{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "whatsapp-cloud-api",
    "name": "WhatsApp Business Platform (Cloud API)",
    "vendor": "Meta Platforms, Inc.",
    "vendorUrl": "https://developers.facebook.com",
    "kind": "http-api",
    "category": "messaging",
    "summary": "Meta's WhatsApp Business Platform Cloud API sends and receives WhatsApp messages for a business phone number through the Graph API, with inbound messages and status updates arriving by webhook. Access uses a Meta developer app and OAuth access tokens.",
    "url": "https://www.anchorterminal.com/tools/whatsapp-cloud-api",
    "markdownUrl": "https://www.anchorterminal.com/tools/whatsapp-cloud-api.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/whatsapp-cloud-api.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/whatsapp-cloud-api.json",
    "repo": "https://github.com/facebook/openapi",
    "license": "Proprietary service under the Meta Terms for WhatsApp Business Platform. The OpenAPI document in facebook/openapi is MIT",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://graph.facebook.com",
    "packages": [],
    "auth": "oauth",
    "authNotes": "Every call needs a Bearer access token from a Meta developer app with the WhatsApp use case. Access is self-serve for a business using its own account, with no App Review. A person creates the app, a business portfolio and a system user in Meta's dashboards, then generates a system user token with `whatsapp_business_messaging` and `whatsapp_business_management`. Apps that act for other businesses need Advanced access through App Review and onboard customers with Embedded Signup. Business verification raises the messaging limit above 250 recipients a day.",
    "pricing": "usage",
    "pricingNotes": "Charged per delivered message, by category (marketing, utility, authentication, service) and recipient country, with no platform or per-number fee found. Meta publishes rate cards as CSV and PDF in 16 currencies. We couldn't read the files, and the one rate we saw in prose is 0.68 US cents for a utility or authentication message to Brazil. Service messages are charged from 1 October 2026 per Meta's timeline. A test account and test number send without a payment method, so an agent can start without a contract (checked 2026-10-08).",
    "priceSummary": "Pay per use",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the WhatsApp documentation, the llms.txt indexes, the pricing pages or the OpenAPI document (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://developers.facebook.com/documentation/business-messaging/whatsapp/overview",
    "llmsTxt": "https://developers.facebook.com/documentation/business-messaging/whatsapp/llms.txt",
    "openapi": "https://raw.githubusercontent.com/facebook/openapi/main/business-messaging-api_v23.0.yaml",
    "capabilities": [
      "messaging.whatsapp",
      "messaging.inbound"
    ],
    "tags": [
      "hosted",
      "usage-based",
      "oauth",
      "openapi",
      "llms-txt",
      "webhooks",
      "whatsapp",
      "mcp",
      "sandbox",
      "status-page",
      "bug-bounty",
      "soc2"
    ],
    "lastRelease": "2026-08-11",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 67.1,
      "grade": "B",
      "agentReady": false,
      "rank": 218,
      "ranked": true,
      "rankOf": 722,
      "categoryRank": 5,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 67,
        "maintenance": 34,
        "payments": 40,
        "reliability": 80,
        "schema": 82,
        "security": 67,
        "transparency": 82
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 80,
          "points": 16,
          "reason": "Graded on the public Cloud API, with the hosted lines. metastatus.com lists the WhatsApp Business Platform with a Cloud API component, an incident history and availability and latency figures (20). The Cloud API component shows no incident in the 90 days to 8 October 2026. The Marketing Messages API had high disruptions for 70 minutes on 19 July, and Meta Business Agent a 20-minute low disruption on 1 October, so we departed from the full 30 (25). Before the window, Cloud API had high disruptions for about 2 hours 40 minutes on 12 June and medium disruptions on 23 June. Limits are published with numbers for throughput, per recipient and management calls (15). Throttling codes are documented with a 4^X second backoff rule for the per-recipient limit. No Retry-After header on message sends and no idempotency key were found (10). No SLA found. Meta's terms on facebook.com couldn't be read (0). Cloud API is generally available, while the MCP server is in beta (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 82,
          "points": 13.33,
          "reason": "A public OpenAPI 3.1 document in facebook/openapi with 78 paths, 113 operations and 369 schemas. It is pinned to v23.0 while the Graph API is at v26.0, so 3 off (22). llms.txt indexes and a Markdown copy of every guide and reference page (10). Guides explain when a template is required, when the service window applies and which token type suits which developer. Reference text is thin in places, and the send endpoint's description reads only Send Message (13). Request schemas carry types, required marks and 201 enum lists, with templates and interactive messages as nested objects (12). Request examples on most pages, example webhook payloads and an error code reference. Examples mix v17.0, v23.0 and v25.0 (13). Graph API versions with a dated table, and a WhatsApp changelog whose only 2026 entry is 12 May (12)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 67,
