WhatsApp Business API: The Complete 2026 Guide

WhatsApp Business API: The Complete 2026 Guide
Share this post

The WhatsApp Business API is the Meta-approved way for companies to talk to customers at scale and automate customer service on WhatsApp. In practice, it connects a business phone number to Meta so that platforms, AI agents, and support teams can serve customers within the rules.

WhatsApp Business API: official Meta screen used to connect a business phone number
Official Meta screen used to connect a business phone number to the WhatsApp Business API.

The topic gained weight between 2025 and 2026. Meta shut down the self-hosted version, changed its pricing, and launched coexistence with the app. In November 2025, a wave of account blocks hit businesses in Brazil, according to Times Brasil (in Portuguese).

Any company that has dealt with a banned WhatsApp number knows the channel is part of daily operations. This guide covers the official WhatsApp API end to end: how it differs from the app, how it works, how to get access, requirements, pricing, limits, risks, use cases, data protection, and challenges.

Key Takeaways

  • The WhatsApp Business API is Meta’s WhatsApp Business Platform, now centered on the Cloud API, and it is the authorized way to automate conversations at scale.
  • Since July 2025, Meta charges per delivered template message. From October 1, 2026, Meta also charges for service messages, with 1,000 free service messages per phone number each month.
  • Coexistence lets a company use the same number in the WhatsApp Business app and the API, which makes it easier to adopt AI agents.

What Is the WhatsApp Business API

Before pricing and setup, it helps to understand what Meta actually means by the official API. The popular name covers a set of services with different jobs, all maintained by Meta.

Definition and Platform Components

According to the WhatsApp Business Platform documentation, the platform lets businesses talk to customers at scale through APIs. It runs on Meta’s Graph API, using HTTP requests and OAuth authentication, and it has three parts.

  • Cloud API: sends and receives messages and calls, including text, media, interactive messages, groups, and voice.
  • Business Management API: manages phone numbers, message templates, analytics, and costs.
  • Marketing Messages API: built for campaigns, with conversion tracking and, according to Meta, up to 9% more marketing message deliveries.

When the market talks about the WhatsApp Business API or the WhatsApp Cloud API, it means this set of services. Meta handles the hosting. The business or its provider only integrates its own systems with the API.

End of the On-Premises Version

For years there was an On-Premises version, installed on the servers of the business or its provider. Meta phased this option out in stages, and since January 2024 new features ship only on the Cloud API.

Since July 2024, new phone numbers can only be registered on the Cloud API. On October 23, 2025, the last On-Premises version expired, and messages from numbers still registered on it stopped being delivered.

Today, the official WhatsApp API is, in practice, the Cloud API hosted by Meta. With no server to maintain, the focus shifts to the platform that uses the API, such as a CRM or an AI chatbot.

WhatsApp Business App, API, and Coexistence

Many companies start with the free app and hit its limits as they grow. Understanding the three options helps decide when to migrate and which setup fits best.

Differences Between the App and the API

The WhatsApp Business app is free and designed for small businesses. According to the comparison published by WhatsApp Business, it uses one number per account and was not built for teams with many users.

The API platform supports multiple numbers, CRM integration, and operations with thousands of agents and bots. It is the right fit for companies that need a shared WhatsApp inbox for several agents, automation, and reporting.

CriteriaWhatsApp Business appWhatsApp Business API
Usage costFreeCharged per delivered template
Phone numbersOne per accountMultiple numbers and display names
TeamBuilt for a few usersMany agents and bots at the same time
IntegrationsNo API integrationCRM, internal systems, and AI

How Coexistence Works

Coexistence connects a WhatsApp Business app number to the Cloud API through a provider, using Embedded Signup. According to Meta’s coexistence documentation, the app must be on version 2.24.17 or later.

With coexistence, the team keeps using the phone while the API handles conversations in parallel, and messages sent from the app remain free. This lets a company adopt AI agents without changing the number customers already know.

Throughput in this mode is 20 messages per second, compared with 80 in standard use. The setup also has feature and phone-usage limitations, covered in the challenges section.

How the WhatsApp Cloud API Works

The API revolves around three concepts: the customer service window, approved templates, and webhooks. Together, they define when and how a business can message each customer.

Service Messages and the 24-Hour Window

According to Meta’s documentation, when a user messages or calls a business, a 24-hour timer starts. This is the customer service window. Each new message or call from the customer resets the timer.

