STRAX Reach · Omnichannel hubs

Vonage Messages API as a Reach channel

The Vonage Messages API reaches clients on several channels with one request shape. Reach uses it as a single channel and verifies every inbound call with Vonage's own signature.

Part of Reach
  • Messages API
  • Signed webhook JWT
  • Sandbox for staging

Signed inbound calls and one request shape

Vonage signs every Messages API webhook with a token in the Authorization header that carries a hash of the body. Reach checks the signature with your account signature secret and compares the hash, so a message cannot be altered on the way in.

Outbound messages use the same request for every channel, with the channel and sender chosen from the address and your settings. The Reach message id travels as the client reference, which ties a Vonage log entry to the Reach record.

Vonage bills and reports per channel inside one account, which makes it straightforward for finance to reconcile messaging spend against the Reach records of what was sent and why.

Staging can point at the Vonage Messages sandbox, where test handsets join by sending a keyword. Production switches to the live host with a settings change, without touching the workflows.

Where it helps

Wallet top-up confirmations

Confirm a wallet top-up on the client's preferred channel and handle any follow-up question from the same record.

Clients who change phones

A client who moves from SMS to WhatsApp keeps one history, because both identities belong to the same contact.

Safe rehearsal

Run the full two-way flow against the Vonage sandbox on staging before any real client sees a message.

What you need

  • A Vonage account

    With a Messages API application and the senders for each channel you use.

  • Key, secret and signature secret

    The API key and secret for sending and the signature secret for inbound checks, all in the STRAX credential vault.

  • A public HTTPS address

    Set as the application's inbound URL.

  • Reach Core

    Holds the contacts and conversations every hub channel shares.

Good to know

WhatsApp free text is accepted only within 24 hours of the client's last message. Check the WhatsApp and Viber inbound shapes against a live message before go-live.

Questions

Which senders do we configure?

One per channel you use: an SMS number or sender id, the WhatsApp number linked to your application, the Viber service id and the RCS agent id.

How does the address choose a channel?

It starts with sms, whatsapp, viber or rcs and a colon. A bare number uses the default channel setting.

What stops a forged webhook?

The signed token Vonage adds to every call: requests without a valid signature and a matching body hash are refused before any workflow runs.

Are delivery statuses recorded?

They are acknowledged and skipped in this version. Reach records whether Vonage accepted each send.

Read more

Add Vonage to Reach

Tell us which channels your clients use and we will plan the rollout with your team.

Premium Requires STRAX Reach - Core, which is licensed.

About this listing

Version1.0.0
AuthorSTRAX
CategoryCommunication
Published2026-09-24

What's inside

Credential 2
Global variable 6
Workflow 2

What happens on install

After the import, and only with your consent, the installer runs:

  • Reach - Register Channel : Registers the Vonage channel with Reach Core, disabled until its credentials are entered
Security screening. This bundle carries executable workflow steps. These flags are recomputed server-side from the actual package contents (they are never taken from the author), and STRAX asks for your explicit consent before installing executable content.

Free listing

Install it from Feature Marketplace inside STRAX

It builds on STRAX Reach - Core, a premium package. Ask us for a quote to license it first.

Open Feature Marketplace

In your STRAX installation, open Feature Marketplace from the navigation.

Find "STRAX Reach - Vonage"

Search or browse to this listing and review the contents disclosure; every package shows what it contains before anything runs.

Install

Choose Install, or "Customise with AI" to adapt the package to your environment first. No licence is needed for free listings.

Back to the catalogue →

See it on your own systems.

A demo takes an hour, on your data landscape rather than ours.