Appearance
WhatsApp setup
This guide walks through every Meta screen you go through to connect a WhatsApp number to Desorix, in order. The Desorix connection wizard links to the matching section at each step.
Desorix uses the official WhatsApp Cloud API (Graph API v26.0). You connect your own number by copying a few values from Meta into Desorix. There is no "Login with Facebook" button: that feature (Embedded Signup) is only for Meta partners, and Desorix doesn't use it.
How long it takes
Plan for about an hour the first time. Most of it is waiting for SMS codes and clicking through Meta's screens. Meta changes its dashboard often; if a button name here doesn't match what you see, look for the closest equivalent. Where Meta's naming varies between accounts, this guide says so.
The short version:
- Create a Meta app with the WhatsApp use case.
- Add a real phone number to your WhatsApp Business Account.
- Create a system user and a permanent token.
- Copy the App ID and App Secret and the WhatsApp Business Account ID.
- In Desorix, go to WhatsApp → Connect WhatsApp and paste those values.
- Set up the webhook with the Callback URL and Verify token Desorix shows you.
- Publish the app (set it to Live).
- Test the connection and register the number if needed.
Before you start
You need:
- A Facebook account that can log in to Meta for Developers (developers.facebook.com) and Meta Business Suite (business.facebook.com).
- A Meta business portfolio. This used to be called Business Manager, and some screens still use that name. If you don't have one, you can create it while creating the app.
- A phone number for WhatsApp. It must:
- be a number you own, with country and area code (short codes don't work),
- be able to receive an SMS or a voice call, so Meta can send you a verification code,
- not be in use on the WhatsApp or WhatsApp Business app. If it is, either delete the WhatsApp account on that phone first (Settings → Account → Delete account in the app), or migrate the number. After deleting, wait a few minutes before adding it to Meta.
- Desorix installed on HTTPS with a valid certificate (for example
https://chat.yourbusiness.com). Meta refuses plainhttp://addresses and self-signed certificates. Free Let's Encrypt / AutoSSL certificates from cPanel are fine. - A payment method on your WhatsApp Business Account. See the warning below.
Payment method required from 1 October 2026
Meta bills per delivered message. From 1 October 2026 Meta also charges for service messages (your free-form replies inside the 24-hour customer service window), after a free allowance of 1,000 service messages per business phone number per month. Businesses without a payment method on file by 30 September 2026 stop having their service messages delivered: customers can still write to you, but your replies won't arrive. Template messages (marketing, utility, authentication) have always needed a payment method.
To add one: in Meta Business Suite, open Billing & payments (named Billing and payments or Billing Hub depending on your account) → Payment methods → Add, then assign it to your WhatsApp Business Account on the WhatsApp Business accounts tab. Meta accepts bank-issued credit and debit cards; prepaid and virtual cards are usually refused.
Create the app
A Meta app is the "container" that holds your API access, webhook settings and App Secret.
- Go to developers.facebook.com and log in. If asked, register as a developer (it's free, and needs a verified phone or card).
- Click My Apps (top right), then Create app.
- App details: enter an app name (your business name is fine; it can't contain "WhatsApp" or other Meta trademarks) and a contact email. Click Next.
- Use cases: select Connect with customers through WhatsApp. Click Next.
- On older dashboards you're instead asked for an app type: pick Business.
- Business: choose your business portfolio, or create a new one. Choose the portfolio that owns (or will own) your WhatsApp number. Click Next.
- Requirements / Publishing requirements: Meta lists what the app will need later. Click Next.
- Overview: check the details and click Create app. Meta may ask for your Facebook password.
You land on the app's dashboard.
Add WhatsApp
If you picked the WhatsApp use case, WhatsApp is already added. Meta takes you to Customize use case → Connect on WhatsApp → Quickstart (on some accounts the page is just called WhatsApp → Quickstart).
- Click Start using the API (or API Setup in the left menu).
- At the top of API Setup, Meta asks which WhatsApp Business Account to use. Select an existing one, or click Create a WhatsApp Business account.
- Meta shows the account's WhatsApp Business Account ID and a test phone number.
The left menu under WhatsApp now shows Quickstart, API Setup, Configuration and a few partner-only items (Tech Provider onboarding, Partner Solutions, Embedded Signup Builder). You can ignore the partner items.
If you created the app without the WhatsApp use case: open the dashboard, find Add use cases (or Add product on older dashboards), and add WhatsApp.