          "points": 10.89,
          "reason": "Graph API reads take `fields` and `limit`, and one field, `health_status`, summarises whether a number can send. The MCP server isn't what we graded (20). Cursor paging on list edges and filters on template and analytics reads. Inbound messages can't be listed or paged and arrive only by webhook (18). Errors carry `code`, `error_data.details` and `fbtrace_id`, and the reference maps codes to causes and fixes. Some failures arrive only by webhook (18). No idempotency key for sends was found in the docs or the OpenAPI document, and webhook receivers must deduplicate. The MCP send tool asks for confirmation (5). A text send needs four fields. Receiving needs a public HTTPS server, and Meta has no current SDK for Cloud API since archiving its Node.js one (6)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 67,
          "points": 11.73,
          "reason": "OAuth access tokens with permissions that separate messaging from account management, revocable, with a chosen expiry on system user tokens. The documented `debug_token` call passes the token to inspect as a query parameter, which costs 10 (20). System users can hold partial, view-only access to one WhatsApp Business account, and Meta reviews templates before they can be sent. The API has no approval step before a send (13). Inbound user messages are untrusted content. Meta's MCP documentation warns about prompt injection from webhook payloads and advises against write scopes for agents that read untrusted input. The Cloud API docs carry no such guidance (8). No audit log of API calls was found. Per-message status webhooks, `fbtrace_id`, and messaging and pricing analytics give partial visibility (7). security.txt valid to 7 November 2026, a bug bounty, SOC 2 Type II and ISO 27001 reports for Cloud API, HMAC-signed webhooks and optional mutual TLS (19)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 40,
          "points": 5,
          "reason": "No x402, MPP or L402 (0). Per-message pricing is public without a login, as CSV and PDF rate cards in 16 currencies and an interactive table on whatsappbusiness.com. We couldn't open the rate files and scored the line on the public pages that list them (20). A test WhatsApp Business account and number send template messages with no payment method (20). A person has to create a Meta account, a developer app and a system user in a browser (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 34,
          "points": 2.98,
          "reason": "Closed service. The newest dated API change we found is the OpenAPI document's update on 11 August 2026, 58 days ago, after Graph API v26.0 on 29 July (20). Two dated changes in the 90 days to 8 October, and the WhatsApp changelog's last entry is 12 May 2026, so the three-entry line isn't met (0). A changelog, developer support, a community forum, bug reports and Direct Support with a 24-hour first-response aim for partners. The changelog has one entry in 2026 (8). No current official SDK. The Node.js SDK is archived at 0.0.5-Alpha from April 2023, and the MCP server isn't in the official MCP registry. A Postman collection and the OpenAPI document exist (3). The OpenAPI repository is active but still at v23.0 (3)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 82,
          "points": 7.18,
          "note": "editorial 70, provenance 94",
          "reason": "Editorial half only. Closed service with named terms and policies and an MIT OpenAPI document. The Meta Terms for WhatsApp Business Platform render only with JavaScript and weren't read (15). The docs state Meta is processor for Cloud API, messages are kept at most 30 days and encrypted at rest, and the data processing terms of 22 August 2025 agree on processor duties, breach notice and deletion on termination (25). Graph API versions carry end dates about two years out, the pricing calendar fixes one, three and six months' notice, and deprecated fields are flagged in the docs (20). Processing is in Meta data centres with optional in-country storage. The data processing terms allow Meta companies and third parties as sub-processors, and the list is said to be in the hosting terms, which we couldn't read (10)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Graph API reads take `fields` and `limit`, and one field, `health_status`, summarises whether a number can send. The MCP server isn't what we graded (20). Cursor paging on list edges and filters on template and analytics reads. Inbound messages can't be listed or paged and arrive only by webhook (18). Errors carry `code`, `error_data.details` and `fbtrace_id`, and the reference maps codes to causes and fixes. Some failures arrive only by webhook (18). No idempotency key for sends was found in the docs or the OpenAPI document, and webhook receivers must deduplicate. The MCP send tool asks for confirmation (5). A text send needs four fields. Receiving needs a public HTTPS server, and Meta has no current SDK for Cloud API since archiving its Node.js one (6).",
