiles: CHANGELOG.md (9733b), integrations.md (4799b), moltflow-a2a/SKILL.md (12998b), moltflow-admin/SKILL.md (10162b), moltflow-ai/SKILL.md (13322b), moltflow-leads/SKILL.md (10290b), moltflow-onboarding/SKILL.md (6093b), moltflow-outreach/SKILL.md (17841b), moltflow-reviews/SKILL.md (8224b), moltflow/SKILL.md (15168b), package.json (1303b), SKILL.md (19584b), _meta.json (137b)\n\nFile v2.15.0:moltflow-a2a/SKILL.md\n\n---\nname: moltflow-a2a\ndescription: \"Agent-to-Agent protocol for MoltFlow: agent discovery, encrypted messaging, group management, content policy. Use when: a2a, agent card, agent message, encrypted, content policy, agent discovery.\"\nsource: \"MoltFlow Team\"\nversion: \"2.11.8\"\nrisk: safe\nrequiredEnv:\n  - MOLTFLOW_API_KEY\nprimaryEnv: MOLTFLOW_API_KEY\ndisable-model-invocation: true\n---\n\n> **MoltFlow** -- WhatsApp Business automation for teams. Connect, monitor, and automate WhatsApp at scale.\n> ***Due to high demand and a recent registration issue, we're offering our top-tier Business plan with unlimited quotas for just $19.90/month on yearly billing — for a limited time only.*** [**Claim the deal**](https://buy.stripe.com/cNifZibX7gpQebJ0nsfnO00)\n> Free tier available. [Sign up](https://molt.waiflow.app/checkout?plan=free)\n\n# MoltFlow A2A (Agent-to-Agent) Protocol\n\nEnables AI agents to communicate securely through MoltFlow using the A2A protocol. Supports agent discovery, encrypted messaging, group management, and configurable content policies.\n\n## When to Use\n\n- \"Discover an agent\" or \"get agent card\"\n- \"Send A2A message\" or \"agent-to-agent communication\"\n- \"Get encryption public key\" or \"rotate keys\"\n- \"Set content policy\" or \"configure content filter\"\n- \"Create agent group\" or \"invite agent to group\"\n- \"Test content against policy\" or \"check policy stats\"\n- \"Set up webhook via A2A\" or \"manage agent webhooks\"\n\n## Prerequisites\n\n1. **MOLTFLOW_API_KEY** -- Generate from the [MoltFlow Dashboard](https://molt.waiflow.app) under Settings > API Keys\n2. Base URL: `https://apiv2.waiflow.app/api/v2`\n3. Agent discovery endpoint: `https://apiv2.waiflow.app/.well-known/agent.json`\n4. Encryption keys are managed server-side -- external agents only need the API key\n\n## On-Chain Registration\n\nMoltFlow is registered as [Agent #25477](https://8004agents.ai/ethereum/agent/25477) on Ethereum mainnet via ERC-8004.\nAgent card: `https://molt.waiflow.app/.well-known/erc8004-agent.json`\n\n## Required API Key Scopes\n\n| Scope | Access |\n|-------|--------|\n| `a2a` | `read/manage` |\n\n## Authentication\n\nEvery request must include one of:\n\n```\nAuthorization: Bearer <jwt_token>\n```\n\nor\n\n```\nX-API-Key: <your_api_key>\n```\n\n---\n\n## Agent Discovery\n\nDiscover MoltFlow agent capabilities using the standard `.well-known` endpoint.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/.well-known/agent.json` | Agent card (capabilities, skills, public key) |\n\n### Agent Card\n\n**GET** `https://apiv2.waiflow.app/.well-known/agent.json`\n\n```json\n{\n  \"name\": \"MoltFlow\",\n  \"description\": \"WhatsApp Business automation agent\",\n  \"url\": \"https://apiv2.waiflow.app\",\n  \"version\": \"1.2.0\",\n  \"capabilities\": {\n    \"messaging\": true,\n    \"groups\": true,\n    \"encryption\": \"X25519-ECDH-AES-256-GCM\",\n    \"webhooks\": true\n  },\n  \"skills\": [\n    \"agent.message.send\",\n    \"agent.group.create\",\n    \"agent.group.invite\",\n    \"agent.group.list\",\n    \"group.getContext\",\n    \"webhook_manager\"\n  ],\n  \"public_key\": \"base64-encoded-X25519-public-key\"\n}\n```\n\n---\n\n## Encryption\n\nMoltFlow uses X25519 ECDH key exchange with AES-256-GCM encryption for A2A message confidentiality. Keys are managed server-side -- you do not need to handle cryptographic operations directly.