API access, app setup, and permissions
Meta API access is not one universal switch. The required app, business, permission, token, review, and access level depend on the product and whether you are using your own assets or serving other businesses.
Direct access for your own business
- Create a developer account and app: use Meta’s current app-creation flow and choose the use case that matches the product.
- Connect the business: connect the app to the Business Portfolio that owns or manages the assets.
- Add products and permissions: request only the API products and scopes needed for the endpoints you will use.
- Create controlled credentials: use a system user and server-side token for automation; never put app secrets or tokens in browser code.
- Test and review: test with owned assets, then request Advanced Access/App Review when serving people or businesses outside app roles.
WhatsApp permissions and tokens
Manage or read WABA metadata, phone numbers, templates, analytics, and relevant non-message account webhooks.
Send messages and receive incoming-message or message-status webhook events.
Use only when the application genuinely needs to manage Business Portfolio resources programmatically.
Embedded Signup returns a customer-scoped code that the server exchanges for the business integration system-user token used for the customer’s assets.
Embedded Signup v4 flow
For a provider onboarding another business, the customer authenticates with Meta, selects or creates eligible business assets, and returns the WABA ID, phone-number ID, and exchangeable code. The server exchanges the code, registers or validates the phone, subscribes the app to WABA webhooks, and completes the configured integration.
Standard and Advanced Access
Standard Access generally supports development with app roles and assets owned or managed by the business. Advanced Access is required for many production use cases involving people or businesses outside app roles and must be approved for the relevant permission or feature. Business Verification and App Review are separate processes.
App Review and Business Verification
- Write a precise justification for every requested permission.
- Provide a working reviewer path and screen recording where requested.
- Demonstrate the complete user value, not only an API call.
- Keep privacy policy, data handling, domains, and contact details current.
- Complete Business Verification when serving other businesses requires it.
- Request no permissions that the product does not use.
Webhooks and production operations
Configure an HTTPS endpoint, verify the challenge, subscribe only to required fields, validate signatures, acknowledge quickly, persist an event identifier, process asynchronously, and make event handling idempotent. WhatsApp events include messages, delivery/read/failure statuses, template changes, quality signals, and account or phone events.
Instagram and Marketing API access
Instagram access differs by login configuration: Facebook Login for Business commonly uses a Page-linked professional account, while Business Login for Instagram supports eligible professional accounts with an Instagram-only presence. Consumer accounts are not supported. Marketing API uses the hierarchy Campaign → Ad set → Creative → Ad; common permissions are ads_read and ads_management, with separate limited/full access requirements.
Rate limits and safe scaling
Limits differ by product, app, user, ad account, business use case, and endpoint. Read throttle headers, avoid bursts, queue work, use exponential backoff, respect retry estimates, and monitor errors. Never promise a fixed request-per-second number without checking the endpoint’s current Meta documentation.