About the test number
Meta gives every new app a free test number. It's handy for a first try from the API Setup page, but it has limits: it can only send to up to 5 recipient numbers that you add and verify under To, and it isn't meant for real customers. Connect a real number for anything else. If you do connect the test number to Desorix, messages to numbers not on that list fail with error 131030 (see Troubleshooting).
Business portfolio and WhatsApp Business Account
Meta keeps things in three places. It helps to know which is which:
| Thing | What it is | Where you manage it |
|---|---|---|
| Business portfolio | Your company on Meta. Owns apps, WhatsApp accounts, system users and payment methods. | business.facebook.com → Settings (named Business settings or Settings depending on your account). |
| WhatsApp Business Account (WABA) | Holds your WhatsApp phone numbers, message templates and billing. One portfolio can have several. | WhatsApp Manager: in Business Suite, open Settings → Accounts → WhatsApp accounts, select the account and click WhatsApp Manager (or go to business.facebook.com/wa/manage). |
| Meta app | Your API access and webhook settings. | developers.facebook.com → My Apps. |
In WhatsApp Manager, Account tools → Phone numbers lists your numbers with their status, quality rating and messaging limit. Account tools → Message templates is where templates live (Desorix creates and syncs them through the API, but you can see them here too).
One Desorix workspace connects one WhatsApp Business Account per connection. You can add several connections to a workspace, and choose which of each account's numbers to use.
Phone number
Add your real business number to the WhatsApp Business Account.
- In the App Dashboard, open WhatsApp → API Setup. Scroll to Step 5: Add a phone number (the step number varies) and click Add phone number.
- You can also do this in WhatsApp Manager: Account tools → Phone numbers → Add phone number.
- Business profile: enter the display name (the name customers see), your time zone, category and an optional description.
- The display name must match your business, for example the name on your website or signage. Meta reviews it; approval usually takes from a few minutes to a couple of days. You can send messages while the review is pending, but a rejected name needs editing and resubmitting.
- Changing the display name later triggers a new review, and afterwards the number must be registered again.
- Phone number: enter the number with country code and choose Text message or Phone call for the verification code.
- Enter the 6-digit code Meta sends you.
- Two-step verification PIN. Choose a 6-digit PIN and write it down somewhere safe. You need it to register the number in Desorix and whenever the number is re-registered.
- To set or change it later: WhatsApp Manager → Account tools → Phone numbers → select the number → Two-step verification tab → Change PIN (or Turn on two-step verification if it was never set).
Check the number's Status column in WhatsApp Manager → Phone numbers. Connected means it's ready. Pending or Offline usually means it still needs registering, which Desorix does for you in Register phone number.
System user and permanent token
Desorix needs an access token to call the WhatsApp API on your behalf. The token must belong to a system user and never expire.
Don't use the temporary token
The Generate access token button on the API Setup page makes a temporary token that expires after about 24 hours. If you paste it into Desorix, everything works for a day and then stops with error 190. Always create a system user token as below.
Create the system user
- Go to business.facebook.com → Settings (Business settings), and make sure the right business portfolio is selected (top left).
- In the left menu, open Users → System users.
- Click Add (the button may show as + Add).
- Enter a name such as
desorixand set the role to Admin. Click Create system user.- An Admin system user automatically has access to all WhatsApp Business Accounts in the portfolio. An Employee system user works too, but you must assign each account by hand.
- If Meta asks you to accept the Non-Discrimination Policy first, accept it.
Assign assets
- Select the new system user and click Assign assets (named Add assets on some accounts).
- Choose Apps, select your app, and turn on Manage app under Full control.
- Choose WhatsApp accounts (or WhatsApp Business accounts), select your account, and turn on Manage WhatsApp Business accounts under Full control.
- Click Assign assets (or Save changes).
Generate the token
- With the system user selected, click Generate new token (named Generate token on some accounts).
- Select app: choose your app.
- Token expiration: choose Never.
- Permissions: tick
whatsapp_business_messagingwhatsapp_business_managementbusiness_management(Meta's guide lists it too; Desorix doesn't strictly need it, but it does no harm)
- Click Generate token and copy it right away. Meta shows it only once. If you lose it, generate a new one.
Treat the token like a password
Anyone with this token can send messages as your business and read your account. Don't email it, don't paste it into chat tools, and don't commit it anywhere. Desorix stores it encrypted. If you think it leaked, go back to the system user and click Revoke tokens, then generate a new one and paste it into Desorix.