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/agent/public-key` | Get platform X25519 public key |\n| GET | `/agent/peer/{tenant_id}/public-key` | Get a tenant's public key |\n| POST | `/agent/rotate-keys` | Rotate encryption keys |\n| GET | `/agent/capabilities` | Get encryption capabilities |\n| POST | `/agent/initialize` | Initialize encryption for tenant |\n| GET | `/agent/bootstrap` | Skill bootstrap info |\n\n### Get Public Key\n\n**GET** `/agent/public-key`\n\n```json\n{\"public_key\": \"base64-encoded-X25519-public-key\", \"algorithm\": \"X25519\", \"created_at\": \"2026-02-11T10:00:00Z\"}\n```\n\n**GET** `/agent/peer/{tenant_id}/public-key` -- Retrieve another tenant's public key for encrypted communication.\n\n### How Encryption Works\n\nEach tenant has an X25519 keypair generated on initialization. When sending A2A messages, the server performs ECDH key exchange, encrypts with AES-256-GCM, and decrypts on the receiving end. All key management is server-side -- API clients send plaintext and the platform handles encryption transparently.\n\n---\n\n## A2A JSON-RPC\n\nThe core A2A endpoint accepts JSON-RPC 2.0 requests. All agent-to-agent operations go through this single endpoint. Use the fully scoped URL from your webhook configuration.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| POST | `/a2a/{tenant_id}/{session_id}/{webhook_id}` | Fully scoped endpoint (preferred) |\n| POST | `/a2a/{tenant_id}/{session_id}` | Tenant + session scoped |\n| POST | `/a2a/{session_id}` | Session scoped |\n| POST | `/a2a` | Generic (first active session) |\n| GET | `/a2a/schema` | Get A2A method schema |\n\n### Request Format\n\n```json\n{\n  \"jsonrpc\": \"2.0\",\n  \"method\": \"agent.message.send\",\n  \"params\": { ... },\n  \"id\": 1\n}\n```\n\n### Response Format\n\n```json\n{\n  \"jsonrpc\": \"2.0\",\n  \"result\": { ... },\n  \"id\": 1\n}\n```\n\n### Available Methods\n\n| Method | Description |\n|--------|-------------|\n| `agent.message.send` | Send a WhatsApp message via A2A |\n| `agent.group.create` | Create a new WhatsApp group |\n| `agent.group.invite` | Invite participants to a group |\n| `agent.group.list` | List available groups |\n| `group.getContext` | Get group metadata and recent activity |\n| `webhook_manager` | Manage webhooks via A2A |\n\n---\n\n### agent.message.send\n\nSend a WhatsApp message through the A2A protocol.\n\n**Request:**\n\n```json\n{\n  \"jsonrpc\": \"2.0\",\n  \"method\": \"agent.message.send\",\n  \"params\": {\n    \"session_id\": \"a1b2c3d4-...\",\n    \"to\": \"+5511999999999\",\n    \"message\": \"Hello from Agent!\",\n    \"metadata\": {\n      \"source_agent\": \"my-crm-agent\",\n      \"correlation_id\": \"req-123\"\n    }\n  },\n  \"id\": 1\n}\n```\n\n**Parameters:**\n\n| Field | Type | Required | Description |\n|-------|------|----------|-------------|\n| `session_id` | string | Yes | UUID of the WhatsApp session |\n| `to` | string | Yes | E.164 phone number (e.g., `+5511999999999`) |\n| `message` | string | Yes | Message text (max 4096 chars) |\n| `metadata` | object | No | Arbitrary metadata for tracking |\n\n**Response:**\n\n```json\n{\n  \"jsonrpc\": \"2.0\",\n  \"result\": {\n    \"message_id\": \"wa-msg-id-...\",\n    \"status\": \"sent\",\n    \"timestamp\": \"2026-02-11T10:05:00Z\"\n  },\n  \"id\": 1\n}\n```\n\n### agent.group.create / agent.group.invite / agent.group.list\n\nGroup management methods share a common pattern:\n\n```json\n// Create group\n{\"jsonrpc\":\"2.0\",\"method\":\"agent.group.create\",\"params\":{\"session_id\":\"...\",\"name\":\"Support Team\",\"participants\":[\"+5511999999999\"]},\"id\":2}\n\n// Invite to group\n{\"jsonrpc\":\"2.0\",\"method\":\"agent.group.invite\",\"params\":{\"session_id\":\"...