Baileys turns linked accounts into an operator-owned gateway
WA-AKG connects WhatsApp accounts by QR code, keeps their sessions on your server, and exposes messaging through a dashboard and REST endpoints. That is useful when an internal system needs to send a document, react to an incoming message, or schedule a reply without a person holding a phone. The project uses Baileys to speak to WhatsApp, so adoption includes that library's behavior and the ongoing job of keeping linked sessions healthy. This is different from buying Meta's official Business Platform.
The dashboard manages multiple sessions, chats, contacts, groups, labels, auto-replies, and webhooks. The README documents more than 109 endpoints and includes a Swagger interface at /docs. Recurring schedules can run every set number of minutes or hours, on selected weekdays, or from a cron expression. Media-only scheduled messages and replies arrived in v1.6.3. An n8n community package adds action and trigger nodes for teams already using that workflow runner.
A broad API does not prove message delivery
The feature list reaches beyond a simple send endpoint. You can register event callbacks, apply session-level settings, restrict commands through allowlists and blocklists, and use roles for super administrators, owners, and staff. Broadcasts add randomized delays and batching. Those are useful controls, but the phrase "sent" still needs an application-level meaning: accepted by the local gateway, accepted upstream, or received by the destination are three different states.
Open issue 90 supplies the uncomfortable example. A user on v1.6.3 reported two broadcast attempts that the interface marked as sent, while neither recipient received a message. That report does not establish a failure rate, and our sandbox did not connect a WhatsApp account. It does show why a business should run delivery probes with its own number formats and message types before trusting campaign totals. The README separately warns against using its status-update endpoint in production because text styling and media upload can fail.
What happened when we ran it
Our run checked commit c7dd01a in a fresh unprivileged container with 3 CPUs and 8 GB of RAM. Npm installed 1,343 packages in 105 seconds and occupied 1,197 MB. The production build completed successfully in 87 seconds. The 4.7 MB checkout contained 274 files and about 32,052 lines of source, so most of the local footprint arrived through dependencies rather than the application code.
There was no test script or target, so the lab skipped tests rather than manufacturing a command. Our scan also found no tests directory and no CI workflow files. Npm audit reported 58 known vulnerabilities: 5 critical, 22 high, 29 moderate, and 2 low. We did not determine exploitability from the totals alone, but 27 critical or high findings deserve package-level triage before the API is exposed to the internet.
Production needs a database, durable state, and changed defaults
The shortest manual route still has several moving parts. WA-AKG needs MySQL or PostgreSQL, a Prisma schema push, a generated admin account, and an authentication secret. Public URL values must agree when the app sits behind a reverse proxy. Each WhatsApp account then needs QR pairing. Uploaded media defaults to a project-relative directory, while scheduled campaigns use the configured timezone. Lose the session or media volumes and the gateway does not behave like the server you thought you backed up.
The environment guide sets a 24-hour login session, a 50 MB upload limit, and 60 requests per minute by default. Swagger is enabled with admin and admin123 shown as the example credentials, and the docs explicitly tell operators to change them. The remove.bg integration needs a separate API key only if automatic sticker background removal is used. Otherwise, the central secrets are the database connection, authentication secret, API keys issued by the app, and administrator password.
Docker exists, but two open reports weaken the easy path
The repository includes a multi-stage Dockerfile and a Compose file that starts the application beside MySQL 8.0. Named volumes preserve database, application, and upload data. The container starts by pushing the Prisma schema and can create an administrator from environment values. There is also a PM2 route and a start.sh helper for dependency installation, configuration checks, build, database setup, and process startup. On paper, both deployment choices are unusually well documented for a project this size.
Open issues make the container path less settled. Issue 88 says docker build . after a fresh clone failed unless the reporter first ran npm install on the host. Issue 61 reports a container that repeatedly failed to start. Neither report includes enough log detail for us to name a cause. Our successful 87-second application build does not resolve them because the lab did not run the Docker image. A first evaluation should build and restart the exact deployment form you plan to keep.
No test target is the main maturity limit
The missing test command matters because WA-AKG touches authentication, message routing, scheduled work, file uploads, database mutations, and external callbacks. A TypeScript build can catch type and bundling errors. It cannot prove that a recurring job fires once, a webhook retries safely, an allowlist blocks the right sender, or a broadcast status matches delivery. With no repository test target and no CI workflow, an adopter inherits the work of creating smoke checks for those paths.
GitHub showed 401 stars and 10 open issues and pull requests on October 2, 2026. The API split that queue into 5 issues and 5 pull requests. The last push was September 21, while v1.6.3 shipped June 30 with recurring schedules, media-only messages, deployment scripting, and an MIT license. That activity is current enough to justify a trial. The decision turns on risk tolerance: our 87-second build passed, but 58 audit findings, no tests, and an unresolved delivery report make monitored internal use a better fit than an unattended customer channel.

