An unofficial WhatsApp API connects a phone number without Meta’s authorization, outside the official WhatsApp Business API. WhatsApp’s Terms prohibit this kind of integration. Businesses that keep using it risk losing the number, being blocked from creating another business account, and having the whole organization banned.
Many companies started on the WhatsApp Business app. As they grew, they automated customer service with tools connected through a QR code, often without knowing those tools were unofficial. This guide covers the risks, how to spot an official provider, and how to migrate.

Key Takeaways
- An unofficial WhatsApp API violates the WhatsApp Terms of Service and the WhatsApp Business Terms. WhatsApp also states it cannot validate the security practices of these third-party apps.
- The risk goes beyond a banned number. The business can be blocked from creating a new business account, and the entire organization can be banned from WhatsApp products.
- To move to the official API, a business can register the number on the Cloud API and lose its chat history, or use coexistence with the Business app, which keeps the history.
- Before signing a contract, check Meta’s partner directory and ask the provider to describe, in writing, how the number will be registered.
What Is an Unofficial WhatsApp API?
The word “API” is misleading. These tools do not use any interface released by Meta. Understanding how they work shows why they clash directly with the platform’s rules.
How Unofficial Integrations Work
Typically, the tool asks someone to scan a QR code. From then on, it controls the session as if it were a linked device, mimicking WhatsApp Web or the app itself. On top of that session, it runs broadcasts, auto-replies, and a WhatsApp chatbot.
In this model there is no WhatsApp Business Account (WABA), no approval of message templates, no official webhooks, and no Meta support. The WhatsApp Help Center classifies these third-party apps as violations of the Terms and says the platform does not support them.
WhatsApp’s reason is simple: it cannot validate the security practices of these apps. In other words, the number’s session sits in the hands of a third party with no contract or formal commitment to Meta.
What WhatsApp’s Terms Say
The WhatsApp Terms of Service list prohibited conduct that describes exactly how these tools operate, including bulk messaging, automated messaging, and integrations created through unauthorized means. The most direct points are:
- Reverse engineering: modifying, decompiling, or extracting code from WhatsApp’s services.
- Unauthorized collection: collecting user information in unauthorized ways.
- Software that mimics the service: creating software or APIs that function substantially like WhatsApp’s services.
The WhatsApp Business Terms go further. They prohibit any application that interacts with the business services without prior written consent. That is why customer service automation stays within the rules only when it runs through a channel Meta has authorized.
Testing and Low Volume Are Not Exceptions
A common argument is that the unofficial tool is “just for testing” or for small volumes. The Terms, however, make no exception based on purpose or message volume.
To test the API, Meta’s intended path is direct access, with a developer account and an app that has the WhatsApp use case, or working with a Meta solution partner. For manual conversations, the WhatsApp Business app itself does the job with no contractual risk.
Official vs Unofficial WhatsApp API: Practical Differences

Beyond the rules, the two options differ in signup, available features, and support. A side-by-side comparison also helps a business figure out which one it already uses.
Access, Signup, and Features
The official API requires a Business Portfolio, a WhatsApp Business Account (WABA), an approved display name, and a two-step verification PIN when the number is registered. Access can be direct through Meta or through a partner using Embedded Signup.
In return, the business gets approved message templates, webhooks for every message and delivery status, Flows for in-chat forms, and eligibility for the Official Business Account badge. This foundation is what supports WhatsApp AI tools at scale.
Comparison Table: Official vs Unofficial
The table sums up the criteria that matter most, from a small shop to a contact center with many agents. Platform rules are the same for every business. Cost gets its own section further down.
| Criterion | Official API | Unofficial API |
|---|---|---|
| Allowed by the Terms | Authorized by Meta | Prohibited by the Terms |
| Signup | Embedded Signup or direct access, with a WABA | QR code scan |
| Messages outside the 24-hour window | Approved templates only | No official rule |
| Messaging limits | Tiers per portfolio | No official control |
| Quality rating | Yes, with warnings and pauses | Does not exist |
| Official Business Account badge | Available | Not available |
| Support and security | Support from Meta and the solution partner | No support and no security validation by WhatsApp |
| Switching providers | Portability that keeps the number | Start over from scratch |
| Cost | Per billable message, based on Meta’s official rate card (new rules from October 1, 2026) | Tool subscription plus the risk |
How to Tell if a Provider Is Official
Many businesses do not realize they are on an unofficial WhatsApp API. Serious support automation platforms explain from day one how the number will be registered. Integrations without Meta’s authorization usually show at least one of these signs:
- QR code signup: the number shows up as a linked device in the app, and no Meta screen appears at any point.
- “No limits” promises: unlimited sending or “no blocks,” with no mention of messaging tiers or quality rating.
- No templates or portfolio: there is no template approval, no display name, and no Business Portfolio.
Meta keeps a public partner directory that can be checked before signing. It also helps to ask the provider to explain, in writing, how the number will be registered on the Cloud API.
Teams that build AI agents for WhatsApp on the official API can describe this flow plainly, including the Meta screen where the business itself authorizes the connection.