While the window is open, the business can send any service message: text with link previews, audio, documents, images, video, stickers, reply buttons, lists, location requests, contacts, reactions, and catalog messages.

Flows deserve special mention. They are multi-step forms inside the chat for booking appointments, browsing products, collecting feedback, or capturing leads, with real-time lookups to systems such as a calendar.

Approved Message Templates

Outside the 24-hour window, a business can only start conversations with approved message templates. According to Meta, templates fall into three categories: marketing, utility, and authentication.

Utility templates cover confirmations and reminders, and authentication templates deliver access codes. Marketing templates cover promotions and re-engagement, with buttons and an unsubscribe option so customers can leave the list.

Webhooks and System Integration

All inbound messages and delivery statuses arrive by webhook, an automatic notification from Meta to the company’s system. That is how a CRM knows the customer replied or read a message.

Default throughput is 80 messages per second per number, and one message every 6 seconds to the same user. This design is the foundation for automating WhatsApp customer service without losing messages.

Ways to Access the WhatsApp API

There are two paths to activate the WhatsApp API: integrate directly with Meta or use a provider platform. The choice depends on the available engineering team and the level of support needed.

Direct Access Through Meta

Direct access requires a Facebook account or a Meta managed account, a developer registration, a Meta app with the WhatsApp use case, a WhatsApp Business Account (WABA), and a phone number.

After that, the company must build the integration and the agent interface, or build a WhatsApp chatbot from scratch. This path works for companies with an engineering team, but it is heavy for those that just want to serve and sell.

Providers and Embedded Signup

Meta describes its providers on the solution providers page. A Solution Partner is a Meta Business Partner, offers full service, and can extend its own line of credit to the client, billing for API usage.

A Tech Provider can also offer full service, but without a line of credit. The client adds its own payment method, Meta bills the API usage, and the provider bills for its own services.

In both cases, activation uses Embedded Signup. It opens on the provider’s website, creates the client’s WhatsApp assets, and authorizes the app. After that, the team works in ready-made support automation screens.

Requirements and Setup Steps

Once the access path is chosen, activation follows a predictable sequence. Preparing the requirements up front avoids rework and delays in approving the number and the display name.

Account and Phone Number Requirements

The first requirement is a Meta Business Portfolio, formerly Business Manager, which holds the WhatsApp Business Accounts. Business verification unlocks more throughput and is a prerequisite for the Official Business Account badge.

Under Meta’s rules, the number must belong to the business, include the country and area code, and be able to receive an SMS or a call. Short codes are not accepted, and a banned number must be appealed first.

If the number is already active on WhatsApp, it must be deleted from the app before registration, except in coexistence mode. That is why it pays to decide early between a new number and the current one.

A new portfolio starts with up to 2 phone numbers. The limit rises to 20 after business verification or after reaching the messaging limit of 2,000 unique recipients in 24 hours.

Step-by-Step Activation

With a provider platform, activation usually follows this order:

  1. Portfolio: create or review the Business Portfolio and start business verification.
  2. Number: choose between a new number or the current number with coexistence.
  3. Signup: complete Embedded Signup and register the number with the two-step verification PIN.
  4. Display name: submit a name tied to the business and wait for approval.
  5. Templates: create the first utility and marketing templates and wait for review.

The display name can be pending, approved, rejected, or expired, and it only takes effect once approved. A rejected name can be corrected or appealed, and approval arrives by webhook.

With the number live, the team should define business hours, tone of voice, and routing rules, following customer service best practices, before turning on AI agents and templates.

WhatsApp Business API Pricing

Pricing changed in 2025 and is one of the most common sources of questions. Knowing what is paid and what is free helps plan campaigns and customer service.

Per-Message Pricing

According to Meta’s pricing page, since July 1, 2025, Meta charges per delivered message rather than per conversation. The rate depends on the message category (marketing, utility, or authentication) and on the recipient’s country code.

As a result, cost follows usage. A marketing campaign to thousands of contacts is charged per delivered template. Customer-initiated support mostly uses service messages, which were free through September 30, 2026. From October 1, 2026, they are charged above a monthly allowance of 1,000 per phone number.

