WhatsApp Business Platform
Cloud API and messaging
Design reliable business messaging around authenticated server-side calls, webhooks, customer opt-in, approved templates, and clear support ownership.
WABA and phone setup
- Confirm the connected WABA is the client's intended business asset and record its owner and administrator.
- Choose a phone number that meets current Meta onboarding rules. Confirm country, display name, verification-code access, and whether it is registered elsewhere.
- Register the number through the supported Meta flow, complete verification, and wait for the displayed status before production traffic.
- Record phone number ID, WABA ID, quality/limit signals, timezone, and support owner in a restricted configuration record—not frontend code.
Capability map
Messages
Send supported message types from the server and handle API responses without exposing credentials.
Templates
Create truthful, policy-aware templates and track approval, quality, category, and state.
Webhooks
Receive inbound messages, delivery, read, account, capability, and template-related events.
Operations
Track failures, retries, rate limits, opt-outs, incidents, and escalation context.
Templates: submit, test, and operate
- Write the customer journey, language, category, variables, opt-in source, and opt-out wording.
- Use clear, truthful copy with stable placeholders. Do not disguise promotional content or imply approval.
- Submit through the current Meta interface/API and save name, language, category, and status.
- Wait for Meta's result. If rejected, read the reason, revise the use case/copy, and resubmit after addressing it.
- Test approved templates with a controlled recipient, realistic variables, delivery/read events, failures, and opt-out handling.
- Monitor quality and status changes; pause or replace templates that create complaints or unexpected delivery behavior.
Webhook setup and verification
- Expose an HTTPS callback endpoint with a server-side verify token and secret app configuration.
- Implement Meta's verification challenge exactly, then subscribe only to needed fields.
- Validate the request signature using the raw body and app secret before parsing or queuing.
- Return a fast success response, persist an event ID, and process asynchronously with idempotency and bounded retries.
- Send a test event and confirm logs contain redacted event ID, timestamp, type, result, and correlation ID.
Webhook event groups
| Group | Operational use | Design note |
|---|---|---|
| messages | Inbound messages and status updates. | Deduplicate event IDs and preserve ordering assumptions. |
| account updates | Changes affecting a connected WABA. | Notify the responsible operator and re-check access. |
| business capability | Capability or eligibility signals. | Do not assume a capability remains available. |
| template status | Approval, rejection, quality, or state changes. | Use current status before sending a template. |
Production checklist
- Keep tokens and app credentials on the server.
- Verify webhook signatures and use HTTPS.
- Make event processing idempotent and retry safely.
- Collect lawful opt-in and provide an opt-out path.
- Redact message content and identifiers in logs.
- Do not claim approval until Meta confirms it.
- Define rollback, revoke, incident owner, monitoring, and alerting.