Risks for the Number and the Business
The risks start with the number. Depending on the violation, they reach the business account and then the whole organization. Each step shuts down more than the one before.
Temporary and Permanent Bans
The Help Center separates three situations. A restricted account is temporary and ends on its own. A temporarily banned notice may point to the use of an unofficial app or to data scraping.
With a permanent ban, the account can no longer use WhatsApp. According to WhatsApp, if the user does not switch to the official app after the temporary notice, the account may be banned for good. The guide on a banned WhatsApp number covers each case.
Instability, Outages, and No Support
Because an unofficial integration depends on mimicking the app, any WhatsApp update can drop the session without warning. When that happens, there is no Meta support and no authorized partner to open a ticket or follow an appeal.
On the official API, a drop in performance usually gives signs first. According to Meta’s documentation, the quality rating considers blocks and reports from the last 7 days. Templates that perform poorly are paused for 3 hours, then for 6 hours, before being disabled.
Each pause gives the team time to review content, frequency, and audience, following customer service best practices. With an unofficial tool, the first sign of trouble is often the number itself getting disconnected.
Account Termination and Organization Bans
The WhatsApp Business Terms state that, in case of a violation, WhatsApp may limit, throttle, suspend, or terminate the business account. After termination, creating another business account requires express written permission, so switching SIM cards does not solve it.
The WhatsApp Business Messaging Policy goes one step further. If an account is terminated for violating the terms or policies, WhatsApp may ban the business and its organization from using any WhatsApp product in the future, including the official API itself.
For companies that run most customer service on WhatsApp, everything stops at once: campaigns, reminders, and CRM integration. A shortcut taken to save money can close the door on the right solution later.
Data Security, Consent, and Privacy Laws

Customer data is also at stake, not just the account. Names, phone numbers, orders, and conversations flow through the chosen tool, and the business remains responsible for how that data is processed.
Customer Data in Unvalidated Tools
Whoever controls the number’s session can see the chat history, the contact list, and order details shared in the chat. Under Brazil’s data protection law (LGPD), the business is accountable for that processing, even when the tool belongs to an outside vendor. Similar rules apply under GDPR in the EU.
On the official API, messages use end-to-end encryption based on the Signal protocol, and events reach the business’s systems through webhooks. Even so, poorly configured AI agents can expose data, so clear rules and permissions remain essential.
Opt-In, Unsubscribes, and What the Law Requires
The WhatsApp Business Messaging Policy requires opt-in: the customer must have provided the number and given permission to receive messages. Opt-out requests must also be honored. This applies to every business, whatever tool it uses.
Brazil’s data protection law (LGPD) requires a legal basis and transparency for any processing of personal data, and similar rules apply under GDPR in the EU. On the official API, templates with an unsubscribe button and a record of each opt-in help support customer retention with traceability.
The Real Cost: Why the Unofficial Option Ends Up Costing More
The low monthly fee of an unofficial WhatsApp API hides costs that only show up after a block. Comparing just the tool’s price with the official API’s price leads to an incomplete calculation.
Hidden Costs of the Unofficial Option
The cost of a block rarely appears on a vendor spreadsheet. It shows up as a lost number, chat history and contacts wiped out with the session, and a stalled operation, with customers messaging a line that no longer answers.
Each business can measure this impact with its own indicators, such as downtime, lost conversations, and revenue in the period. Tracking customer service metrics before and after an incident shows clearly how much the shortcut really cost.
How Official API Billing Works
Meta charges per delivered message, based on the message category and the recipient’s country. Since July 1, 2025, template messages have been billed per delivery in the marketing, utility, and authentication categories. Rates are listed on Meta’s official pricing page, which should be checked before any cost estimate. The WhatsApp API pricing guide explains the model in detail.
Until September 30, 2026, service messages and utility messages sent inside the 24-hour window were free. From October 1, 2026, Meta charges for these messages too, with 1,000 free service messages delivered per phone number per month. In Brazil, each of these messages costs R$ 0.035. Details are in Meta’s billing rules for non-template messages.
With coexistence, messages sent from the app remain free. Separately, Meta’s AI Providers pricing, in effect in Brazil since March 11, 2026, applies to general-purpose AI assistants.
That charge does not apply to businesses that use AI in their own customer service or sales follow-up.
How to Migrate to the Official API
Meta offers two paths to bring an existing number to the official API. The choice depends on two factors: how much the chat history matters, and whether the team needs to keep using the app on the phone.
Path 1: Register the Number on the Cloud API
In the first path, the business deletes the number’s account in the app and registers it directly on the Cloud API. According to Meta’s migration guide, the number becomes available for registration within 3 minutes after deletion.
With this path, the message history is lost, and Meta recommends backing it up first. The number also cannot return to the WhatsApp Business app until it is deregistered from the Cloud API. This option suits businesses that want to run everything through the API.
Path 2: Coexistence With the WhatsApp Business App
In the second path, the WhatsApp Business app number is connected to the Cloud API by a partner through Embedded Signup. With coexistence, up to 180 days of history are synced, and the app and the API work together on the same number.