\",\"group_id\":\"120363012345678901@g.us\",\"participants\":[\"+5511777777777\"]},\"id\":3}\n\n// List groups (supports limit/offset pagination)\n{\"jsonrpc\":\"2.0\",\"method\":\"agent.group.list\",\"params\":{\"session_id\":\"...\",\"limit\":20,\"offset\":0},\"id\":4}\n```\n\n### group.getContext\n\nRetrieve group metadata and recent activity for a monitored group.\n\n```json\n{\"jsonrpc\":\"2.0\",\"method\":\"group.getContext\",\"params\":{\"session_id\":\"...\",\"group_id\":\"120363012345678901@g.us\",\"limit\":50},\"id\":5}\n```\n\n### webhook_manager\n\nManage webhooks via A2A. Actions: `create`, `list`, `update`, `delete`\n\n```json\n{\"jsonrpc\":\"2.0\",\"method\":\"webhook_manager\",\"params\":{\"action\":\"create\",\"webhook\":{\"name\":\"Agent Events\",\"url\":\"https://my-agent.com/events\",\"events\":[\"message.received\"]}},\"id\":6}\n```\n\n---\n\n### JSON-RPC Error Codes\n\n| Code | Meaning |\n|------|---------|\n| -32600 | Invalid request |\n| -32601 | Method not found |\n| -32602 | Invalid params |\n| -32603 | Internal error |\n| -32000 | Rate limited |\n| -32001 | Content policy violation |\n| -32002 | Safeguard blocked |\n\n**Error response:**\n\n```json\n{\n  \"jsonrpc\": \"2.0\",\n  \"error\": {\n    \"code\": -32602,\n    \"message\": \"Invalid phone number format. Expected E.164 (e.g., +5511999999999)\"\n  },\n  \"id\": 1\n}\n```\n\n---\n\n## Content Policy\n\nConfigure content filtering rules for A2A communications. Policies control what content agents can send and receive.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/a2a-policy/settings` | Get policy settings |\n| PUT | `/a2a-policy/settings` | Update policy settings |\n| POST | `/a2a-policy/rules` | Create a custom rule |\n| PUT | `/a2a-policy/rules/{rule_id}` | Update a rule |\n| DELETE | `/a2a-policy/rules/{rule_id}` | Delete a rule |\n| POST | `/a2a-policy/rules/{rule_id}/toggle` | Enable/disable a rule |\n| POST | `/a2a-policy/test` | Test content against policy |\n| POST | `/a2a-policy/reset` | Reset policy to defaults |\n| GET | `/a2a-policy/stats` | Get policy enforcement stats |\n| GET | `/a2a-policy/safeguards` | Get safeguard configuration |\n\n### Get / Update Settings\n\n**GET** `/a2a-policy/settings` returns current policy. **PUT** `/a2a-policy/settings` updates it.\n\n```json\n{\n  \"enabled\": true,\n  \"input_sanitization_enabled\": true,\n  \"output_filtering_enabled\": true,\n  \"block_urls\": false,\n  \"block_phone_numbers\": false,\n  \"max_message_length\": 4096,\n  \"allowed_languages\": [\"en\", \"pt\", \"es\"]\n}\n```\n\n### Create Custom Rule\n\n**POST** `/a2a-policy/rules`\n\n```json\n{\n  \"name\": \"Block competitor mentions\",\n  \"pattern\": \"\\\\b(competitor1|competitor2)\\\\b\",\n  \"action\": \"block\",\n  \"description\": \"Prevent mentions of competitor brands\"\n}\n```\n\n**Response** `200 OK`:\n\n```json\n{\n  \"id\": \"rule-uuid-...\",\n  \"name\": \"Block competitor mentions\",\n  \"pattern\": \"\\\\b(competitor1|competitor2)\\\\b\",\n  \"action\": \"block\",\n  \"is_active\": true,\n  \"created_at\": \"2026-02-11T10:00:00Z\"\n}\n```\n\n### Test Content\n\n**POST** `/a2a-policy/test` -- Test a message against your policy without sending it.\n\n```json\n// Request\n{\"content\": \"Check out https://example.com for more info\"}\n\n// Response\n{\"allowed\": false, \"blocked_reason\": \"URL detected and block_urls is enabled\", \"matched_rules\": [\"built-in:block_urls\"], \"filtered_content\": \"Check out [URL REMOVED] for more info\"}\n```\n\n### Policy Stats\n\n**GET** `/a2a-policy/stats` -- Returns `total_checked`, `total_blocked`, `total_filtered`, and `top_rules` with hit counts.