# WhatsApp templates (submit for approval in Meta Business Manager, or create in Caresoft's WhatsApp platform)

Create each template in English (`en`), Hindi (`hi`) and Marathi (`mr`) under the same name. Names are editable per hospital in the console.

| Name | Category | Body (English) | Variables |
|---|---|---|---|
| `ck_token_confirm` | Utility | Hello {{1}}, you are registered. Your token is *{{2}}* for {{3}} at {{4}}. Please wait for your token on the display. | name, token, department, hospital |
| `ck_token_called` | Utility | {{1}}, it's your turn. Token *{{2}}* — please come to {{3}} now. | name, token, department |
| `ck_otp` | Authentication | *{{1}}* is your verification code. For your security, do not share this code. (copy-code button) | code |

Hindi example (`ck_token_confirm`, hi): नमस्ते {{1}}, आपका पंजीकरण हो गया है। {{4}} में {{3}} के लिए आपका टोकन *{{2}}* है। कृपया डिस्प्ले पर अपने टोकन का इंतज़ार करें।

Marathi example (`ck_token_confirm`, mr): नमस्कार {{1}}, तुमची नोंदणी झाली आहे. {{4}} मध्ये {{3}} साठी तुमचा टोकन *{{2}}* आहे. कृपया डिस्प्लेवर तुमच्या टोकनची वाट पाहा.

## Webhook provider (Caresoft WhatsApp platform)
CareKiosk POSTs:
```json
{"kind":"token","to":"919819012345","template":"ck_token_confirm","lang":"hi","params":["Sunita More","ABH-001","General Medicine","City Care Hospital"],"tenant":"citycare","ref":42}
```
with `X-CK-Timestamp` and `X-CK-Signature = hex HMAC-SHA256(secret, ts + "." + body)`. Reply 2xx (optionally `{"id":"<message id>"}`) on acceptance.

## Consent rules (enforced in code)
* `token` / `called`: sent only if the patient's latest choice for **"Visit updates on WhatsApp and SMS"** is *granted*. Re-checked at send time, so a withdrawal stops queued messages.
* `otp`: sent only when a returning patient asks for it at the kiosk, and only to numbers already registered at that hospital.