There are limits: throughput of 20 messages per second, broadcast lists become read-only, and disappearing messages, view once, and live location are turned off. If the primary phone goes unused for about 14 days, the connection drops.
Coexistence starts from the WhatsApp Business app. Anyone on regular WhatsApp must first move the number to the Business app. After that, customer service automation runs through the API while the team keeps using the phone.
Number Already Banned: What to Do Before Migrating
If the number was banned while on the unofficial tool, the business needs to appeal before registering it on the official API. The review request deserves care: media reports citing the Help Center indicate it can be submitted only once per number.
If the appeal is denied, the way out is a new number. In that case the contractual rule matters again: if the business account was terminated, opening another business account depends on WhatsApp’s authorization, not just on a different SIM card.
Migration Checklist for the Official API
Leaving an unofficial WhatsApp API is straightforward when the migration follows an order. The checklist below splits the process into two stages and keeps the operation from stalling halfway through the switch.
Before the Switch
Preparation involves decisions that cannot be undone later, such as choosing the path, protecting the history, and cleaning up the contact base that feeds the sales pipeline. The recommended steps are:
- Back up conversations and export the contact list.
- Choose the path: coexistence, or a deleted or new number on the Cloud API.
- Verify the Business Portfolio and the company’s details.
- Pick a display name that follows Meta’s guidelines.
- Create the two-step verification PIN.
- Review the contact base and keep only contacts with a recorded opt-in.
After the Switch
Once the number is registered, the priority is to run the operation within the rules, with no rush to return to the old volume. The suggested sequence for the first weeks is:
- Create and approve templates, including an unsubscribe button.
- Set up webhooks and integrations with the company’s systems.
- Make sure handoff to a human agent is fast and clear.
- Shut down the old tool and revoke its sessions and linked devices.
- Keep the primary phone active, if using coexistence.
- Increase volume gradually, respecting the messaging tiers.
Messaging limits rise in tiers of 250, 2,000, 10,000, and 100,000 unique recipients in 24 hours, up to unlimited. The human handoff in step 3 is also required by the Policy, and it pairs well with properly configured AI in customer service.
Operating Safely After the Migration

Migrating is only the start. Keeping conversation quality high is what protects the number day to day and avoids repeating, on the official API, the mistakes made before.
Templates, the 24-Hour Window, and Quality Rating
Inside the 24-hour window opened by a customer’s message, the business can send any service message. Outside it, according to Meta’s documentation, only approved templates in the marketing, utility, and authentication categories can be sent.
Since October 2025, the messaging limit applies per portfolio, and a drop in quality rating no longer lowers that limit. Template pauses triggered by blocks and reports still apply, though, and they call for constant attention to content and audience.
The official API does not make a number immune to blocks; it reduces the risk by offering clear rules and warning signs. AI assistants on WhatsApp help teams reply quickly inside the window, which improves both customer experience and quality.
Portability Between Partners and the ConverZap Solution
On the official API, the business is not locked into a vendor. According to the documentation on migrating between partners, a business can switch partners and keep its number, display name, quality rating, limits, and Official Business Account badge.
Templates are copied over but start with an unknown rating for the first 24 hours. Registration is instant and does not interrupt sending. The only requirement is to turn off two-step verification before the switch.
ConverZap is an AI agent platform for WhatsApp connected to the official API with coexistence. It offers broadcasts with approved templates and unsubscribe options, win-back campaigns, reminders, CRM integration, and dashboards.
The platform’s vertical AI agents take actions in other systems, such as logging data in the CRM or querying a database, without leaving the conversation.
Frequently Asked Questions
The questions below add to what this guide has covered. For more context, see how AI chatbots and artificial intelligence can improve customer service on WhatsApp.
It may work technically for a while, but it remains outside the rules and can be blocked at any moment. The fact that a tool works today does not reduce the contractual risk to the number or to the business.
Not exactly. Modified versions are altered copies of the consumer app, while an unofficial API is an automation tool aimed at businesses. Both, however, are third-party apps that the WhatsApp Help Center classifies as violations of the Terms.
WhatsApp Web is WhatsApp’s own feature for using an account on a computer, with a person handling the conversations. An unofficial integration uses a similar session so third-party software can automate sending, and that unauthorized use is what the Terms prohibit.
Yes, as long as it runs through a channel authorized by Meta. The Policy allows automation within the 24-hour window, provided the customer has a fast, clear, and direct way to reach a human.
That is not recommended. A temporary ban notice already indicates the number has been linked to an unofficial app, and the review request is a single chance. Migrating before the first warning avoids relying on an appeal to keep the number.
Conclusion
Replacing an unofficial tool with the official API trades apparent savings for an operation Meta recognizes, with warnings before any restriction and no threat to the business’s access to WhatsApp products. With a backup, the right path, and gradually increasing volume, the switch happens without stopping customer service.
To migrate with coexistence and run AI agents on the official API, talk to the ConverZap team.