What Is Free and the Rule for AI Providers

Through September 30, 2026, non-template messages sent inside the 24-hour window were free, as were utility templates sent while the window was open. From October 1, 2026, Meta charges for both. In Brazil, for example, each delivered message costs R$ 0.035, while marketing costs R$ 0.3217, with 1,000 free service messages delivered per phone number per month and no rollover. The 72-hour free entry point window opened by click-to-WhatsApp ads remains free.

Brazil also has a specific rule. Since March 11, 2026, Meta charges AI providers, meaning general-purpose assistants, for non-template messages sent to +55 numbers.

Companies that use AI in their own customer service are not covered by this rule. A business that deploys an agent to answer its own customers, for example with ChatGPT on WhatsApp, pays the standard rates.

Messaging Limits and Number Quality

The official API has volume and quality rules. Meta controls how many new customers each business can reach per day and tracks how people react to its messages.

Messaging Limit Tiers

According to the messaging limits documentation, the limit counts unique recipients in 24 hours and rises in tiers: 250, 2,000, 10,000, 100,000, and unlimited. It applies to business-initiated conversations using templates.

Since October 2025, according to Meta, the limit applies per portfolio rather than per number. In addition, a drop in quality no longer downgrades the tier a business has already reached.

Quality Rating and Template Pausing

Each message template gets a high, medium, or low quality rating, calculated from signals over the last 7 days, such as blocks and reports. Tracking this rating alongside customer service metrics shows whether customers welcome the messages.

Under the template pausing rules, a template with many negative reactions is paused for 3 hours, then for 6 hours, and disabled if the problem persists. The rating works as an early warning before a small problem becomes a block.

Official API vs. Unofficial Solutions

Tools that mimic WhatsApp Web or rely on modified apps are still sold as a cheap alternative. The difference from the official API goes well beyond price. The guide on the unofficial WhatsApp API covers the topic in depth.

Risks of Unofficial Tools

The WhatsApp Terms of Service prohibit bulk and automated messaging, autodialing, modified apps, and integrations through unauthorized means. Accounts that violate the letter or the spirit of these rules can be suspended or terminated.

Companies that automate outside the API risk having the account suspended or banned and losing the number as a service channel. The guide on how to avoid a banned WhatsApp number explains the types of blocks and the appeal process.

Benefits of Operating Within the Rules

The official API offers public rules, reviewed templates, known limits, and a visible quality rating. That does not mean a number can never be blocked, but it keeps the operation within what Meta allows and gives clear signals before a problem.

Another benefit is governance. With the API, every message is logged, the team works from a single inbox, and the company can choose WhatsApp AI tools without depending on a single phone to serve customers.

Use Cases for the Official API

WhatsApp message template with a Learn more button and an Unsubscribe button, sent through the WhatsApp Business API
Approved template with buttons and an unsubscribe option, sent through the WhatsApp Business API.

The official API enables uses the app cannot handle. The most common ones combine automated customer service, proactive outreach to the customer base, and integration with company systems.

Customer Service with AI Agents

One of the highest-impact uses is AI agents, which understand questions the way customers phrase them, look up the company’s knowledge base, and take actions. They go beyond a menu-based WhatsApp chatbot.

Building an AI agent for WhatsApp starts with a knowledge base, clear instructions, and integrations. Niche businesses can go further with vertical AI agents trained for a specific industry.

Campaigns, Reminders, and Re-engagement

With approved templates, a business can send promotions to people who opted in, appointment reminders, delivery updates, and payment reminders. This supports customer retention automation without relying on purchased lists. The guide to WhatsApp bulk messaging explains how to do it safely.

Re-engagement reaches contacts who stopped replying, with spaced-out, relevant messages. Combined with sales follow-up tools, it helps recover opportunities at every stage of the sales funnel.

CRM and System Integration

Webhooks let a company log every conversation in the CRM, update lead status, and trigger messages from events such as an approved order. Integrating WhatsApp with a CRM eliminates the rework of copying data between screens.

A restaurant, for example, can connect its menu and ordering system to an AI delivery chatbot that takes the order, confirms the address, and sends status updates until delivery.

Security, Privacy, and Data Protection

WhatsApp chat with a verified business badge and Meta's secure service notice, shown in conversations handled through the official API
Meta’s secure service notice in a conversation handled through the WhatsApp Business API.

Automating WhatsApp means processing personal data at volume. The platform’s technical security must be matched by internal processes aligned with data protection law.

Encryption and the Official Business Account Badge

According to Meta, messages are encrypted with the Signal protocol between the customer and the Cloud API, which Meta itself hosts. On the company side, the job is to protect access tokens, restrict permissions, and review who can see conversations.