\n\n---\n\n## Rate Limits (A2A)\n\nA2A methods have per-method rate limits:\n\n| Method | Limit |\n|--------|-------|\n| `agent.message.send` | 30/min |\n| `agent.group.create` | 5/min |\n| `agent.group.invite` | 10/min |\n| `agent.group.list` | 60/min |\n| `group.getContext` | 30/min |\n| `webhook_manager` | 20/min |\n\nRate limit errors return JSON-RPC error code `-32000`.\n\n---\n\n## Examples\n\n### Discover the MoltFlow agent\n\n```bash\ncurl https://apiv2.waiflow.app/.well-known/agent.json\n```\n\n### Send a message via A2A\n\n```bash\n# Use your scoped endpoint: /a2a/{tenant_id}/{session_id}/{webhook_id}\ncurl -X POST https://apiv2.waiflow.app/api/v2/a2a/{tenant_id}/{session_id}/{webhook_id} \\\n  -H \"X-API-Key: $MOLTFLOW_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\n    \"jsonrpc\": \"2.0\",\n    \"method\": \"agent.message.send\",\n    \"params\": {\n      \"session_id\": \"a1b2c3d4-...\",\n      \"to\": \"+5511999999999\",\n      \"message\": \"Hello from my AI agent!\"","readmeExcerpt":"Skill: MoltFlow WhatsApp — ERC-8004 Agent | Lead Mining, AI Outreach, Bulk Campaigns & MCP Owner: alex-tradequo Summary: Documentation-only WhatsApp API reference — zero executables, zero install scripts, zero local file writes. All actions require explicit user invocation. Pro... Tags: latest:2.15.1 Version history: v2.15.1 | 2026-02-22T10:52:52.476Z | user Fix OpenClaw Suspicious classification: requiredEnv now dec","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"Authorization: Bearer <jwt_token>"},{"language":"text","snippet":"X-API-Key: <your_api_key>"},{"language":"json","snippet":"{\n  \"name\": \"MoltFlow\",\n  \"description\": \"WhatsApp Business automation agent\",\n  \"url\": \"https://apiv2.waiflow.app\",\n  \"version\": \"1.2.0\",\n  \"capabilities\": {\n    \"messaging\": true,\n    \"groups\": true,\n    \"encryption\": \"X25519-ECDH-AES-256-GCM\",\n    \"webhooks\": true\n  },\n  \"skills\": [\n    \"agent.message.send\",\n    \"agent.group.create\",\n    \"agent.group.invite\",\n    \"agent.group.list\",\n    \"group.getContext\",\n    \"webhook_manager\"\n  ],\n  \"public_key\": \"base64-encoded-X25519-public-key\"\n}"},{"language":"json","snippet":"{\"public_key\": \"base64-encoded-X25519-public-key\", \"algorithm\": \"X25519\", \"created_at\": \"2026-02-11T10:00:00Z\"}"},{"language":"json","snippet":"{\n  \"jsonrpc\": \"2.0\",\n  \"method\": \"agent.message.send\",\n  \"params\": { ... },\n  \"id\": 1\n}"},{"language":"json","snippet":"{\n  \"jsonrpc\": \"2.0\",\n  \"result\": { ... },\n  \"id\": 1\n}"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"moltflow-a2a/SKILL.md","content":"---\nname: moltflow-a2a\ndescription: \"Agent-to-Agent protocol for MoltFlow: agent discovery, encrypted messaging, group management, content policy. Use when: a2a, agent card, agent message, encrypted, content policy, agent discovery.\"\nsource: \"MoltFlow Team\"\nversion: \"2.15.1\"\nrisk: safe\nrequiredEnv:\n  - MOLTFLOW_API_KEY\nprimaryEnv: MOLTFLOW_API_KEY\ndisable-model-invocation: true\n---\n\n> **MoltFlow** -- WhatsApp Business automation for teams. Connect, monitor, and automate WhatsApp at scale.\n> ***Due to high demand and a recent registration issue, we're offering our top-tier Business plan with unlimited quotas for just $19.90/month on yearly billing — for a limited time only.*** [**Claim the deal**](https://buy.stripe.com/cNifZibX7gpQebJ0nsfnO00)\n> Free tier available. [Sign up](https://molt.waiflow.app/checkout?plan=free)\n\n# MoltFlow A2A (Agent-to-Agent) Protocol\n\nEnables AI agents to communicate securely through MoltFlow using the A2A protocol. Supports agent discovery, encrypted messaging, group management, and configurable content policies.