WinZapp is a free, self-hosted, open-source desktop WhatsApp client for Windows, built primarily for accessibility for blind and low-vision users. It is designed from the ground up to work with screen readers (NVDA, JAWS, Narrator) through accessible-output2, with a fully keyboard-navigable interface built on plain wxPython controls rather than custom-drawn UI.
Only download WinZapp from this repository's Releases page: https://github.com/gabrielhhaber/WinZapp_Python/releases. Copies of WinZapp on other websites, file-sharing services or app stores are not ours, and we cannot vouch for what they contain.
Every release lists these files under "Assets":
- WinZappInstaller.exe: the installer. This is the right choice for most people.
- WinZapp.zip: the same program as a ZIP file. Extract it to a folder on a local disk and run
WinZapp.exefrom there. - SHA256SUMS.txt: the SHA-256 checksum of the two files above, used to check your download (see "Check your download").
- SHA256SUMS.txt.sig: a digital signature of the checksum file. It is present on newer releases (currently the alpha releases).
- Stable releases are made by hand and are the recommended choice. The newest one is marked "Latest" on the Releases page.
- Alpha releases are marked "Pre-release". They are built automatically from the
mainbranch for every change, they are not tested, and they may contain bugs. Their version numbers end in "alpha".
If you are not sure which to pick, download the release marked "Latest".
- Windows 10 or Windows 11, 64-bit. The bundled Node.js runtime is a 64-bit Windows build, and the code targets Windows 10 and 11. We have not published a tested list of older builds.
- An internet connection, and a WhatsApp account on your phone.
- A screen reader is optional. WinZapp works with NVDA, JAWS and Narrator.
- Download
WinZappInstaller.exefrom the Releases page. - Run it. By default it installs into
%LOCALAPPDATA%\WinZapp, which does not need administrator rights. You can choose another folder with the Browse button. - Two check boxes, both checked by default, create a desktop shortcut and a Start menu shortcut.
- Press Install, then start WinZapp.
The installer also registers an uninstaller, so you can remove WinZapp from Windows Settings, Apps. Install on a local disk: WinZapp cannot run from a network folder such as \\server\share.
The release includes the program and a portable Node.js runtime, so you do not need to install Node.js. It does not include the WPPConnect Server's own dependencies (the files that let WinZapp talk to WhatsApp Web). On first start WinZapp downloads and sets them up, including a browser component (Chromium) that it uses to reach WhatsApp Web. This needs an internet connection and shows a progress window. Starting the API for the first time can then take up to 3 minutes while its database is prepared; WinZapp tells you to wait. Later starts skip these steps.
On first start WinZapp asks you to connect your account. You have two choices:
- Connect with phone number: enter your number and WinZapp shows a pairing code. On your phone, open WhatsApp, Linked devices, Link a device, and choose to link with a phone number instead.
- Connect with QR code: scan the QR code with WhatsApp on your phone, under Linked devices.
WinZapp is a linked device, like WhatsApp Web. Your phone stays your main device.
WinZapp keeps everything next to the program, in a data folder: your accounts, message history, downloaded media and logs. With the installer that is %LOCALAPPDATA%\WinZapp\data. Back this folder up if you want to keep your history when moving to another computer.
WinZapp checks GitHub Releases for new versions and offers to download and install them. You can also choose Help, Check for updates. Every version of the updater checks the SHA-256 checksum of the download. Builds from the 2.0 line onward also require a valid signature and refuse a release that has none. The updater in the stable version 1.1.1.0 only checks the checksum, because signatures did not exist yet when it was built.
By default you only receive stable releases. To also receive alpha releases, check "Check for alpha updates (unstable)" in Settings, General tab.
Every release has a SHA256SUMS.txt file with one line per file: the checksum, then the file name. Newer releases start the file with a line beginning with #, such as # winzapp-version: 2.0.0.3904alpha; that is a comment, not a checksum, so ignore it. The signature file SHA256SUMS.txt.sig currently exists only on the alpha releases; the stable release 1.1.1.0 has none. To check a download in Windows PowerShell, run this in the folder where you saved the file, and compare the result with the line for that file in SHA256SUMS.txt:
Get-FileHash .\WinZappInstaller.exe -Algorithm SHA256The two values must be identical. If they differ, delete the file and download it again from the Releases page.