          "maintenance": "Closed service. The newest dated API change we found is the OpenAPI document's update on 11 August 2026, 58 days ago, after Graph API v26.0 on 29 July (20). Two dated changes in the 90 days to 8 October, and the WhatsApp changelog's last entry is 12 May 2026, so the three-entry line isn't met (0). A changelog, developer support, a community forum, bug reports and Direct Support with a 24-hour first-response aim for partners. The changelog has one entry in 2026 (8). No current official SDK. The Node.js SDK is archived at 0.0.5-Alpha from April 2023, and the MCP server isn't in the official MCP registry. A Postman collection and the OpenAPI document exist (3). The OpenAPI repository is active but still at v23.0 (3).",
          "payments": "No x402, MPP or L402 (0). Per-message pricing is public without a login, as CSV and PDF rate cards in 16 currencies and an interactive table on whatsappbusiness.com. We couldn't open the rate files and scored the line on the public pages that list them (20). A test WhatsApp Business account and number send template messages with no payment method (20). A person has to create a Meta account, a developer app and a system user in a browser (0).",
          "reliability": "Graded on the public Cloud API, with the hosted lines. metastatus.com lists the WhatsApp Business Platform with a Cloud API component, an incident history and availability and latency figures (20). The Cloud API component shows no incident in the 90 days to 8 October 2026. The Marketing Messages API had high disruptions for 70 minutes on 19 July, and Meta Business Agent a 20-minute low disruption on 1 October, so we departed from the full 30 (25). Before the window, Cloud API had high disruptions for about 2 hours 40 minutes on 12 June and medium disruptions on 23 June. Limits are published with numbers for throughput, per recipient and management calls (15). Throttling codes are documented with a 4^X second backoff rule for the per-recipient limit. No Retry-After header on message sends and no idempotency key were found (10). No SLA found. Meta's terms on facebook.com couldn't be read (0). Cloud API is generally available, while the MCP server is in beta (10).",
          "schema": "A public OpenAPI 3.1 document in facebook/openapi with 78 paths, 113 operations and 369 schemas. It is pinned to v23.0 while the Graph API is at v26.0, so 3 off (22). llms.txt indexes and a Markdown copy of every guide and reference page (10). Guides explain when a template is required, when the service window applies and which token type suits which developer. Reference text is thin in places, and the send endpoint's description reads only Send Message (13). Request schemas carry types, required marks and 201 enum lists, with templates and interactive messages as nested objects (12). Request examples on most pages, example webhook payloads and an error code reference. Examples mix v17.0, v23.0 and v25.0 (13). Graph API versions with a dated table, and a WhatsApp changelog whose only 2026 entry is 12 May (12).",
          "security": "OAuth access tokens with permissions that separate messaging from account management, revocable, with a chosen expiry on system user tokens. The documented `debug_token` call passes the token to inspect as a query parameter, which costs 10 (20). System users can hold partial, view-only access to one WhatsApp Business account, and Meta reviews templates before they can be sent. The API has no approval step before a send (13). Inbound user messages are untrusted content. Meta's MCP documentation warns about prompt injection from webhook payloads and advises against write scopes for agents that read untrusted input. The Cloud API docs carry no such guidance (8). No audit log of API calls was found. Per-message status webhooks, `fbtrace_id`, and messaging and pricing analytics give partial visibility (7). security.txt valid to 7 November 2026, a bug bounty, SOC 2 Type II and ISO 27001 reports for Cloud API, HMAC-signed webhooks and optional mutual TLS (19).",
          "transparency": "Editorial half only. Closed service with named terms and policies and an MIT OpenAPI document. The Meta Terms for WhatsApp Business Platform render only with JavaScript and weren't read (15). The docs state Meta is processor for Cloud API, messages are kept at most 30 days and encrypted at rest, and the data processing terms of 22 August 2025 agree on processor duties, breach notice and deletion on termination (25). Graph API versions carry end dates about two years out, the pricing calendar fixes one, three and six months' notice, and deprecated fields are flagged in the docs (20). Processing is in Meta data centres with optional in-country storage. The data processing terms allow Meta companies and third parties as sub-processors, and the list is said to be in the hosting terms, which we couldn't read (10)."
