Developer reference
Build securely from day one
The public portal explains the integration. Your private backend should own credentials, business identifiers, event processing, and audit trails.
Token and credential boundaries
- The browser may start a hosted Meta flow, but must not receive app secrets, long-lived tokens, system-user tokens, or private client identifiers.
- The backend exchanges and stores credentials in server-side secret storage with least-privilege access, rotation, expiry, and revocation ownership.
- Use separate development, staging, and production credentials/endpoints. Never copy production tokens into screenshots, issues, or chat.
- Return only the minimum safe result to the browser; keep raw provider responses and credential metadata restricted and redacted.
Webhook verification runbook
- Verify the challenge with the configured verify token.
- Read raw request bytes, calculate the expected signature with the app secret, and compare in constant time.
- Reject missing, malformed, stale, or invalid signatures before parsing or queuing.
- Persist an idempotency key/event ID, acknowledge quickly, and process with a retry-safe queue.
- Alert on signature failures, event spikes, repeated retries, and dead-letter items.
Testing matrix
- Verify webhook challenge and signature handling.
- Send controlled test messages and confirm delivery status events.
- Test duplicate events, retries, timeouts, invalid payloads, and revoked access.
- Confirm templates, opt-out handling, and escalation ownership.
- Remove test identifiers from production logs and screenshots.
Production checklist
- HTTPS, signature validation, rate limits, and bounded retries.
- Structured logs with event IDs—not private message content by default.
- Separate environments, secret rotation, and documented revocation.
- Monitoring for auth errors, webhook failures, queue backlog, and API limits.
- Incident owner, rollback path, support runbook, and client handoff.
- Redacted evidence only in support requests.
Reference links
Meta WhatsApp Cloud API documentation
Meta Marketing API overview