App ID and App Secret
Desorix uses the App Secret to check that incoming webhooks really come from Meta.
- In the App Dashboard, open App settings → Basic.
- Copy the App ID (a long number at the top).
- Next to App secret, click Show. Meta asks for your Facebook password. Copy the secret.
The App Secret is also a password. If you ever click Reset next to it, paste the new one into Desorix immediately, or Desorix will reject all webhooks (see Troubleshooting).
WhatsApp Business Account ID and phone number ID
WhatsApp Business Account ID (Desorix asks for this):
- App Dashboard → WhatsApp → API Setup: shown under the phone number selector as WhatsApp Business Account ID.
- Or WhatsApp Manager: the account ID appears under the account name in the account selector (top left), and in the page URL as
waba_id=…. - Or Business Suite → Settings → Accounts → WhatsApp accounts: select the account; the ID is shown in the details panel.
Phone number ID (Desorix finds it for you): each number has its own ID, different from the phone number itself. Desorix lists your numbers and their IDs automatically after Test connection. If you need it for support, it's on API Setup under the From selector, and in WhatsApp Manager → Phone numbers (click the number).
Don't mix up the IDs
The WhatsApp Business Account ID, the phone number ID, the App ID and your business portfolio ID are all long numbers. Desorix's Test connection tells you if you pasted the wrong one.
Enter the details in Desorix
In Desorix, open the sidebar → WhatsApp → Connect WhatsApp. Step 1, Meta details:
| Field | What to paste |
|---|---|
| Name | Any label, e.g. "Main shop number". Only you see it. |
| WhatsApp Business Account ID | From this section. |
| App ID | From App settings → Basic. |
| App Secret | From App settings → Basic. |
| Access token | The permanent system user token. |
Desorix stores the App Secret and token encrypted. Continue to step 2.
Webhook
The webhook is how Meta tells Desorix about incoming messages, delivery statuses and template approvals.
In Desorix (wizard step 2, Webhook) you see two values, each with a Copy button:
- Callback URL, like
https://YOUR-DESORIX-DOMAIN/webhooks/whatsapp/<unique id> - Verify token, a random string
Keep that page open.
In Meta:
- App Dashboard → WhatsApp → Configuration. (On apps created with the WhatsApp use case, the path may show as Use cases → Customize → Configuration.)
- In the Webhook section, click Edit.
- Paste the Callback URL and Verify token from Desorix.
- Click Verify and save.
- Meta immediately sends a
GETrequest to the Callback URL withhub.mode=subscribe,hub.verify_tokenand a randomhub.challenge. Desorix checks the token and answers with the challenge. If it matches, Meta saves the settings. - The Desorix wizard page switches to Verified on its own when this request arrives.
- Meta immediately sends a
- Under Webhook fields, click Manage if the list is collapsed, and turn on Subscribe for each of these fields:
| Field | What Desorix uses it for |
|---|---|
messages | Incoming messages and delivery/read statuses of outgoing ones. |
message_template_status_update | Template approved, rejected, paused or disabled. |
template_category_update | Meta re-categorised a template (for example utility → marketing), which changes its price. |
phone_number_quality_update | Quality rating and messaging limit changes. |
account_update | Account-level events such as restrictions, bans and verification changes. |
Leave the other fields off.
If verification fails, see Troubleshooting. The most common causes are a verify token with a stray space, or a Desorix site that isn't reachable on HTTPS.
Why the webhook still stays quiet
Two more things are needed before real messages arrive: the app must be Live, and your WhatsApp Business Account must be subscribed to the app. Desorix does the subscription for you in Test connection.
Publish your Meta app (set it to Live)
Every buyer hits this. A Meta app starts in Development mode. Meta's webhook documentation warns that "some webhooks will not be sent if your app is in Dev mode". In practice, the only webhooks you can count on in Development mode are the test events you send by hand from App Dashboard → WhatsApp → Configuration. Real customer messages and delivery statuses may never reach Desorix. The fix is to switch the app to Live.
Do I need App Review?
Confirmed
Tested on 2026-09-26: a WhatsApp-only Business app published without App Review received real customer messages and delivery statuses.
No, if you only use your own WhatsApp Business Account, which is how Desorix works (each workspace connects its own number manually):
- Business apps automatically get Standard Access to every permission, including
whatsapp_business_messagingandwhatsapp_business_management. Standard Access needs no App Review. It covers accounts that have a role on the app, and the system user whose token you give Desorix has one. - App Review for Advanced Access is only needed by partners (Tech Providers and Solution Partners) whose app is granted permissions by other businesses during onboarding. Desorix doesn't use Embedded Signup, so you are not a partner.