        },
        "sources": [
          {
            "what": "developer llms.txt",
            "url": "https://developers.facebook.com/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "WhatsApp docs index",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "API reference index",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/reference/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "get started guide",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/get-started",
            "seen": "2026-10-08"
          },
          {
            "what": "about the platform, rate limits",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/about-the-platform",
            "seen": "2026-10-08"
          },
          {
            "what": "access tokens",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/access-tokens",
            "seen": "2026-10-08"
          },
          {
            "what": "permissions and App Review",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/permissions",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/pricing",
            "seen": "2026-10-08"
          },
          {
            "what": "pricing for non-template messages",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/pricing/non-template-messages",
            "seen": "2026-10-08"
          },
          {
            "what": "AI Providers pricing policy",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/pricing/ai-providers",
            "seen": "2026-10-08"
          },
          {
            "what": "interactive pricing page",
            "url": "https://whatsappbusiness.com/products/platform-pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "throughput",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/throughput",
            "seen": "2026-10-08"
          },
          {
            "what": "messaging limits",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/messaging-limits",
            "seen": "2026-10-08"
          },
          {
            "what": "sending messages and service windows",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/messages/send-messages",
            "seen": "2026-10-08"
          },
          {
            "what": "error codes",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/support/error-codes",
            "seen": "2026-10-08"
          },
          {
            "what": "webhook endpoint requirements",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/webhooks/create-webhook-endpoint",
            "seen": "2026-10-08"
          },
          {
            "what": "health status",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/support/health-status",
            "seen": "2026-10-08"
          },
          {
            "what": "data privacy and security",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/data-privacy-and-security",
            "seen": "2026-10-08"
          },
          {
            "what": "local storage",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/local-storage",
            "seen": "2026-10-08"
          },
          {
            "what": "support channels",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/support",
            "seen": "2026-10-08"
          },
          {
            "what": "policy enforcement",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/policy-enforcement",
            "seen": "2026-10-08"
          },
          {
            "what": "WhatsApp changelog",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "Marketing Messages API changelog",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/marketing-messages/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "Graph API changelog and version table",
            "url": "https://developers.facebook.com/docs/graph-api/changelog",
            "seen": "2026-10-08"
          },
          {
            "what": "status page documentation",
            "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/support/api-status-page",
            "seen": "2026-10-08"
          },
          {
            "what": "status history",
            "url": "https://metastatus.com/data/outages/whatsapp-business-api.history.json",
            "seen": "2026-10-08"
          },
          {
            "what": "OpenAPI repository",
            "url": "https://github.com/facebook/openapi",
            "seen": "2026-10-08"
          },
          {
            "what": "Meta MCP overview",
            "url": "https://developers.facebook.com/documentation/mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "WhatsApp Business Tools MCP",
            "url": "https://developers.facebook.com/documentation/mcp/whatsapp-business-tools-mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "MCP protected resource metadata",
            "url": "https://mcp.facebook.com/.well-known/oauth-protected-resource/whatsapp_business_tools",
            "seen": "2026-10-08"
          },
          {
            "what": "official MCP registry search",
            "url": "https://registry.modelcontextprotocol.io/v0/servers?search=whatsapp",
            "seen": "2026-10-08"
          },
          {
            "what": "archived Node.js SDK",
            "url": "https://github.com/WhatsApp/WhatsApp-Nodejs-SDK",
            "seen": "2026-10-08"
          },
          {
            "what": "Node.js SDK on npm",
            "url": "https://registry.npmjs.org/whatsapp",
            "seen": "2026-10-08"
