Meta WhatsApp Cloud API

WhatsApp Cloud API Integration for Your Software

Connect your application, CRM or website to the WhatsApp Business Platform properly: verified webhooks, approved templates, secure tokens, reliable delivery tracking, and backend logic that does something useful with every message.

  • Direct integration with Meta’s Cloud API
  • Webhook signatures verified, events de-duplicated
  • You own the code, the data and the deployment
Send a template message (simplified)
POST https://graph.facebook.com/<API_VERSION>/<PHONE_NUMBER_ID>/messages
Authorization: Bearer <ACCESS_TOKEN>

{
  "messaging_product": "whatsapp",
  "to": "91…",
  "type": "template",
  "template": {
    "name": "booking_confirmation",
    "language": { "code": "en" },
    "components": [{ "type": "body", "parameters": [
      { "type": "text", "text": "Meera" },
      { "type": "text", "text": "Sat 12 Dec, 4:30 pm" }
    ]}]
  }
}

→ 200  { "messages": [{ "id": "wamid.…" }] }
  • Webhook verified
  • Signature checked
  • Template approved
  • Status: delivered
The basics

What the WhatsApp Cloud API is, and what it is not

The Cloud API is Meta’s hosted interface to the WhatsApp Business Platform. It lets software, not a person on a phone, send and receive WhatsApp messages for a business.

Hosted by Meta

There is no WhatsApp server for you to run. Your software talks to Meta over HTTPS, and Meta takes care of delivery to the customer’s phone.

Two directions

You call the API to send messages. Meta calls your webhook, an HTTPS address on your server, to tell you about incoming messages and delivery statuses.

A platform with rules

Customers must opt in, replies are free-form only inside a 24-hour window, and everything else goes through approved templates. Good integrations are designed around those rules.

WhatsApp Business app compared with the WhatsApp Cloud API
WhatsApp Business appWhatsApp Cloud API
Built forA small business answering chats by hand on a phoneBusinesses that want software to send, receive and act on messages
AutomationGreeting, away message and quick repliesAny logic your backend can run: bookings, tokens, CRM updates, reminders
Your own softwareNot connectedTwo-way: webhooks into your system, REST calls out of it
TeamOne phone and a few linked devicesAny number of agents, through a dashboard or inbox you control
Starting a conversationFree-form messages, within WhatsApp’s spam limitsPre-approved templates, to customers who have opted in
CostThe app is freeMeta charges per template message by category and country; development is separate

Read the full comparison

How a message travels

Inbound and outbound, step by step

The part most integrations get wrong is not sending a message. It is receiving one reliably, exactly once, and doing the right thing with it.

  1. 01

    Customer messages you

    Text, button tap, image or location

  2. 02

    Meta posts to your webhook

    A signed HTTPS request

  3. 03

    Signature verified, 200 returned

    Fast, before any processing

  4. 04

    Event queued

    So a spike never loses a message

  5. 05

    Worker de-duplicates

    On the message ID, so a retry is harmless

  6. 06

    Business logic runs

    Rules, state, records, alerts

  7. 07

    Reply sent, status tracked

    Free-form or template; sent → delivered → read

Webhook: verification and signature check (pseudocode)
// 1. One-time verification when you register the webhook (GET)
if (query["hub.mode"] === "subscribe" && query["hub.verify_token"] === VERIFY_TOKEN) {
  return reply(200, query["hub.challenge"]);
}

// 2. Every event after that (POST): check the signature, answer fast, work later
const expected = "sha256=" + hmacSha256(APP_SECRET, rawBody);
if (!timingSafeEqual(expected, headers["x-hub-signature-256"])) return reply(401);
reply(200);                                   // acknowledge immediately
queue.add("whatsapp.event", JSON.parse(rawBody)); // a worker does the real processing
Incoming button tap (simplified)
{
  "object": "whatsapp_business_account",
  "entry": [{ "changes": [{ "field": "messages", "value": {
    "metadata": { "phone_number_id": "<PHONE_NUMBER_ID>" },
    "contacts": [{ "profile": { "name": "Meera" }, "wa_id": "91…" }],
    "messages": [{
      "from": "91…",
      "id": "wamid.…",                 // de-duplicate on this
      "type": "interactive",
      "interactive": { "type": "button_reply", "button_reply": { "id": "reschedule", "title": "Reschedule" } }
    }]
  }}]}]
}
Delivery status update (simplified)
{
  "entry": [{ "changes": [{ "field": "messages", "value": {
    "statuses": [{
      "id": "wamid.…",                 // the message you sent
      "status": "delivered",           // sent · delivered · read · failed
      "timestamp": "…",
      "recipient_id": "91…"
      // on "failed": an errors[] entry explains why
    }]
  }}]}]
}

Shortened for readability; real payloads carry more fields.

What you get

What a Cloud API integration from us includes

Nine pieces that together make an integration you can rely on and hand to your own team.