- A Live app can only request permissions from people outside the app with App Review. That doesn't affect you either: your own system user already has access.
Business verification isn't required to go Live either. Meta only needs it to access data you don't own. You will still want it later: it's how you raise your messaging limit beyond the starting tier and get a verified display name.
What the Live toggle needs
Fill these in under App Dashboard → App settings → Basic before you flip the App mode toggle (at the top of the dashboard) from Development to Live. Meta's documentation marks the first six as required, and in practice the Live toggle also asks for a Privacy Policy URL.
Meta fetches the Privacy Policy and Terms URLs. Simple placeholder pages are accepted, but each URL must load publicly and return HTTP 200. A 404, a "coming soon" redirect or a login page blocks the switch, and if the page breaks later, Meta can move the app back to Development mode.
Desorix serves ready-made pages you can use for this:
https://YOUR-DESORIX-DOMAIN/privacyhttps://YOUR-DESORIX-DOMAIN/terms
Edit their text in Administration → Legal pages (add your company name and contact details before going Live). Open both URLs in a private browser window first to make sure they load without logging in.
| Field | Required for Live | What to enter |
|---|---|---|
| Display name | Yes | Your business or product name. It can't contain "WhatsApp" or other Meta trademarks. |
| Contact email | Yes | An inbox you read. Meta sends developer notices here. |
| App icon | Yes | A square image of your logo. 1024 × 1024 px PNG or JPG is the safe size. |
| Category | Yes | Business and pages (or the closest business category offered). |
| App purpose | Yes | "Yourself or your own business". |
| Terms of Service URL | Yes | https://YOUR-DESORIX-DOMAIN/terms |
| Privacy Policy URL | Yes (enforced by the toggle) | https://YOUR-DESORIX-DOMAIN/privacy |
| User data deletion | Recommended | Choose Data deletion instructions URL and enter https://YOUR-DESORIX-DOMAIN/privacy#data-deletion |
| App domains | No | Your Desorix domain, e.g. chat.yourbusiness.com. |
You can use pages on your own website instead of the Desorix ones, as long as they meet the same rule: public, and returning HTTP 200.
Then:
- Click Save changes.
- Toggle App mode to Live. If Meta refuses, the message names the missing field.
- Check the switch took effect: the toggle shows Live, and the app's status badge on My Apps changes.
After going Live
- The webhook Callback URL and Verify token you entered stay as they are. Nothing needs to be re-entered in Desorix.
- Desorix subscribes your WhatsApp Business Account to the app automatically when you run Test connection in the wizard. Without that subscription, webhooks are silently not delivered even to a Live app. If you configured things by hand, the connection tester flags a missing subscription.
- Send a WhatsApp message from your personal phone to the business number. It should appear in the Desorix inbox within a few seconds. A dashboard test event is not enough proof, because those also arrive in Development mode.
Test connection
In Desorix, wizard step 3, click Test connection. Desorix runs these checks in order. Each one shows pass, warning or fail, and warnings and failures link back to the section of this guide that fixes them. You can run the test as often as you like.
| Check | What it means | If it fails or warns |
|---|---|---|
| App ID and App Secret | Meta accepts the pair (Desorix inspects your token using the app's credentials, so a wrong secret fails here). | Copy both again from App settings → Basic. If you reset the secret in Meta, paste the new one. |
| Access token | The token is valid and belongs to this app. Warning if it is a temporary or personal token, or has an expiry date: it works now but will stop working. | Generate a system user token with expiry Never. A temporary token from the API Setup page is fine for a first test, but it expires after 24 hours. |
| Permissions | whatsapp_business_messaging and whatsapp_business_management are granted. | Generate a new token and tick both. Also check the system user has the app and the WhatsApp account assigned with full control. |
| WhatsApp Business Account | The ID exists and the token can read it. Desorix also saves your business portfolio ID. | Check the WhatsApp Business Account ID (not the phone number ID or portfolio ID), and that the account is assigned to the system user. |
| App subscription | Desorix checks which apps receive this account's webhooks, and subscribes yours if it's missing (POST /{waba-id}/subscribed_apps). An account can be subscribed to several apps; that's normal, for example if Meta subscribed a test app for you. | Usually a permissions problem: the token needs whatsapp_business_management and Full control of the account. |
| Phone numbers | Desorix lists the account's numbers for step 4. | No numbers means none have been added yet: Phone number. |
| Webhook | Meta has called your Callback URL and the Verify token matched. Warning until that happens. | Finish Webhook. The account page updates by itself when Meta's check arrives. |
The account shows Connected when nothing fails (warnings allowed) and Needs attention otherwise.
