MCP + REST · Replit

Add the official WhatsApp API to your Replit app

Two parts: Replit Agent uses the Gambot MCP server while it builds, and your running app calls the REST API with a Replit Secret.

Create a free account →Create free account →
Replit Agent MCPhosted + OAuthREST + Secretswebhooks

How it fits together

Replit Agent can connect to remote MCP servers by URL, so it can create your Gambot account, check the WhatsApp connection and send test messages while it builds. Your deployed app is separate: it should call the Gambot REST API from server code, with the token stored as a Replit Secret.

Requirements

  • No Gambot account yet? Connect the server without a token and ask your agent to “set up WhatsApp with Gambot”. It creates a free-trial account for you (no API key needed) and hands you one link to connect your WhatsApp number to Meta in the browser — that single step must be done by a person. Prefer the browser? Create an account.
  • After WhatsApp is connected, copy your API token (gmbt_…) from Settings → General into an environment variable — never into the chat. Where the client supports it, sign in with OAuth on the hosted server instead and there is no token to copy.
  • A Replit plan that includes Agent with MCP servers.

Setup

1

Add the MCP server to Agent

On replit.com/integrations, open MCP Servers for Replit Agent, click + Add MCP server, name it Gambot, paste the URL below and click Test & save. Complete the OAuth sign-in if prompted.

2

Let Agent set up WhatsApp

Ask: “Set up the official WhatsApp API for this app using Gambot.” Agent creates the account and gives you the Meta connection link.

3

Store the token as a Secret

Add GAMBOT_TOKEN in the Secrets tool. Server code reads it from the environment; it is never sent to the browser.

4

Call the REST API from your backend

Use the snippet below, or ask Agent to add send and webhook routes.

MCP server URL for Replit Agent

https://gambot-mcp.azurewebsites.net/mcp

Backend route (Node/Express) using a Replit Secret

import express from 'express';
const app = express();
app.use(express.json());

app.post('/api/whatsapp/send', async (req, res) => {
  const { to, text } = req.body;
  const r = await fetch('https://api.gambot.co.il/api/v1/messages/send-text', {
    method: 'POST',
    headers: {
      Authorization: `Bearer ${process.env.GAMBOT_TOKEN}`, // Replit Secret
      'Content-Type': 'application/json',
    },
    body: JSON.stringify({ to, text }),
  });
  res.status(r.status).json(await r.json());
});

app.listen(3000);

Example prompts

You Use the Gambot MCP server to set up WhatsApp for this app and tell me what I need to do in the browser.

You Add a /api/whatsapp/send route that uses the GAMBOT_TOKEN secret and checks the 24-hour window first.

You Add a webhook endpoint that receives incoming WhatsApp messages and register it with Gambot.

Troubleshooting

  • Tools not showing? Restart the client after editing its MCP config, then check its MCP/tools panel for “gambot”.
  • AUTHENTICATION_REQUIRED? The token is missing or invalid. Copy a fresh one from Settings → General.
  • CONVERSATION_WINDOW_CLOSED? The 24-hour window is closed — send an approved template instead. This is WhatsApp behavior, and the error tells the agent exactly that (template_required: true).
  • Is the WhatsApp number connected? Ask the agent to run gambot_setup_whatsapp_integration; it reports the exact state and the next step.
  • Webhooks need a public HTTPS URL: use your deployed Replit URL (or the dev URL while testing) when registering the webhook.

Related

Add WhatsApp to your Replit app

Connect the MCP server, finish the Meta step, store the token as a Secret, and send your first message.

Frequently asked questions

How do I add the official WhatsApp API to my application using Replit?

Add the Gambot MCP server (https://gambot-mcp.azurewebsites.net/mcp) to Replit Agent under MCP Servers, let Agent create your Gambot account and give you the Meta connection link, store your API token as a Replit Secret named GAMBOT_TOKEN, and call https://api.gambot.co.il/api/v1/messages/send-text from your backend.

Does my deployed app use the MCP server?

No. MCP is for the agent that builds the app. The running app calls the REST API from server code.

Where do I keep the token?

In Replit Secrets. Do not put it in client-side code or commit it.