STRAX Reach · Omnichannel hubs
Vonage Messages API as a Reach channel
The Vonage Messages API reaches clients on several channels with one request shape. Reach uses it as a single channel and verifies every inbound call with Vonage's own signature.
- Messages API
- Signed webhook JWT
- Sandbox for staging
Signed inbound calls and one request shape
Vonage signs every Messages API webhook with a token in the Authorization header that carries a hash of the body. Reach checks the signature with your account signature secret and compares the hash, so a message cannot be altered on the way in.
Outbound messages use the same request for every channel, with the channel and sender chosen from the address and your settings. The Reach message id travels as the client reference, which ties a Vonage log entry to the Reach record.
Vonage bills and reports per channel inside one account, which makes it straightforward for finance to reconcile messaging spend against the Reach records of what was sent and why.
Staging can point at the Vonage Messages sandbox, where test handsets join by sending a keyword. Production switches to the live host with a settings change, without touching the workflows.
Where it helps
Wallet top-up confirmations
Confirm a wallet top-up on the client's preferred channel and handle any follow-up question from the same record.
Clients who change phones
A client who moves from SMS to WhatsApp keeps one history, because both identities belong to the same contact.
Safe rehearsal
Run the full two-way flow against the Vonage sandbox on staging before any real client sees a message.
What you need
-
A Vonage account
With a Messages API application and the senders for each channel you use.
-
Key, secret and signature secret
The API key and secret for sending and the signature secret for inbound checks, all in the STRAX credential vault.
-
A public HTTPS address
Set as the application's inbound URL.
-
Reach Core
Holds the contacts and conversations every hub channel shares.
Good to know
WhatsApp free text is accepted only within 24 hours of the client's last message. Check the WhatsApp and Viber inbound shapes against a live message before go-live.
Questions
Which senders do we configure?
One per channel you use: an SMS number or sender id, the WhatsApp number linked to your application, the Viber service id and the RCS agent id.
How does the address choose a channel?
It starts with sms, whatsapp, viber or rcs and a colon. A bare number uses the default channel setting.
What stops a forged webhook?
The signed token Vonage adds to every call: requests without a valid signature and a matching body hash are refused before any workflow runs.
Are delivery statuses recorded?
They are acknowledged and skipped in this version. Reach records whether Vonage accepted each send.
Read more
-
The whole Reach family →
Reach Core and every channel package, with what each one needs.
Add Vonage to Reach
Tell us which channels your clients use and we will plan the rollout with your team.
Premium Requires STRAX Reach - Core, which is licensed.
About this listing
| Version | 1.0.0 |
| Author | STRAX |
| Category | Communication |
| Published | 2026-09-24 |
What's inside
| Credential | 2 |
| Global variable | 6 |
| Workflow | 2 |
What happens on install
After the import, and only with your consent, the installer runs:
- Reach - Register Channel : Registers the Vonage channel with Reach Core, disabled until its credentials are entered
Free listing
Install it from Feature Marketplace inside STRAX
It builds on STRAX Reach - Core, a premium package. Ask us for a quote to license it first.
Open Feature Marketplace
In your STRAX installation, open Feature Marketplace from the navigation.
Find "STRAX Reach - Vonage"
Search or browse to this listing and review the contents disclosure; every package shows what it contains before anything runs.
Install
Choose Install, or "Customise with AI" to adapt the package to your environment first. No licence is needed for free listings.
Vonage, WhatsApp and Viber are trademarks of their owners, named here only to identify the service this package connects to.
See it on your own systems.
A demo takes an hour, on your data landscape rather than ours.