When every check passes, continue to step 4.
Register phone number
In wizard step 4, Phone numbers, tick the numbers of this WhatsApp Business Account that this workspace should use. Each shows its display name, status and quality rating.
A number must be registered with the Cloud API before it can send or receive. Numbers you added through the App Dashboard are often not registered yet, and a number needs registering again after a display name change. When Desorix shows a number as Not registered (its status in WhatsApp Manager is not Connected):
- Enter the 6-digit two-step verification PIN you chose in Phone number.
- If two-step verification was never turned on, the PIN you type here becomes the number's new PIN. Write it down.
- If you've forgotten the PIN, reset it in WhatsApp Manager → Phone numbers → your number → Two-step verification.
- Click Register. Desorix calls
POST /{phone-number-id}/register. - The status changes to Connected within a minute.
Meta allows 10 registration attempts per number in 72 hours. After that it blocks registration for 72 hours (error 133016), so check the PIN before retrying repeatedly.
After registering, open the number's page in Desorix and use Send a test message to send a message to your own phone. The Recent messages table on the same page shows each message's status (sent, delivered, read, failed) and its estimated cost.
First message must be a template
A business can only send free-form text to someone who messaged it in the last 24 hours. For the test, send a WhatsApp message from your phone to the business number first, or send an approved template (Meta's hello_world template is available on new accounts).
Send a test message
Open WhatsApp → (your number) in Desorix.
- Receive first. From your personal phone, send a WhatsApp message to the business number. Within a few seconds it appears under Recent messages. This proves webhooks work end to end; a test event from Meta's dashboard doesn't, because those arrive even when the app isn't Live.
- Send a template. Under Send a test message, enter your phone number in international format (
+14155550123), keep Template withhello_world/en_US, and click Send. With a Meta test number, the recipient must be in the test number's allowed list (API Setup → To → Manage phone number list). - Reply with text. Because you messaged the number in step 1, the 24-hour customer service window is open, so Text messages work too. Outside the window Desorix refuses free-form text and asks for a template, just like Meta would.
The table shows each message's status (pending → sent → delivered → read, or failed with Meta's error) and its cost:
- Category: marketing, utility, authentication, authentication_international or service. Predicted when sending, then corrected by Meta's delivery webhook.
- Market: where the recipient's number is from, which decides the price.
- Estimated: recorded before sending, from the rate table in Administration → Pricing.
- Cost: set once Meta reports the message delivered. It is 0 when Meta marks the message as free (
billable: false), for example service replies before 1 October 2026 or within the monthly free allowance.
Meta bills your WhatsApp Business Account directly. Desorix only records what each message costs so you can track and forecast spend.
Messaging limits
Meta limits how many different people you can start conversations with using templates.
- What counts: unique WhatsApp users you deliver messages to outside a customer service window, in a moving 24-hour period. Replies inside the 24-hour window after a customer messages you don't count.
- Shared across the portfolio: the limit is set at business portfolio level and shared by all phone numbers in it, not per number.
- Tiers: 250 (new portfolios) → 2,000 → 10,000 → 100,000 → unlimited.
- Getting to 2,000: complete business verification (Business Suite → Settings → Business info or Security Center, depending on your account), or send 2,000 delivered template messages to unique users within 30 days using templates with a high quality rating.
- Beyond 2,000: Meta raises the limit automatically when your quality rating is good and you've used at least half your current limit in the past 7 days.
You can see your current limit in WhatsApp Manager → Phone numbers (or Overview). Desorix broadcasts throttle to your tier, and the number page shows the current limit and quality rating from the phone_number_quality_update webhook.
