Meta documentation / API access

API access, app setup, and permissions

Meta API access is not one universal switch. The required app, business, permission, token, review, and access level depend on the product and whether you are using your own assets or serving other businesses.

Use official documentation for the live requirement: Meta changes permissions, product versions, review requirements, and limits. This page is an implementation map, not an approval guarantee.

Direct access for your own business

  1. Create a developer account and app: use Meta’s current app-creation flow and choose the use case that matches the product.
  2. Connect the business: connect the app to the Business Portfolio that owns or manages the assets.
  3. Add products and permissions: request only the API products and scopes needed for the endpoints you will use.
  4. Create controlled credentials: use a system user and server-side token for automation; never put app secrets or tokens in browser code.
  5. Test and review: test with owned assets, then request Advanced Access/App Review when serving people or businesses outside app roles.

WhatsApp permissions and tokens

whatsapp_business_management

Manage or read WABA metadata, phone numbers, templates, analytics, and relevant non-message account webhooks.

whatsapp_business_messaging

Send messages and receive incoming-message or message-status webhook events.

business_management

Use only when the application genuinely needs to manage Business Portfolio resources programmatically.

Business integration token

Embedded Signup returns a customer-scoped code that the server exchanges for the business integration system-user token used for the customer’s assets.

Embedded Signup v4 flow

For a provider onboarding another business, the customer authenticates with Meta, selects or creates eligible business assets, and returns the WABA ID, phone-number ID, and exchangeable code. The server exchanges the code, registers or validates the phone, subscribes the app to WABA webhooks, and completes the configured integration.

Version note: Meta currently documents Embedded Signup v4 as the current version. Confirm the live version and migration dates in Meta’s official Embedded Signup versions documentation before release.

Standard and Advanced Access

Standard Access generally supports development with app roles and assets owned or managed by the business. Advanced Access is required for many production use cases involving people or businesses outside app roles and must be approved for the relevant permission or feature. Business Verification and App Review are separate processes.

App Review and Business Verification

  • Write a precise justification for every requested permission.
  • Provide a working reviewer path and screen recording where requested.
  • Demonstrate the complete user value, not only an API call.
  • Keep privacy policy, data handling, domains, and contact details current.
  • Complete Business Verification when serving other businesses requires it.
  • Request no permissions that the product does not use.

Webhooks and production operations

Configure an HTTPS endpoint, verify the challenge, subscribe only to required fields, validate signatures, acknowledge quickly, persist an event identifier, process asynchronously, and make event handling idempotent. WhatsApp events include messages, delivery/read/failure statuses, template changes, quality signals, and account or phone events.

Instagram and Marketing API access

Instagram access differs by login configuration: Facebook Login for Business commonly uses a Page-linked professional account, while Business Login for Instagram supports eligible professional accounts with an Instagram-only presence. Consumer accounts are not supported. Marketing API uses the hierarchy Campaign → Ad set → Creative → Ad; common permissions are ads_read and ads_management, with separate limited/full access requirements.

Rate limits and safe scaling

Limits differ by product, app, user, ad account, business use case, and endpoint. Read throttle headers, avoid bursts, queue work, use exponential backoff, respect retry estimates, and monitor errors. Never promise a fixed request-per-second number without checking the endpoint’s current Meta documentation.

Official Meta references