Connect your application, CRM or website to the WhatsApp Business Platform properly: verified webhooks, approved templates, secure tokens, reliable delivery tracking, and backend logic that does something useful with every message.
POST https://graph.facebook.com/<API_VERSION>/<PHONE_NUMBER_ID>/messages
Authorization: Bearer <ACCESS_TOKEN>
{
"messaging_product": "whatsapp",
"to": "91…",
"type": "template",
"template": {
"name": "booking_confirmation",
"language": { "code": "en" },
"components": [{ "type": "body", "parameters": [
{ "type": "text", "text": "Meera" },
{ "type": "text", "text": "Sat 12 Dec, 4:30 pm" }
]}]
}
}
→ 200 { "messages": [{ "id": "wamid.…" }] }The Cloud API is Meta’s hosted interface to the WhatsApp Business Platform. It lets software, not a person on a phone, send and receive WhatsApp messages for a business.
There is no WhatsApp server for you to run. Your software talks to Meta over HTTPS, and Meta takes care of delivery to the customer’s phone.
You call the API to send messages. Meta calls your webhook, an HTTPS address on your server, to tell you about incoming messages and delivery statuses.
Customers must opt in, replies are free-form only inside a 24-hour window, and everything else goes through approved templates. Good integrations are designed around those rules.
| WhatsApp Business app | WhatsApp Cloud API | |
|---|---|---|
| Built for | A small business answering chats by hand on a phone | Businesses that want software to send, receive and act on messages |
| Automation | Greeting, away message and quick replies | Any logic your backend can run: bookings, tokens, CRM updates, reminders |
| Your own software | Not connected | Two-way: webhooks into your system, REST calls out of it |
| Team | One phone and a few linked devices | Any number of agents, through a dashboard or inbox you control |
| Starting a conversation | Free-form messages, within WhatsApp’s spam limits | Pre-approved templates, to customers who have opted in |
| Cost | The app is free | Meta charges per template message by category and country; development is separate |
The part most integrations get wrong is not sending a message. It is receiving one reliably, exactly once, and doing the right thing with it.
Customer messages you
Text, button tap, image or location
Meta posts to your webhook
A signed HTTPS request
Signature verified, 200 returned
Fast, before any processing
Event queued
So a spike never loses a message
Worker de-duplicates
On the message ID, so a retry is harmless
Business logic runs
Rules, state, records, alerts
Reply sent, status tracked
Free-form or template; sent → delivered → read
// 1. One-time verification when you register the webhook (GET)
if (query["hub.mode"] === "subscribe" && query["hub.verify_token"] === VERIFY_TOKEN) {
return reply(200, query["hub.challenge"]);
}
// 2. Every event after that (POST): check the signature, answer fast, work later
const expected = "sha256=" + hmacSha256(APP_SECRET, rawBody);
if (!timingSafeEqual(expected, headers["x-hub-signature-256"])) return reply(401);
reply(200); // acknowledge immediately
queue.add("whatsapp.event", JSON.parse(rawBody)); // a worker does the real processing{
"object": "whatsapp_business_account",
"entry": [{ "changes": [{ "field": "messages", "value": {
"metadata": { "phone_number_id": "<PHONE_NUMBER_ID>" },
"contacts": [{ "profile": { "name": "Meera" }, "wa_id": "91…" }],
"messages": [{
"from": "91…",
"id": "wamid.…", // de-duplicate on this
"type": "interactive",
"interactive": { "type": "button_reply", "button_reply": { "id": "reschedule", "title": "Reschedule" } }
}]
}}]}]
}{
"entry": [{ "changes": [{ "field": "messages", "value": {
"statuses": [{
"id": "wamid.…", // the message you sent
"status": "delivered", // sent · delivered · read · failed
"timestamp": "…",
"recipient_id": "91…"
// on "failed": an errors[] entry explains why
}]
}}]}]
}Shortened for readability; real payloads carry more fields.
Nine pieces that together make an integration you can rely on and hand to your own team.
An HTTPS endpoint that verifies Meta’s signature, acknowledges at once and hands the event to a queue.
Drafting, categorising and submitting the templates your workflows need, with variables and buttons.
Access tokens and the app secret kept server-side, rotated safely, never exposed to a browser.
Free-form replies inside the 24-hour window and template messages outside it, with retries on failure.
Sent, delivered, read and failed statuses stored per message, with alerts when something does not arrive.
The conversation state and rules that decide what each message does in your system.
Contacts, conversations, messages and consent records in your database, ready for reporting.
Where your team reads, replies and takes over from the bot, when the project calls for it.
How it works, how to operate it and where everything lives. You own the code.
WhatsApp is strict about who may message whom, and when. We design each workflow inside those rules, so your number stays healthy.
When a customer messages you, a 24-hour window opens in which you can reply freely. After it closes, only approved templates can be sent.
Every send chooses between free-form and template automatically, and the dashboard shows how long each window has left.
Businesses need a customer’s permission before messaging them on WhatsApp.
Opt-in is captured and stored with its source and time, and “stop” requests are honoured everywhere.
Templates are reviewed by WhatsApp and belong to a category (utility, marketing or authentication), which affects the rules and the price.
Templates are written for the right category, versioned, and rejected ones are reworked rather than worked around.
WhatsApp rates your messages by how customers react, and limits how many customers you can start conversations with each day.
Volumes are paced, and complaint and block signals are watched so one bad campaign cannot cost you the number.
Verifying the business with Meta and getting a display name approved unlock higher limits and some features.
We prepare the documents and details you need, so the review is not the part that stalls the project.
Meta bills template messages by category and destination country; replies inside the customer service window do not carry a Meta charge. Meta updates its rates from time to time.
We model your expected volume against the current rates before you commit.
Meta’s policies and pricing change from time to time. We check the current rules with you at the start of every project.
From you
From us
No. You can integrate with the Cloud API directly through Meta, which is how we build. A third-party platform can be useful if you want a ready-made shared inbox, but it is not a requirement, and going direct gives you full control of your data and your logic.
Usually yes, but not without a decision. A number that is currently used in the WhatsApp or WhatsApp Business app generally has to be moved to the API, and the way chat history and parallel app use are handled has been changing, so we check Meta’s current options with you before registering anything. A fresh number is the simplest route.
Template reviews are often quick, but neither they nor business verification come with a guaranteed time, and both are outside our control. We start them early and plan the project around them rather than at the end.
Meta bills template messages by category and destination country, and replies inside the 24-hour customer service window do not carry a Meta charge. Rates change from time to time, so we work from Meta’s current pricing when we estimate your volume. Our development fee is separate from Meta’s message charges.
On infrastructure you choose: your own cloud or server, or one we set up for you. You own the code, the database and the deployment, and we document how it runs.
Messages are encrypted in transit, and we keep tokens and secrets on the server, verify every webhook signature, restrict who can read conversations and log access. Because the Cloud API is hosted by Meta, we advise against collecting passwords or highly sensitive data in chat, and we design the flow so that anything sensitive moves to a secure page instead.
Yes. A single backend can manage several numbers, route each customer to the right branch or team and keep their data separate, with its own templates and dashboards where you need them.
Yes. We can review what you have: webhook verification, retries, duplicate handling, token storage and template use. We tell you plainly whether it is worth repairing or better rebuilt.
Tell us what your software does today and what you want WhatsApp to trigger. We will say how we would connect it, and what to watch out for.
WhatsApp is a trademark of Meta Platforms, Inc. Stack Bridge Labs is an independent software company and is not affiliated with, endorsed by or sponsored by WhatsApp or Meta. Conversations, names, numbers and templates shown on this page are fictional examples.