Viber Chatbot Development: Registration, Webhook, Rich Media & Deployment
Many teams confuse Viber Public Account and Bot API when starting automation, picking the wrong account type. They waste time on bureaucracy or hit Bot API limitations despite Rich Media and Keyboard capabilities. Choosing correctly from the start saves up to 2 weeks of development.
Another frequent issue is a webhook without signature validation. Without HMAC verification, an attacker can send a forged message on behalf of a user. We always implement X-Viber-Content-Signature verification to eliminate this attack vector entirely.
Why Viber Bot API Is Better for Automation
Viber Bot API is registered via developers.viber.com for free, no contract or moderation required. You get an auth_token within minutes and can immediately set the webhook. Unlike Public Account, there are no strict content requirements — you decide what messages to send.
Key differences:
| Criteria | Viber Bot | Viber Public Account |
|---|---|---|
| Registration | Self-service, free | Via partners, paid |
| Webhook | Yes | Yes |
| Rich Media | Yes | Yes |
| Mass messaging | Only subscribed | Subscribed + segments |
| Moderation | No | Yes, strict |
| Launch time | 1 day | 2–4 weeks |
How to Set Up Webhook and Ensure Security
Creating a bot is done through the Viber Admin Panel. After creation, an auth_token is issued — used in every API request in the X-Viber-Auth-Token header. The webhook is set via a single POST request:
import requests
def set_webhook(url: str, auth_token: str):
response = requests.post(
"https://chatapi.viber.com/pa/set_webhook",
headers={"X-Viber-Auth-Token": auth_token},
json={
"url": url,
"event_types": [
"delivered", "seen", "failed",
"subscribed", "unsubscribed",
"conversation_started", "message"
],
"send_name": True,
"send_photo": True
}
)
return response.json() # {"status": 0, "status_message": "ok"}
Viber confirms the webhook immediately in the response to set_webhook — no separate verification challenge like in WhatsApp/Meta. This simplifies integration.
Webhook Security
Webhook security is achieved by verifying the signature of each incoming request. Viber sends the header X-Viber-Content-Signature, which contains HMAC-SHA256 of the request body with the auth_token as the key.
import hmac, hashlib
def verify_viber_signature(body: bytes, signature: str, auth_token: str) -> bool:
expected = hmac.new(
auth_token.encode(),
body,
hashlib.sha256
).hexdigest()
return hmac.compare_digest(expected, signature)
Without this check, your webhook can accept fake messages from third parties. We implement signature verification at the middleware level in all projects.
Common Webhook Setup Mistakes
- Using HTTP instead of HTTPS — Viber rejects insecure URLs.
- Ignoring X-Viber-Content-Signature — the bot becomes vulnerable.
- Wrong auth_token — ensure the token is from the Admin Panel, not from a Public Account.
- Missing conversation_started handling — the bot cannot greet new users.
- Mass messaging to non-subscribers — Viber blocks the account.
What Message Types Does Viber Support?
Viber supports: text, picture, video, file, sticker, contact, url, location, and rich_media. Rich Media is a custom carousel format with buttons, images, and titles. Rich Media is specific to Viber — no direct analog in Telegram. Ideal for product catalogs, news, and service cards.
Example of sending Rich Media:
def send_rich_media(receiver: str, auth_token: str, items: list):
rich_media = {
"Type": "rich_media",
"ButtonsGroupColumns": 6,
"ButtonsGroupRows": 7,
"BgColor": "#FFFFFF",
"Buttons": []
}
for item in items:
rich_media["Buttons"].extend([
{
"Columns": 6, "Rows": 3,
"ActionType": "open-url",
"ActionBody": item["url"],
"Image": item["image_url"]
},
{
"Columns": 6, "Rows": 1,
"Text": f"<b>{item['title']}</b>",
"ActionType": "none"
},
{
"Columns": 3, "Rows": 1,
"Text": "Learn more",
"ActionType": "open-url",
"ActionBody": item["url"],
"BgColor": "#2db5f5"
}
])
requests.post(
"https://chatapi.viber.com/pa/send_message",
headers={"X-Viber-Auth-Token": auth_token},
json={"receiver": receiver, "type": "rich_media", "rich_media": rich_media}
)
Keyboard and One-Time Buttons
Viber Keyboard is a custom keyboard at the bottom of the screen. min_api_version: 1 for basic buttons:
keyboard = {
"Type": "keyboard",
"DefaultHeight": True,
"BgColor": "#FFFFFF",
"Buttons": [
{
"Columns": 3, "Rows": 1,
"Text": "Catalog",
"ActionType": "reply",
"ActionBody": "catalog",
"BgColor": "#f5f5f5"
},
{
"Columns": 3, "Rows": 1,
"Text": "Support",
"ActionType": "reply",
"ActionBody": "support",
"BgColor": "#f5f5f5"
}
]
}
The keyboard is sent with each message — it does not "stick" like in Telegram. Standard pattern: attach a keyboard to every bot response.
conversation_started Event
conversation_started — the user opens the chat with the bot for the first time or via a deep link. This is the only moment when you can send a welcome message to an unsubscribed user. After that, the user must write (subscribe) before the bot can send messages.
Limitation: Viber does not allow mass messaging to unsubscribed users — only to those who have subscribed (event subscribed).
Error Handling and Retries
When sending messages, Viber returns a failed status in the webhook. It is crucial to set up retry logic with exponential backoff. We use Redis to store the message queue and retry sending up to 3 times with delays of 5, 30, and 120 seconds. This boosts deliverability to 99.8%.
What's Included in Viber Bot Development
When ordering turnkey Viber bot development, you get:
- Registration and bot setup in Viber Admin Panel
- Webhook installation with signature verification
- Handling of all events (message, conversation_started, subscribed, unsubscribed)
- Rich Media / Keyboard implementation according to your design
- Dialog scenarios with state management (Redis FSM)
- Integration with your CRM or backend systems
- Bot API documentation and access credentials
- Post-launch support (2 weeks free)
We have been developing mobile solutions for over 6 years — we have completed more than 30 projects on Viber, Telegram, and WhatsApp. Our engineers are certified in Swift and Kotlin, ensuring high code quality. Every bot undergoes load testing before release. We provide a 3-month warranty on bot operation after launch.
"On Viber, we built a catalog bot with Rich Media — conversion to purchase increased by 25% in the first week" — client feedback.
Timeline Estimates
| Bot Type | Timeline |
|---|---|
| Simple information bot with keyboard and text | 1–2 weeks |
| Bot with Rich Media and basic FSM | 2–4 weeks |
| Full bot with CRM integration and analytics | 4–7 weeks |
Cost is calculated individually based on complexity and integrations. Contact us — we'll evaluate your project within 1 business day. Reach out for a consultation on your project.







