/v1/contacts/{contact_id}betaDelete a contact
- Needs
- Create and edit contacts, tags, contact groups and custom fields
(crm:write) - Plan
- Any plan with API access
- Limits
- 60 a minute per key
- Dry run
- Yes — every check runs with ?dry_run=true, nothing changes
- Confirm
- Header
Api-Confirm: delete - Undo
- Cannot be undone. Create the contact again with the same phone number.
Deletes one contact. It disappears from groups, tags and future broadcasts.
Refused when the contact has already received messages, so conversation history is never lost.
Try it
Protects against doing it twice if you retry: a retry with the same key gets the first answer back instead of running again.
Code and response
curl -X DELETE 'https://mcp.wa-api.cloud/v1/contacts/48213?dry_run=true' \ -H "Authorization: Bearer $API_KEY" \ -H "Idempotency-Key: $(uuidgen)"
The code reads your key from $API_KEY.
Parameters
| Field | Type | What it is |
|---|---|---|
| contact_idrequired | string | integer · path | The contact id.pattern ^[1-9]\d{0,18}$Signed in? Pick one from your data with “My data”. |
Headers
| Field | Type | What it is |
|---|---|---|
| Authorizationrequired | header | Bearer $API_KEY — your API key. |
| Api-Version | header | The API version to use, e.g. 2026-10-01. Default: the version your key is pinned to.one of: 2026-10-01 · pattern ^\d{4}-\d{2}-\d{2}$ |
| Idempotency-Key | header | Any unique string (8–128 characters). A retry with the same key returns the first answer instead of running twice. Kept 24 hours.pattern ^[A-Za-z0-9._:-]+$ · 8–128 characters |
| Api-Confirmrequired | header | Type the operation's verb (e.g. delete, submit) to confirm a change that cannot be undone or that WhatsApp or your customers see. Not needed with dry_run=true. |
Response 200
Deleted.
| Field | Type | What it is |
|---|---|---|
| idrequired | string | |
| deletedrequired | boolean | |
| dry_run | boolean | true when this was a dry run: every check ran and nothing changed. |
Errors
Errors are application/problem+json. Branch on code.
| Status | Code | When |
|---|---|---|
| 400 | invalid_input | A field is missing or has the wrong format. |
| 401 | unauthenticated | The Authorization header is missing, the key is unknown, expired or revoked. |
| 403 | entitlement_required | The workspace's plan does not include API access ( |
| 403 | forbidden | The contact has received messages and is kept for history. |
| 403 | insufficient_scope | The key does not have the permission this operation needs. |
| 404 | not_found | No contact with this id. |
| 409 | conflict | Also returned while a request with the same Idempotency-Key is still running. |
| 428 | confirm_required | Send the header |
| 429 | rate_limited | The key or workspace went over its rate limit. Wait for |
| 503 | upstream_unavailable | A service behind the API is briefly unavailable. Safe to retry with backoff. |
| 504 | timeout | The change did not finish in time. Retry with the same Idempotency-Key: it never runs twice. |
Examples
Delete a test contact
Response 200
{
"id": "48213",
"deleted": true
}Webhook events
These events can fire after this call. Subscribe an endpoint to hear about them.
Operation path
The same operation is also at POST /v1/ops/crm_delete_contact, with every field in the JSON body.