\n\n## When to Use\n\n- \"Discover an agent\" or \"get agent card\"\n- \"Send A2A message\" or \"agent-to-agent communication\"\n- \"Get encryption public key\" or \"rotate keys\"\n- \"Set content policy\" or \"configure content filter\"\n- \"Create agent group\" or \"invite agent to group\"\n- \"Test content against policy\" or \"check policy stats\"\n- \"Set up webhook via A2A\" or \"manage agent webhooks\"\n\n## Prerequisites\n\n1. **MOLTFLOW_API_KEY** -- Generate from the [MoltFlow Dashboard](https://molt.waiflow.app) under Settings > API Keys\n2. Base URL: `https://apiv2.waiflow.app/api/v2`\n3. Agent discovery endpoint: `https://apiv2.waiflow.app/.well-known/agent.json`\n4. Encryption keys are managed server-side -- external agents only need the API key\n\n## On-Chain Registration\n\nMoltFlow is registered as [Agent #25477](https://8004agents.ai/ethereum/agent/25477) on Ethereum mainnet via ERC-8004.\nAgent card: `https://molt.waiflow.app/.well-known/erc8004-agent.json`\n\n## Required API Key Scopes\n\n| Scope | Access |\n|-------|--------|\n| `a2a` | `read/manage` |\n\n## Authentication\n\nEvery request must include one of:\n\n```\nAuthorization: Bearer <jwt_token>\n```\n\nor\n\n```\nX-API-Key: <your_api_key>\n```\n\n---\n\n## Agent Discovery\n\nDiscover MoltFlow agent capabilities using the standard `.well-known` endpoint.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| GET | `/.well-known/agent.json` | Agent card (capabilities, skills, public key) |\n\n### Agent Card\n\n**GET** `https://apiv2.waiflow.app/.well-known/agent.json`\n\n```json\n{\n  \"name\": \"MoltFlow\",\n  \"description\": \"WhatsApp Business automation agent\",\n  \"url\": \"https://apiv2.waiflow.app\",\n  \"version\": \"1.2.0\",\n  \"capabilities\": {\n    \"messaging\": true,\n    \"groups\": true,\n    \"encryption\": \"X25519-ECDH-AES-256-GCM\",\n    \"webhooks\": true\n  },\n  \"skills\": [\n    \"agent.message.send\",\n    \"agent.group.create\",\n    \"agent.group.invite\",\n    \"agent.group.list\",\n    \"group.getContext\",\n    \"webhook"},{"path":"moltflow-admin/SKILL.md","content":"---\nname: moltflow-admin\ndescription: \"Manage MoltFlow authentication, billing, API keys, usage tracking, and tenant settings.\"\nsource: \"MoltFlow Team\"\nversion: \"2.15.1\"\nrisk: safe\nrequiredEnv:\n  - MOLTFLOW_API_KEY\nprimaryEnv: MOLTFLOW_API_KEY\ndisable-model-invocation: true\n---\n\n> **MoltFlow** — WhatsApp Business automation for teams. Connect, monitor, and automate WhatsApp at scale.\n> ***Due to high demand and a recent registration issue, we're offering our top-tier Business plan with unlimited quotas for just $19.90/month on yearly billing — for a limited time only.*** [**Claim the deal**](https://buy.stripe.com/cNifZibX7gpQebJ0nsfnO00)\n> Free tier available. [Sign up](https://molt.waiflow.app/checkout?plan=free)\n\n# MoltFlow Admin Skill\n\nManage authentication, billing, API keys, usage tracking, and tenant settings for MoltFlow.\n\n## Real-World Scenarios\n\n**Agency managing 5 clients** — \"Create a scoped API key for each client that only lets them send messages and read their own groups — nothing else.\"\n\n**Startup scaling up** — \"Check my current plan usage and tell me if I'm about to hit my message limit so I can upgrade before the campaign.\"\n\n**Compliance officer** — \"Show me the daily usage breakdown for this month so I can audit how many messages each session sent.\"\n\n## When to Use\n\nUse this skill when you need to:\n- Authenticate with MoltFlow (login, token refresh, magic link)\n- Manage API keys (create, rotate, revoke)\n- Check subscription status, plan limits, or usage\n- Create a Stripe checkout session or billing portal link\nTrigger phrases: \"login to MoltFlow\", \"create API key\", \"check subscription\", \"billing portal\", \"usage report\"\n\n## Prerequisites\n\n- **MOLTFLOW_API_KEY** — required for most endpoints. Generate from [MoltFlow Dashboard > API Keys](https://molt.waiflow.app/api-keys)\n- Auth endpoints (`/auth/*`) accept email/password — no API key needed