WhatsApp Business Platform

Cloud API and messaging

Design reliable business messaging around authenticated server-side calls, webhooks, customer opt-in, approved templates, and clear support ownership.

WABA and phone setup

  1. Confirm the connected WABA is the client's intended business asset and record its owner and administrator.
  2. Choose a phone number that meets current Meta onboarding rules. Confirm country, display name, verification-code access, and whether it is registered elsewhere.
  3. Register the number through the supported Meta flow, complete verification, and wait for the displayed status before production traffic.
  4. Record phone number ID, WABA ID, quality/limit signals, timezone, and support owner in a restricted configuration record—not frontend code.

Capability map

Messages

Send supported message types from the server and handle API responses without exposing credentials.

Templates

Create truthful, policy-aware templates and track approval, quality, category, and state.

Webhooks

Receive inbound messages, delivery, read, account, capability, and template-related events.

Operations

Track failures, retries, rate limits, opt-outs, incidents, and escalation context.

Templates: submit, test, and operate

  1. Write the customer journey, language, category, variables, opt-in source, and opt-out wording.
  2. Use clear, truthful copy with stable placeholders. Do not disguise promotional content or imply approval.
  3. Submit through the current Meta interface/API and save name, language, category, and status.
  4. Wait for Meta's result. If rejected, read the reason, revise the use case/copy, and resubmit after addressing it.
  5. Test approved templates with a controlled recipient, realistic variables, delivery/read events, failures, and opt-out handling.
  6. Monitor quality and status changes; pause or replace templates that create complaints or unexpected delivery behavior.

Webhook setup and verification

  1. Expose an HTTPS callback endpoint with a server-side verify token and secret app configuration.
  2. Implement Meta's verification challenge exactly, then subscribe only to needed fields.
  3. Validate the request signature using the raw body and app secret before parsing or queuing.
  4. Return a fast success response, persist an event ID, and process asynchronously with idempotency and bounded retries.
  5. Send a test event and confirm logs contain redacted event ID, timestamp, type, result, and correlation ID.

Webhook event groups

GroupOperational useDesign note
messagesInbound messages and status updates.Deduplicate event IDs and preserve ordering assumptions.
account updatesChanges affecting a connected WABA.Notify the responsible operator and re-check access.
business capabilityCapability or eligibility signals.Do not assume a capability remains available.
template statusApproval, rejection, quality, or state changes.Use current status before sending a template.

Production checklist

  • Keep tokens and app credentials on the server.
  • Verify webhook signatures and use HTTPS.
  • Make event processing idempotent and retry safely.
  • Collect lawful opt-in and provide an opt-out path.
  • Redact message content and identifiers in logs.
  • Do not claim approval until Meta confirms it.
  • Define rollback, revoke, incident owner, monitoring, and alerting.