          },
          {
            "what": "WhatsApp Business Data Processing Terms",
            "url": "https://www.whatsapp.com/legal/business-data-processing-terms",
            "seen": "2026-10-08"
          },
          {
            "what": "Business Messaging Compliance Centre",
            "url": "https://www.facebook.com/business/business-messaging/compliance",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt",
            "url": "https://www.facebook.com/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP for facebook.com",
            "url": "https://rdap.verisign.com/com/v1/domain/facebook.com",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "unchecked: the Meta Terms for WhatsApp Business Platform and the Cloud API hosting terms on www.facebook.com render only with JavaScript, so the terms, any SLA, the sub-processor list and the wording of the AI Providers clause weren't read",
          "unchecked: the rate card CSV and PDF files. The docs' Markdown copy drops their links, and the interactive table on whatsappbusiness.com loads rates from an endpoint that needs a page token, which we didn't use",
          "unchecked: GitHub stars and open issues for facebook/openapi. The GitHub API refused us for its rate limit",
          "unchecked: the MCP server's tool schemas and annotations, which need a signed-in Meta account to list. Tool names come from the documentation",
          "unchecked: the official Postman workspace, which renders only with JavaScript",
          "unchecked: WhatsApp entries in the Graph API v26.0 changelog page, which wasn't opened",
          "The main pricing page says non-template messages are free, while the non-template pricing page says service messages are charged from 1 October 2026. We recorded the later page's timeline",
          "provenance.privacy points at the WhatsApp Business Data Processing Terms, which we read. Whether the Cloud API hosting terms are the better governing document couldn't be settled without reading them",
          "The AI Providers restriction is taken from Meta's pricing page describing the terms. An operator running a general-purpose assistant should read the terms before building",
          "No idempotency key, no Retry-After header on message sends and no SLA were found in the reviewed documentation",
          "Not tested with a live account, as we had no Meta developer app",
          "The lead held up. The docs have moved from /docs/whatsapp/cloud-api to /documentation/business-messaging/whatsapp, and the lead didn't mention the OpenAPI document or the beta MCP server"
        ]
      },
      "negative": 0,
      "verdict": "The first-party WhatsApp API has a public OpenAPI document, Markdown docs with llms.txt, numeric rate limits and a test number that sends without a payment method. Setup needs a person in three Meta dashboards, no idempotency key was found for sends, and Meta's terms restrict general-purpose AI assistants on the platform.",
      "bestFor": "The direct route to WhatsApp for a business messaging its own customers, with no reseller fee.",
      "strengths": [
        "A test WhatsApp Business account and test number are created with the app and send template messages with no payment method on file",
        "OpenAPI 3.1 document under MIT in facebook/openapi (78 paths, 113 operations), plus llms.txt indexes and a Markdown copy of each docs page",
        "Limits are published with numbers, including 80 messages a second per number, 5,000 requests an hour per active account and one message every 6 seconds per recipient",
        "Message data is kept for at most 30 days, with local storage and no-storage options per phone number, and SOC 2 Type II and ISO 27001 reports for Cloud API",
        "Webhook payloads are signed with HMAC-SHA256 in `X-Hub-Signature-256`, and mutual TLS is available"
      ],
      "weaknesses": [
        "A person has to create a Meta account, a developer app, a business portfolio and a system user in a browser before any token exists",
        "No idempotency key for message sends was found in the reviewed documentation or the OpenAPI document, so a retried send can reach the user twice",
        "Meta's pricing page says the 15 January 2026 terms permit general-purpose AI assistants only where Meta is legally required to allow them",
        "Outside the 24-hour customer service window only pre-approved templates can be sent, and a new business portfolio is limited to 250 recipients in 24 hours",
        "Meta archived its Node.js SDK, and the published OpenAPI document is pinned to v23.0 while the Graph API is at v26.0"
      ],
      "agentNotes": [
        "Check when the user last wrote. Free-form messages are accepted only within 24 hours of the user's last message. After that, send an approved template.",
        "Record the message id from each send and match it to `messages` webhook statuses. Many failures arrive only by webhook, and no idempotency key was found.",
        "On error 130429 or 131056 wait and retry. Meta's guidance for the per-recipient limit is 4^X seconds, with X rising by one per failure.",
        "Verify `X-Hub-Signature-256` with the app secret on every webhook, and deduplicate, because failed deliveries are retried for up to 7 days.",
        "Request `health_status` on the phone number before a campaign to see whether the app, business, account, number and template can send."