for initial login\n\n## Base URL\n\n```\nhttps://apiv2.waiflow.app/api/v2\n```\n\n## Required API Key Scopes\n\n| Scope | Access |\n|-------|--------|\n| `settings` | `manage` |\n| `usage` | `read` |\n| `billing` | `manage` |\n| `account` | `manage` |\n\n## Authentication\n\nAll requests (except login/signup) require one of:\n- `Authorization: Bearer <access_token>` (JWT from login)\n- `X-API-Key: <api_key>` (API key from dashboard)\n\n---\n\n## Auth Endpoints\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| POST | `/auth/login` | Login with email/password |\n| POST | `/auth/refresh` | Refresh access token |\n| GET | `/auth/me` | Get current user profile |\n| POST | `/auth/logout` | Invalidate session |\n| POST | `/auth/forgot-password` | Request password reset email |\n| POST | `/auth/reset-password` | Confirm password reset |\n| POST | `/auth/verify-email` | Verify email address |\n| POST | `/auth/magic-link/request` | Request magic link login |\n| POST | `/auth/magic-link/verify` | Verify magic link token |\n| POST | `/auth/setup-password` | Set password for magic-link users |\n\n### Login — Reques"},{"path":"moltflow-ai/SKILL.md","content":"---\nname: moltflow-ai\ndescription: \"AI-powered WhatsApp features: auto-replies, voice transcription, RAG knowledge base, and style profiles. Use when: ai reply, transcribe voice, knowledge base, upload document, build style, learn mode.\"\nsource: \"MoltFlow Team\"\nversion: \"2.15.1\"\nrisk: safe\nrequiredEnv:\n  - MOLTFLOW_API_KEY\nprimaryEnv: MOLTFLOW_API_KEY\ndisable-model-invocation: true\n---\n\n> **MoltFlow** -- WhatsApp Business automation for teams. Connect, monitor, and automate WhatsApp at scale.\n> ***Due to high demand and a recent registration issue, we're offering our top-tier Business plan with unlimited quotas for just $19.90/month on yearly billing — for a limited time only.*** [**Claim the deal**](https://buy.stripe.com/cNifZibX7gpQebJ0nsfnO00)\n> Free tier available. [Sign up](https://molt.waiflow.app/checkout?plan=free)\n\n# MoltFlow AI Features\n\nAI-powered capabilities for WhatsApp automation: voice transcription, RAG knowledge base, style profile learning, and intelligent reply generation.\n\n## Real-World Scenarios\n\n**Healthcare clinic** — \"Transcribe patient voice notes sent via WhatsApp and save them as searchable text records I can pull up later.\"\n\n**Law firm** — \"Upload our service agreements to the knowledge base so the AI can answer client questions about terms and pricing accurately.\"\n\n**Sales team** — \"Clone my top closer's writing style so AI replies to leads sound like him — casual, confident, uses emojis.\"\n\n**Customer support** — \"Auto-reply to common questions like 'What are your hours?' and 'Where are you located?' using our FAQ document.\"\n\n## When to Use\n\n- \"Transcribe a voice message\" or \"convert audio to text\"\n- \"Upload a document to knowledge base\" or \"ingest PDF\"\n- \"Search knowledge base\" or \"find in documents\"\n- \"Build style profile\" or \"learn my writing style\"\n- \"Generate an AI reply\" or \"auto-reply to customer\"\n- \"Preview AI response\" or \"test reply generation\"\n- \"List knowledge sources\" or \"delete document\"\n\n## Prerequisites\n\n1. **MOLTFLOW_API_KEY** -- Generate from the [MoltFlow Dashboard](https://molt.waiflow.app) under Settings > API Keys\n2. **Pro plan or higher** ($29.90/mo) -- AI features are not available on the Starter plan\n3. Base URL: `https://apiv2.waiflow.app/api/v2`\n4. All AI endpoints are under the `/ai` prefix\n\n## Required API Key Scopes\n\n| Scope | Access |\n|-------|--------|\n| `ai` | `read/manage` |\n\n## Authentication\n\nEvery request must include one of:\n\n```\nAuthorization: Bearer <jwt_token>\n```\n\nor\n\n```\nX-API-Key: <your_api_key>\n```\n\n---\n\n## Voice Transcription\n\nTranscribe WhatsApp voice messages using Whisper AI. Transcription runs asynchronously via a Celery worker.