· 2 min · TextMeFlow Team

Send WhatsApp Messages from Mailchimp or ActiveCampaign via Webhooks

Email marketing tools get opened less every year, but the automations built on top of them — welcome sequences, abandoned-signup nudges, win-back campaigns — are still worth keeping. The fix isn't abandoning Mailchimp or ActiveCampaign, it's adding a WhatsApp step to the automation you already built. Both platforms can call an outgoing webhook on events like "subscriber added", "tag applied" or "automation step reached" — point that webhook at a small endpoint of your own, and forward the message to WhatsApp through the TextMeFlow API.

This is a direct bridge: no Zapier, no Make, no middleman subscription. Just your webhook receiver and one API call.

Where the webhook comes from

Mailchimp has a native webhook setting per audience (Audience → Settings → Webhooks) that can fire on "subscribes", "updates profile", "applies a tag", and a few other events. Mailchimp webhooks arrive as application/x-www-form-urlencoded, not JSON — a detail that trips people up when they copy a JSON-only parser from another integration.

ActiveCampaign doesn't have a global webhook toggle; instead you add a "Webhook" action block inside an automation, right where you'd normally add an email step. That gives you full control over exactly which automations notify WhatsApp, and the payload is JSON with the contact's fields and the automation/action IDs.

Either way, the pattern is the same: platform event -> webhook POST to your server -> your server calls the TextMeFlow API.

A receiver in PHP

<?php
// routes/web.php or a dedicated controller

use Illuminate\Http\Request;
use Illuminate\Support\Facades\Http;

Route::post('/webhooks/mailchimp', function (Request $request) {
    // Mailchimp sends form-encoded data, not JSON
    $email = $request->input('data.email');
    $event = $request->input('type'); // e.g. "subscribe"
    $phone = lookupPhoneForEmail($email); // your own mapping, E.164 format

    if ($event === 'subscribe' && $phone) {
        sendWhatsApp($phone, "Welcome! You're on the list — reply STOP any time to opt out.");
    }

    return response()->noContent();
});

function sendWhatsApp(string $phone, string $body): void
{
    Http::withToken(config('services.textmeflow.api_key'))
        ->post('https://textmeflow.eu/api/messages', [
            'to' => $phone,
            'type' => 'text',
            'text' => $body,
        ]);
}

The ActiveCampaign version is almost identical, just read JSON instead of form fields:

Route::post('/webhooks/activecampaign', function (Request $request) {
    $email = $request->input('contact.email');
    $phone = $request->input('contact.phone'); // only if you collect it in AC

    if ($phone) {
        sendWhatsApp($phone, 'Thanks for signing up — we will follow up shortly on WhatsApp.');
    }

    return response()->noContent();
});

The part people skip: phone numbers

Neither Mailchimp nor ActiveCampaign requires a phone number by default, and when a form does collect one it's rarely in E.164 format (+32...). Validate and normalize it before you ever call the API — a malformed number just produces a rejected send, and at scale that's a chunk of your automation quietly failing. See the practical checklist in validating phone numbers for the WhatsApp API if you haven't built that step yet.

Securing the endpoint

Your webhook route is public by definition — email platforms can't reach an authenticated endpoint. At minimum:

  • Put the route behind a long, random path segment (/webhooks/mc-8f2a...) instead of a guessable one.
  • Check the sender IP range if the platform publishes one (ActiveCampaign does, in their docs).
  • Rate-limit the route — a leaked URL shouldn't be able to trigger unlimited WhatsApp sends.

This is a different trust direction than TextMeFlow's own webhooks (delivery status, inbound replies), which are HMAC-signed so you can verify they really came from TextMeFlow — see verifying TextMeFlow webhook signatures for that side of the integration. Here, Mailchimp and ActiveCampaign are the senders, so the signature check runs on their side of the contract, not yours — treat the inbound payload as semi-trusted and validate the fields you act on (a valid phone number, a known event type) rather than trusting it blindly.

Respect the opt-out

A marketing automation sending WhatsApp messages is still marketing — the same STOP handling that applies to any WhatsApp campaign applies here. TextMeFlow's anti-spam pipeline already enforces rate limits, a risk score, STOP keyword handling and quiet hours on every number, but your own contact list should mirror that: if someone unsubscribes from the Mailchimp list, remove them from the WhatsApp automation too, not just the email one. For the legal side of consent, see proving opt-in for WhatsApp marketing — this article is general information, not legal advice.

Full guide

For the API key setup, rate limits and error codes you'll hit while building this, start at getting started and the webhooks reference. Once your Mailchimp or ActiveCampaign automation is sending its first real WhatsApp message, sign up for the free plan — 50 messages a month, no credit card, enough to test the whole flow end to end.

Zelf WhatsApp-berichten versturen via API?

Gratis voor altijd tot 50 berichten/maand. QR scannen en binnen 5 minuten verstuur je je eerste bericht.

Gratis voor altijd