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "B",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 67.1
        }
      ],
      "editorialScores": {
        "ergonomics": 67,
        "maintenance": 34,
        "payments": 40,
        "reliability": 80,
        "schema": 82,
        "security": 67,
        "transparency": 70
      },
      "provenanceScore": 94
    },
    "connect": {
      "http": "curl 'https://graph.facebook.com/v23.0/\u003cBUSINESS_PHONE_NUMBER_ID\u003e/messages' \\\n  -H 'Content-Type: application/json' \\\n  -H 'Authorization: Bearer \u003cSYSTEM_USER_ACCESS_TOKEN\u003e' \\\n  -d '{\"messaging_product\":\"whatsapp\",\"recipient_type\":\"individual\",\"to\":\"\u003cWHATSAPP_USER_PHONE_NUMBER\u003e\",\"type\":\"text\",\"text\":{\"body\":\"Hello!\"}}'",
      "claudeCode": "claude mcp add --transport http whatsapp_business_tools https://mcp.facebook.com/whatsapp_business_tools"
    },
    "letme": {
      "capability": "https://letme.dev/messaging.whatsapp",
      "tool": "https://letme.dev/whatsapp-cloud-api"
    },
    "sameCompany": [
      "meta-marketing-api"
    ],
    "notable": [
      "Cloud API allows 80 messages a second per business phone number by default and 1,000 by automatic upgrade, and returns error 130429 above that (https://developers.facebook.com/documentation/business-messaging/whatsapp/throughput)",
      "A new business portfolio can message 250 unique users in a moving 24 hours outside customer service windows, rising to 2,000, 10,000, 100,000 and unlimited (https://developers.facebook.com/documentation/business-messaging/whatsapp/messaging-limits)",
      "Meta's timeline says service messages and utility templates sent inside the 24-hour window are charged per message from 1 October 2026, after being free since November 2024 and July 2025 (https://developers.facebook.com/documentation/business-messaging/whatsapp/pricing/non-template-messages)",
      "The AI Providers pricing page says that from 15 January 2026 the terms permit general-purpose AI assistants on the platform only where Meta is legally required to allow them (https://developers.facebook.com/documentation/business-messaging/whatsapp/pricing/ai-providers)",
      "Meta hosts a WhatsApp Business Tools MCP server at https://mcp.facebook.com/whatsapp_business_tools, in beta and rolling out gradually, with 18 documented tools and OAuth sign-in (https://developers.facebook.com/documentation/mcp/whatsapp-business-tools-mcp)",
      "The OpenAPI 3.1 document in facebook/openapi covers 78 paths and 113 operations at v23.0, MIT licensed, last changed on 11 August 2026 (https://github.com/facebook/openapi)",
      "The status history lists no Cloud API incident between 24 June and 8 October 2026. On 12 June 2026 Cloud API had high disruptions for about 2 hours 40 minutes (https://metastatus.com/whatsapp-business-api)",
      "Messages are kept for at most 30 days, and Meta says it has SOC 2 Type II and ISO 27001 reports for Cloud API (https://developers.facebook.com/documentation/business-messaging/whatsapp/data-privacy-and-security)"
    ],
    "area": "communication",
    "details": [
      {
        "label": "API",
        "value": "Graph API at https://graph.facebook.com/\u003cversion\u003e. Cloud API for messages, media, calling and groups, and the Business Management API for accounts, phone numbers, templates and analytics. The reference index lists 66 pages"
      },
      {
        "label": "Versions",
        "value": "Graph API v26.0 from 29 July 2026, v25.0 from 18 February 2026. Each version stays available for about two years (v23.0 until 8 October 2027). Docs examples use v17.0, v23.0 and v25.0"
      },
      {
        "label": "Access",
        "value": "A Meta developer app with the WhatsApp use case, a business portfolio and a WhatsApp Business account. Direct developers need no App Review. Apps acting for other businesses need Advanced access through App Review and Embedded Signup"