Troubleshooting
| Symptom or error | Likely cause and fix |
|---|---|
| "The URL couldn't be validated" when clicking Verify and save | The verify token doesn't match the one in the Desorix wizard (check for a trailing space), or the Callback URL was mistyped. Copy both again with the Copy buttons. |
| Webhook verification fails with a certificate or connection error | The Callback URL isn't HTTPS, the certificate is self-signed or expired, or the site isn't publicly reachable (for example a local install). Enable SSL (AutoSSL / Let's Encrypt in cPanel) and open the URL in a browser to confirm. |
| Dashboard "Test" events arrive, real messages don't | App still in Development mode (publish it), or the WhatsApp Business Account isn't subscribed to the app (run Test connection in Desorix). |
| Desorix account page shows "Webhook signature failed" (Meta gets HTTP 401) | The App Secret in Desorix doesn't match the app that sends the webhooks, often after clicking Reset on the secret. Paste the current App Secret. Desorix rejects unsigned or wrongly signed webhooks on purpose. |
| Live toggle refuses to switch | A required Basic setting is empty (the error names it), or the Privacy Policy / Terms URL doesn't return HTTP 200. Use the Desorix legal pages and check they load in a private window. |
| App went back to Development mode on its own | Meta could no longer load your Privacy Policy or Terms URL, or flagged an app setting. Check App settings → Basic and your email for a notice from Meta. |
| Error 190: access token has expired | You used the temporary token from API Setup, or the token was revoked. Create a permanent system user token. |
| Error 200 or 10: permission not granted | The token lacks whatsapp_business_messaging / whatsapp_business_management, or the system user wasn't given the app or the WhatsApp account with Full control. Redo Assign assets and generate a new token. |
| Error 133010: phone number not registered | Register the number with your two-step verification PIN. |
| Error 133016: too many registration attempts | Wait 72 hours, then register once with the correct PIN. |
| Error 131030: recipient not in allowed list | You're sending from Meta's test number, which only sends to up to 5 numbers added under To on API Setup. Add the recipient there, or connect a real number. |
| Error 131047: re-engagement message | More than 24 hours have passed since the customer last messaged you. Send an approved template instead; Desorix switches the inbox to template-only mode outside the window. |
| Error 131042: payment issue, or replies stop arriving from 1 Oct 2026 | No valid payment method on the WhatsApp Business Account, or the credit line is over its limit. Add a payment method. |
| Error 131031 or 368: account restricted | Meta restricted the WhatsApp Business Account for a policy issue. Check WhatsApp Manager and Business Support Home for the reason and appeal there. |
| Number shows Pending or Offline in WhatsApp Manager | Not registered yet, or the display name is under review. Register it. |
Sources
- Meta: WhatsApp webhooks overview: Live mode warning; list of webhook fields; Configuration path for use-case apps; App Review for advanced access is for partners onboarding other businesses.
- Meta: Create a webhook endpoint: verification GET request (
hub.mode,hub.challenge,hub.verify_token), valid TLS required and self-signed certificates not supported,X-Hub-Signature-256signed with the App Secret. - Meta: Cloud API get started: Create app flow, "Connect with customers through WhatsApp" use case, Quickstart and API Setup pages, test number.
- Meta: Business Management API get started: creating a system user, assigning assets with Full control, generating the token.
- Meta: Access tokens: system user token types (Admin vs Employee), permissions, temporary user tokens for testing only.
- Meta: Business phone numbers: number requirements, adding numbers, two-step verification PIN in WhatsApp Manager, Connected status.
- Meta: Registration:
POST /{phone-number-id}/register, PIN behaviour, 10 attempts per 72 hours (error 133016). - Meta: Messaging limits: portfolio-level tiers 250 → 2,000 → 10,000 → 100,000 → unlimited, what counts, how limits increase.
- Meta: Error codes: 190, 10, 200, 131031, 131042, 131047, 133010, 368.
- Meta: Pricing updates for service messages: service messages charged per message from 1 October 2026.
- 360dialog: Service message charging starts October 1, 2026: no payment method on file by 30 September 2026 means service messages stop being delivered; 1,000 free service messages per number per month.
- Meta: Access levels: Business apps get Standard Access automatically; Standard Access needs no App Review.
- Meta: App modes: what Development and Live mode allow.
- Meta: Basic settings: fields required to switch to Live; business verification not required to go Live.
- respond.io: WhatsApp Cloud API help: reports the Privacy Policy URL being enforced by the Live toggle.
Last verified: 2026-09-26 against Meta's documentation and a live end-to-end test on staging. That test covered a Live app without App Review, webhook verification, WABA subscription by Test connection, a template delivered and read, cost recording, and an inbound reply with the profile name. The payment-method rule, the 1,000 free service messages, error 131030 and the 5-recipient test-number limit come from secondary sources and aren't confirmed yet.