> ## Documentation Index
> Fetch the complete documentation index at: https://devs.izap.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Add contacts to an assistant's contact filter

> Adds up to 500 phone numbers to the allowlist or blocklist in one call. Numbers are stored in canonical E.164 form, so different spellings of one number are one entry. Adding a number that is already listed is not an error; the response reports it separately, along with any input that is not a usable phone number.



## OpenAPI

````yaml /api-reference/openapi.json post /api/v1/businesses/chatbots/{chatbot_id}/contact-filter/entries
openapi: 3.1.0
info:
  contact:
    email: suporte@izap.ai
    name: iZap API Support
  description: Public REST API for the iZap WhatsApp business messaging platform.
  license:
    name: MIT
    url: https://opensource.org/licenses/MIT
  title: iZap API
  version: v1
servers:
  - description: Production
    url: https://api.izap.ai
  - description: Staging
    url: https://api-staging.izap.ai
security: []
tags:
  - description: >-
      Personal access tokens for calling this API, plus introspection of the
      token presented on a request.
    name: api-tokens
  - description: >-
      Create a business, read and update its profile, and manage its opening
      hours.
    name: businesses
  - description: >-
      Reusable images belonging to the caller's business, referenced when
      composing messages.
    name: business-library
  - description: Product catalog menus a business publishes to its customers.
    name: menus
  - description: >-
      Provision and inspect the WhatsApp Cloud API numbers attached to a
      business: registration, WABA details, per-number assistant binding and
      catalog sends.
    name: whatsapp-cloud
  - description: >-
      Conversation lifecycle — list, create and delete chats, and control read,
      snooze, status and AI pause state.
    name: chats
  - description: >-
      Read a conversation's messages, send free-form or template replies, and
      upload attachments.
    name: messages
  - description: >-
      Manage WhatsApp message templates: draft them locally, submit them to Meta
      for review and sync approval status back.
    name: whatsapp-templates
  - description: >-
      Bulk template sends. A transmission is previewed into a draft, then
      confirmed or cancelled — confirming dispatches to real recipients.
    name: transmissions
  - description: >-
      Register URLs that receive signed event deliveries when something happens
      in a business, rotate their signing secrets, and replay an individual
      delivery.
    name: webhooks
  - description: >-
      Server-rendered order visualisation page for a business slug, behind HTTP
      Basic auth.
    name: orders
paths:
  /api/v1/businesses/chatbots/{chatbot_id}/contact-filter/entries:
    post:
      tags:
        - businesses
      summary: Add contacts to an assistant's contact filter
      description: >-
        Adds up to 500 phone numbers to the allowlist or blocklist in one call.
        Numbers are stored in canonical E.164 form, so different spellings of
        one number are one entry. Adding a number that is already listed is not
        an error; the response reports it separately, along with any input that
        is not a usable phone number.
      operationId: addAssistantContactFilterEntries
      parameters:
        - in: path
          name: chatbot_id
          required: true
          schema:
            format: uuid
            title: Chatbot Id
            type: string
        - description: >-
            UUID of the business the request is scoped to. Required on this
            route; the deprecated /businesses/{business_id}/... form takes it
            from the path instead.
          in: header
          name: business-id
          required: true
          schema:
            anyOf:
              - type: string
              - type: 'null'
            description: >-
              UUID of the business the request is scoped to. Required on this
              route; the deprecated /businesses/{business_id}/... form takes it
              from the path instead.
            title: Business-Id
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ContactFilterEntriesIn'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ContactFilterEntriesAddedOut'
          description: Successful Response
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
          description: Missing or invalid credentials.
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
          description: The credential is valid but not authorized for this action.
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
          description: The resource, or the business named in the request, does not exist.
        '422':
          content:
            application/json:
              schema:
                oneOf:
                  - $ref: '#/components/schemas/HTTPValidationError'
                  - $ref: '#/components/schemas/ApiError'
          description: >-
            The request body failed validation, or the allowlist/blocklist is
            already full.
        default:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiError'
          description: Unexpected error.
      security:
        - bearerAuth: []
components:
  schemas:
    ContactFilterEntriesIn:
      properties:
        label:
          anyOf:
            - maxLength: 100
              type: string
            - type: 'null'
          description: Optional note stored with each contact.
          title: Label
        list:
          $ref: '#/components/schemas/ContactFilterList'
          description: 'Which list to add the contacts to: `allow` or `block`.'
        phone_numbers:
          description: >-
            A WhatsApp phone number with its country code (`+5585987504325`;
            spaces, dashes and parentheses are ignored), or a WhatsApp
            business-scoped user ID for contacts whose number is hidden. Numbers
            are stored in canonical E.164 form.
          items:
            type: string
          maxItems: 500
          minItems: 1
          title: Phone Numbers
          type: array
      required:
        - list
        - phone_numbers
      title: ContactFilterEntriesIn
      type: object
    ContactFilterEntriesAddedOut:
      properties:
        added:
          items:
            $ref: '#/components/schemas/ContactFilterEntryOut'
          title: Added
          type: array
        already_listed:
          description: Contacts that were already on the list, in canonical form.
          items:
            type: string
          title: Already Listed
          type: array
        invalid:
          description: Inputs that are not a usable phone number, as sent.
          items:
            type: string
          title: Invalid
          type: array
      required:
        - added
        - already_listed
        - invalid
      title: ContactFilterEntriesAddedOut
      type: object
    ApiError:
      description: >-
        The response body of a handled API error.


        ``detail`` is either a plain string (FastAPI's default for an

        ``HTTPException`` raised with a string, and for the ``default``
        fastapi-users

        messages like ``"Not authenticated"``) or the structured

        :class:`ApiErrorDetail` object described above. ``code`` is present only
        on

        the top-level shape ``aizap.core.exceptions.AppException`` produces for
        its

        own 5xx responses (``"INTERNAL_ERROR"`` / ``"DB_ERROR"``); it does not

        duplicate the ``code`` nested inside a structured ``detail``.
      properties:
        code:
          anyOf:
            - type: string
            - type: 'null'
          default: null
          title: Code
        detail:
          anyOf:
            - type: string
            - $ref: '#/components/schemas/ApiErrorDetail'
          title: Detail
      required:
        - detail
      title: ApiError
      type: object
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          title: Detail
          type: array
      title: HTTPValidationError
      type: object
    ContactFilterList:
      enum:
        - allow
        - block
      title: ContactFilterList
      type: string
    ContactFilterEntryOut:
      properties:
        created:
          format: date-time
          title: Created
          type: string
        id:
          format: uuid
          title: Id
          type: string
        label:
          anyOf:
            - type: string
            - type: 'null'
          title: Label
        phone_number:
          description: >-
            A WhatsApp phone number with its country code (`+5585987504325`;
            spaces, dashes and parentheses are ignored), or a WhatsApp
            business-scoped user ID for contacts whose number is hidden. Numbers
            are stored in canonical E.164 form.
          title: Phone Number
          type: string
      required:
        - id
        - phone_number
        - created
      title: ContactFilterEntryOut
      type: object
    ApiErrorDetail:
      additionalProperties: true
      description: |-
        The structured ``detail`` object some error responses carry.

        Several handlers (the REST API plan gate, the free-tier limits, the
        webhooks entitlement gate, the closed customer-service window) raise
        ``HTTPException(detail={"code": ..., "message": ..., ...})`` — a fixed
        ``code``/``message`` pair plus extra fields specific to that error.
        ``extra="allow"`` keeps those fields in the documented shape instead of
        dropping them.
      properties:
        code:
          title: Code
          type: string
        message:
          title: Message
          type: string
      required:
        - code
        - message
      title: ApiErrorDetail
      type: object
    ValidationError:
      properties:
        ctx:
          title: Context
          type: object
        input:
          title: Input
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          title: Location
          type: array
        msg:
          title: Message
          type: string
        type:
          title: Error Type
          type: string
      required:
        - loc
        - msg
        - type
      title: ValidationError
      type: object
  securitySchemes:
    bearerAuth:
      description: >-
        Personal access token (izap_pat_…) sent as Authorization: Bearer
        <token>; dashboard session JWTs are also accepted.
      scheme: bearer
      type: http

````