An Official Business Account shows a blue badge. It requires a verified portfolio, two-step verification, an approved display name, at least 30 days on the platform, and policy compliance. The badge builds trust with recipients.

Consent, Opt-Out, and LGPD

The WhatsApp Business Messaging Policy requires opt-in, meaning the person provided the number and gave permission to receive messages. Opt-out requests must also be honored in every send.

In Brazil, a phone number is personal data protected by Brazil’s data protection law (LGPD, Law 13,709/2018, in Portuguese), and using it in campaigns requires a legal basis. Similar rules apply under GDPR in the EU. Recorded consent is the first line of defense against user reports and data protection issues.

With AI agents, protection against instruction manipulation, known as prompt hacking, also comes into play. Limiting what the agent can access and logging the actions it takes completes the governance picture.

Challenges and Limitations of the Official API

The official API solves the app’s problems, but it brings costs, rules, and routine adjustments. Knowing these points up front avoids surprises in the budget and in operations.

Costs and Template Approval

Every delivered marketing template is charged, and frequent campaigns to large lists weigh on the budget. In addition, every template goes through review before use, so copy and timelines need to be planned ahead.

Templates with many negative reactions are paused and can be disabled, stopping campaigns midway. That is why content quality and list consent matter as much as send volume.

Coexistence and Quality Rating Limitations

Companies that keep the number in the app with coexistence need to accept a few adjustments:

  • Broadcast lists: become read-only after connecting to the API.
  • Disabled features: disappearing messages, view-once media, and live location stop working.
  • Phone usage: about 14 days without opening the app disconnects the number from the API.

The challenge with the quality rating is that it reacts to recipients: blocks and reports from the last 7 days affect templates, even when sends follow the rules.

How ConverZap Uses the Official API

ConverZap is a WhatsApp AI agent platform connected to the official API with coexistence. Its agents query databases and CRMs, answer with the company’s knowledge, and bring AI into day-to-day customer service.

The platform also handles compliant bulk messaging with approved templates and unsubscribe options, reminders, re-engagement, and dashboards.

To estimate a monthly bill with Meta’s BRL rate card, use the cost calculator (Brazil, in Portuguese). Technical terms are explained in the WhatsApp API glossary.

Frequently Asked Questions

The answers below cover the most common questions about the WhatsApp Business API in customer service, marketing, and sales.

How much does the WhatsApp Business API cost?

Since July 2025, Meta charges per delivered template message, with rates that vary by category and by the recipient’s country. Non-template messages and utility templates inside the 24-hour window were free through September 30, 2026. From October 1, 2026, Meta charges for both, with 1,000 free service messages per phone number each month. The chosen platform charges separately.

Can the WhatsApp Business API use the same number as the WhatsApp Business app?

Yes, through coexistence. The app number is connected to the Cloud API through a provider, and the team keeps using the phone while the API handles conversations in parallel. The app must be on version 2.24.17 or later and must be opened regularly.

Does the WhatsApp Business API prevent a number from being blocked?

No channel is completely free of risk. WhatsApp can suspend accounts that violate its Terms, and templates with many reports are paused and then disabled. The advantage of the official API is operating within the rules, with opt-in, known limits, and a visible quality rating.

How can a business send messages outside the 24-hour window on the WhatsApp API?

Outside the window, only Meta-approved message templates can be sent, in the marketing, utility, or authentication categories. The contact must have opted in, and opt-out requests must be honored to protect the number’s quality rating.

Do I need a developer to use the WhatsApp Business API?

With direct access through Meta, yes, because the business must build the integration with webhooks and message sending. With a provider platform, activation happens through Embedded Signup, and the team works in ready-made screens without writing code.

How does the WhatsApp Business API improve AI-powered customer service?

The API lets a business connect AI agents to its number, integrate its CRM and other systems, and log every conversation. Combined with good service practices, it shortens response times and allows after-hours service within WhatsApp’s rules.

To bring AI agents and customer service automation to the WhatsApp Business API, talk to the ConverZap team.

Share:

Subscribe to our newsletter
Get news and updates about WhatsApp automation and AI agents
Read more
Talk to our team
See how ConverZap can help your business on WhatsApp
Conexão da ConverZap com a API oficial do WhatsApp pela Meta
plugins premium WordPress