Be aware of the limits of this check. SHA256SUMS.txt is published on the same page as the files, so it protects you against a corrupted download, not against someone who can edit the release. For that reason newer releases (currently the alpha releases) are published as immutable, so they cannot be changed afterwards. Older stable releases, including the current "Latest" release, are not immutable. Builds from the 2.0 line onward also verify a signature made with keys that are not stored on GitHub. How this works is described in docs/traps/release-integrity.md. Checking the signature by hand is not something we document for users yet; the updater does it for you.
The repository contains a macOS version for VoiceOver users, described in macos/README.md. No official Mac builds are published from this repository yet. Whether and how to publish them is being discussed in issue 343. Until that is decided, please do not trust Mac downloads from other sources.
Report bugs and ask for features on GitHub Issues. Search the existing issues first. The bug form asks for your WinZapp version (Help, About the program) and your Windows version.
When you report a bug, attach log.log and, for anything about being asked to pair again or losing your session, also shutdown_audit.log. Both are in the logs folder of your account, under data\accounts\<account id>\logs inside the WinZapp folder. If you use several accounts, each has its own folder there; open the one with the most recently modified log.log. log.log is replaced every time WinZapp starts, so copy it before reopening the program. Remove phone numbers, names and messages from the files before you attach them.
- Built entirely from standard wx controls (
wx.ListCtrl,wx.TextCtrl, standard dialogs/menus) so screen readers read them reliably, instead of custom-drawn or owner-drawn UI. - List updates are batched so a screen reader receives one accessibility event per change instead of a flood during bulk updates (e.g. syncing history).
- Dialog titles and list items resolve to human-readable contact/group names rather than raw phone numbers or WhatsApp JIDs.
- Playback controls for voice notes directly inside the conversation view.
- Text, voice notes, images, videos, documents, contacts, replies/quotes, @mentions, reactions, message edits and deletes, read receipts, and typing/recording indicators.
- Local message history stored in a SQLite database (
messages.db) whose message contents are encrypted, with a background-managed connection so the UI never blocks on disk I/O. - Outgoing sends go through a background queue with automatic retry and duplicate-delivery protection for ambiguous network failures.
WhatsApp uses several different identifier formats for the same contact (@s.whatsapp.net, the legacy @c.us, and @lid for linked/multi-device identities). WinZapp normalizes these to a single canonical form per contact, bridges @lid identities to phone numbers as they are resolved, and handles the Brazilian 8/9-digit mobile number variants transparently.
- Checks GitHub Releases for new versions and can download and install updates automatically.
- Before overwriting files, it stops any stray WPPConnect Server (port 6300) or PostgreSQL (port 5433) processes still holding a lock on them.
- The WhatsApp session token and local message payloads are encrypted at rest with a per-install Fernet key.
- Downloaded release assets and the portable Node.js runtime are checksum-verified before use.
The application is split into two processes that run together locally:
- Client (Python 3.13 + wxPython): all UI, business logic, local storage, notifications, and sounds.
- WPPConnect Server (Node.js): a locally-run WhatsApp Web automation gateway, built from the upstream wppconnect-team/wppconnect-server project with a small set of patches WinZapp maintains on top. The client talks to it over local HTTP (
http://127.0.0.1:6300/api/...) and Socket.IO.
Instructions for running WinZapp from source, running the tests and building the installer are in docs/DEVELOPMENT.md. Contribution rules (where code goes, tests, translations) are in CLAUDE.md.
WinZapp is licensed under the GNU General Public License, version 3 or, at your option, any later version (GPL-3.0-or-later; see LICENSE). It works by automating the WhatsApp Web interface and is not built on any official WhatsApp/Meta API. Use of this software is at your own risk. This project is not affiliated with, maintained by, or endorsed by Meta Platforms, Inc.