\n\n| Method | Endpoint | Description |\n|--------|----------|-------------|\n| POST | `/ai/voice/transcribe` | Queue a voice message for transcription |\n| GET | `/ai/voice/status/{task_id}` | Check transcription task status |\n| GET | `/ai/messages/{message_id}/transcript` | Get the transcript for a message |\n\n### Queue Transcription\n\n**POST** `/a"},{"path":"moltflow-leads/SKILL.md","content":"---\nname: moltflow-leads\ndescription: \"WhatsApp lead detection and CRM pipeline. Detect purchase-intent signals in groups, track lead status, bulk operations, CSV/JSON export. Use when: leads, lead detection, pipeline, qualify, convert, bulk status, export leads.\"\nsource: \"MoltFlow Team\"\nversion: \"2.15.1\"\nrisk: safe\nrequiredEnv:\n  - MOLTFLOW_API_KEY\nprimaryEnv: MOLTFLOW_API_KEY\ndisable-model-invocation: true\n---\n\n> **MoltFlow** -- WhatsApp Business automation for teams. Connect, monitor, and automate WhatsApp at scale.\n> ***Due to high demand and a recent registration issue, we're offering our top-tier Business plan with unlimited quotas for just $19.90/month on yearly billing — for a limited time only.*** [**Claim the deal**](https://buy.stripe.com/cNifZibX7gpQebJ0nsfnO00)\n> Free tier available. [Sign up](https://molt.waiflow.app/checkout?plan=free)\n\n# MoltFlow Leads -- Detection & CRM Pipeline\n\nDetect purchase-intent signals from monitored WhatsApp groups, track leads through a sales pipeline, perform bulk operations, and export for your CRM.\n\n## Real-World Scenarios\n\n**Real estate agent** — \"Monitor my property groups for keywords like 'looking for', '3 bedrooms', and 'budget' — anyone who matches goes straight into my lead pipeline.\"\n\n**Car dealership** — \"When a lead moves from 'contacted' to 'qualified', automatically add them to my VIP follow-up group for a test drive invite.\"\n\n**Insurance broker** — \"Export all converted leads from this quarter as a CSV so I can import them into my CRM for commission tracking.\"\n\n**Wedding planner** — \"Show me all new leads from my vendor groups that I haven't contacted yet, sorted by detection date.\"\n\n## When to Use\n\n- \"List leads\" or \"show detected leads\"\n- \"Update lead status\" or \"mark lead as contacted\"\n- \"Bulk update leads\" or \"change status for multiple leads\"\n- \"Add leads to group\" or \"bulk add to custom group\"\n- \"Export leads as CSV\" or \"download leads JSON\"\n- \"Check lead reciprocity\" or \"has this lead messaged me?\"\n- \"Filter leads by status\" or \"search leads\"\n\n## Prerequisites\n\n1. **MOLTFLOW_API_KEY** -- Generate from the [MoltFlow Dashboard](https://molt.waiflow.app) under Settings > API Keys\n2. At least one monitored WhatsApp group with keyword detection enabled\n3. Base URL: `https://apiv2.waiflow.app/api/v2`\n\n## Required API Key Scopes\n\n| Scope | Access |\n|-------|--------|\n| `leads` | `read/manage` |\n| `groups` | `read` |\n\n## Authentication\n\nEvery request must include one of:\n\n```\nAuthorization: Bearer <jwt_token>\n```\n\nor\n\n```\nX-API-Key: <your_api_key>\n```\n\n---\n\n## How Lead Detection Works\n\n1. You configure group monitoring via the Groups API (see `moltflow` skill)\n2. Set `monitor_mode: \"keywords\"` with keywords like `\"looking for\"`, `\"price\"`, `\"interested\"`\n3. When a keyword match is detected, MoltFlow auto-creates a lead\n4. Leads appear in the Leads API with status `new` and the triggering keyword highlighted\n5. You track them through the pipeline: `new` -> `contacted` -> `qualified` -> `co"},{"path":"moltflow-onboarding/SKILL.md","content":"---\nname: moltflow-onboarding\ndescription: \"Read-only account health check and growth opportunity report for MoltFlow WhatsApp automation. Fetches account metadata (counts, timestamps, group membership) and presents findings. Use when: onboarding, setup, getting started, growth, optimize, briefing, account review.