Webhook service

An HTTPS endpoint that verifies Meta’s signature, acknowledges at once and hands the event to a queue.

Message templates

Drafting, categorising and submitting the templates your workflows need, with variables and buttons.

Token and secret handling

Access tokens and the app secret kept server-side, rotated safely, never exposed to a browser.

Sending service

Free-form replies inside the 24-hour window and template messages outside it, with retries on failure.

Delivery tracking

Sent, delivered, read and failed statuses stored per message, with alerts when something does not arrive.

Business logic

The conversation state and rules that decide what each message does in your system.

Data model

Contacts, conversations, messages and consent records in your database, ready for reporting.

Agent dashboard

Where your team reads, replies and takes over from the bot, when the project calls for it.

Documentation and handover

How it works, how to operate it and where everything lives. You own the code.

The rules that shape the design

Six platform rules, and what they mean for the build

WhatsApp is strict about who may message whom, and when. We design each workflow inside those rules, so your number stays healthy.

The 24-hour customer service window

When a customer messages you, a 24-hour window opens in which you can reply freely. After it closes, only approved templates can be sent.

Every send chooses between free-form and template automatically, and the dashboard shows how long each window has left.

Opt-in

Businesses need a customer’s permission before messaging them on WhatsApp.

Opt-in is captured and stored with its source and time, and “stop” requests are honoured everywhere.

Template approval and categories

Templates are reviewed by WhatsApp and belong to a category (utility, marketing or authentication), which affects the rules and the price.

Templates are written for the right category, versioned, and rejected ones are reworked rather than worked around.

Quality rating and messaging limits

WhatsApp rates your messages by how customers react, and limits how many customers you can start conversations with each day.

Volumes are paced, and complaint and block signals are watched so one bad campaign cannot cost you the number.

Business verification and display name

Verifying the business with Meta and getting a display name approved unlock higher limits and some features.

We prepare the documents and details you need, so the review is not the part that stalls the project.

Pricing

Meta bills template messages by category and destination country; replies inside the customer service window do not carry a Meta charge. Meta updates its rates from time to time.

We model your expected volume against the current rates before you commit.

Meta’s policies and pricing change from time to time. We check the current rules with you at the start of every project.

Getting started

What we need from you, and what we take care of

From you

  • The workflows you want on WhatsApp, in your own words
  • A phone number for the API (or help choosing one)
  • Business details for verification, such as your website and registration documents
  • Access to the software the integration must talk to
  • How you collect customer opt-in today

From us

  • Meta app, WhatsApp Business Account and webhook set-up
  • Template drafting and submission
  • The backend, database and sending service
  • Testing of duplicates, failures and awkward conversations
  • Deployment, monitoring and documentation
FAQ

WhatsApp Cloud API integration: your questions answered

Do we need a third-party WhatsApp platform or a Business Solution Provider?

No. You can integrate with the Cloud API directly through Meta, which is how we build. A third-party platform can be useful if you want a ready-made shared inbox, but it is not a requirement, and going direct gives you full control of your data and your logic.

Can we use our existing WhatsApp number?

Usually yes, but not without a decision. A number that is currently used in the WhatsApp or WhatsApp Business app generally has to be moved to the API, and the way chat history and parallel app use are handled has been changing, so we check Meta’s current options with you before registering anything. A fresh number is the simplest route.

How long do Meta’s reviews take?

Template reviews are often quick, but neither they nor business verification come with a guaranteed time, and both are outside our control. We start them early and plan the project around them rather than at the end.

How are WhatsApp messages priced?

Meta bills template messages by category and destination country, and replies inside the 24-hour customer service window do not carry a Meta charge. Rates change from time to time, so we work from Meta’s current pricing when we estimate your volume. Our development fee is separate from Meta’s message charges.

Pricing and how projects are scoped →

Where does the integration run, and who owns it?

On infrastructure you choose: your own cloud or server, or one we set up for you. You own the code, the database and the deployment, and we document how it runs.

Is it safe to collect customer data over WhatsApp?

Messages are encrypted in transit, and we keep tokens and secrets on the server, verify every webhook signature, restrict who can read conversations and log access. Because the Cloud API is hosted by Meta, we advise against collecting passwords or highly sensitive data in chat, and we design the flow so that anything sensitive moves to a secure page instead.

Can one integration serve several branches or phone numbers?

Yes. A single backend can manage several numbers, route each customer to the right branch or team and keep their data separate, with its own templates and dashboards where you need them.

Can you fix or take over an existing WhatsApp integration?

Yes. We can review what you have: webhook verification, retries, duplicate handling, token storage and template use. We tell you plainly whether it is worth repairing or better rebuilt.

Planning a WhatsApp integration? Talk to a specialist first.

Tell us what your software does today and what you want WhatsApp to trigger. We will say how we would connect it, and what to watch out for.