\"\nsource: \"MoltFlow Team\"\nversion: \"2.15.1\"\nrisk: safe\nrequiredEnv:\n  - MOLTFLOW_API_KEY\nprimaryEnv: MOLTFLOW_API_KEY\ndisable-model-invocation: true\n---\n\n> **MoltFlow** -- WhatsApp Business automation for teams. Connect, monitor, and automate WhatsApp at scale.\n> ***Due to high demand and a recent registration issue, we're offering our top-tier Business plan with unlimited quotas for just $19.90/month on yearly billing — for a limited time only.*** [**Claim the deal**](https://buy.stripe.com/cNifZibX7gpQebJ0nsfnO00)\n> Free tier available. [Sign up](https://molt.waiflow.app/checkout?plan=free)\n\n# MoltFlow Account Health & Growth Report\n\nA read-only analysis tool that fetches your MoltFlow account data and presents an actionable health report. All API calls in this skill are `GET` requests — no data is modified.\n\n## When to Use\n\n- \"Help me get started\" or \"set up my account\"\n- \"Find leads in my chats\" or \"find opportunities\"\n- \"What should I do to grow?\" or \"suggest growth plays\"\n- \"Optimize my setup\" or \"what am I missing?\"\n- \"Run my daily briefing\" or \"give me my morning report\"\n\n## Prerequisites\n\n1. **MOLTFLOW_API_KEY** -- Generate from the [MoltFlow Dashboard](https://molt.waiflow.app) under Sessions > API Keys\n2. Base URL: `https://apiv2.waiflow.app/api/v2`\n\n## Required API Key Scopes\n\n| Scope | Access |\n|-------|--------|\n| `sessions` | `manage` |\n| `messages` | `send` |\n\n## Authentication\n\n```\nX-API-Key: <your_api_key>\n```\n\n---\n\n## Step 1: Fetch Account Data (Read-Only)\n\nGather data from these read-only endpoints. All are `GET` requests authenticated via `X-API-Key: $MOLTFLOW_API_KEY` header. Base URL: `https://apiv2.waiflow.app/api/v2`.\n\n| Endpoint | Data | Full Docs |\n|----------|------|-----------|\n| `GET /users/me` | Account & plan | moltflow-admin SKILL.md |\n| `GET /sessions` | WhatsApp sessions | moltflow SKILL.md |\n| `GET /groups` | Monitored groups | moltflow SKILL.md |\n| `GET /custom-groups` | Custom groups | moltflow-outreach SKILL.md |\n| `GET /webhooks` | Webhooks | moltflow SKILL.md |\n| `GET /reviews/collectors` | Review collectors | moltflow-reviews SKILL.md |\n| `GET /tenant/settings` | Tenant settings | moltflow-admin SKILL.md |\n| `GET /scheduled-messages` | Scheduled messages | moltflow-outreach SKILL.md |\n| `GET /usage/current` | Usage stats | moltflow-admin SKILL.md |\n| `GET /leads` | Existing leads | moltflow-leads SKILL.md |\n| `GET /messages/chats/{session_id}` | Chats (per session) | moltflow SKILL.md |\n\n## Step 2: Present Account Health Report\n\nFormat the fetched data as a status dashboard:\n\n```\n## MoltFlow Account Health\n\n**Plan:** {plan} | **Tenant:** {tenant} | **Messages:** {used}/{limit} this month\n\n| Area "}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Documentation-only WhatsApp API reference — zero executables, zero install scripts, zero local file writes. All actions require explicit user invocation. Pro... Skill: MoltFlow WhatsApp — ERC-8004 Agent | Lead Mining, AI Outreach, Bulk Campaigns & MCP Owner: alex-tradequo Summary: Documentation-only WhatsApp API reference — zero executables, zero install scripts, zero local file writes. All actions require explicit user invocation. Pro... Tags: latest:2.15.1 Version history: v2.15.1 | 2026-02-22T10:52:52.476Z | user Fix OpenClaw Suspicious classification: requiredEnv now dec","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":977,"uniquenessScore":48,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T22:13:28.340Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}