      },
      {
        "label": "Credentials",
        "value": "System user access tokens with a chosen expiry, business integration system user tokens per onboarded customer, and short-lived user tokens. Permissions `whatsapp_business_messaging`, `whatsapp_business_management` and `business_management`. Partial or full asset access per WhatsApp Business account"
      },
      {
        "label": "Message rules",
        "value": "Free-form messages only within 24 hours of the user's last message. Outside that window only templates, which Meta reviews and places in the marketing, utility or authentication category. Users must have opted in"
      },
      {
        "label": "Rate limits",
        "value": "80 messages a second per number (1,000 by automatic upgrade, 20 for numbers shared with the WhatsApp Business app). One message every 6 seconds to the same user, with bursts of 45. Management endpoints 200 requests an hour per app and account, 5,000 for active accounts"
      },
      {
        "label": "Messaging limits",
        "value": "Unique users reachable outside service windows in a moving 24 hours, per business portfolio. 250 at first, then 2,000 after business verification or 2,000 good-quality sends in 30 days, then 10,000, 100,000 and unlimited"
      },
      {
        "label": "Webhooks",
        "value": "Inbound messages and delivery statuses arrive only by webhook. HMAC-SHA256 signature in `X-Hub-Signature-256`, optional mutual TLS, batches of up to 1,000 updates, retries with backoff for up to 7 days, and no API for past webhook data"
      },
      {
        "label": "Errors",
        "value": "JSON error object with `code`, `message`, `error_data.details` and `fbtrace_id`. Throttling codes 4, 80007, 130429, 131048 and 131056. Some errors arrive only in the `messages` webhook"
      },
      {
        "label": "Pricing model",
        "value": "Per delivered message, by category and recipient country, with volume tiers for utility and authentication. Rate cards as CSV and PDF in 16 currencies. Rates may change on the first day of a quarter, with one month's notice for rates and six for a model change"
      },
      {
        "label": "Test resources",
        "value": "A test WhatsApp Business account and test number are created with the app, have relaxed limits and need no payment method to send template messages"
      },
      {
        "label": "Data handling",
        "value": "Meta is processor for Cloud API. Messages kept at most 30 days, media 30 days, encrypted at rest. Local storage keeps message content at rest in a chosen region, and a no-storage option was added on 1 December 2025"
      },
      {
        "label": "MCP server",
        "value": "https://mcp.facebook.com/whatsapp_business_tools, streamable HTTP, OAuth with the three WhatsApp permissions, 18 documented tools for accounts, numbers, templates, webhooks and sending. Beta, rolling out gradually. The send tool asks for confirmation"
      },
      {
        "label": "SDKs and tools",
        "value": "No current official SDK for Cloud API. The WhatsApp Node.js SDK (npm `whatsapp` 0.0.5-Alpha, April 2023) is archived. An official Postman collection and an API playground in the reference"
      },
      {
        "label": "Certifications",
        "value": "SOC 2 Type II, SOC 3, ISO 27001, GDPR and LGPD documents for Cloud API listed in the Business Messaging Compliance Centre. Bug bounty at bugbounty.meta.com"
      },
      {
        "label": "Status",
        "value": "metastatus.com/whatsapp-business-api, with components for Cloud API, localised storage, account management, Embedded Signup and the Marketing Messages API, availability and latency figures for Cloud API, and a JSON and RSS history"
      }
    ],
    "unitPrices": [
      {
        "item": "Utility or authentication template, Brazil",
        "unit": "message",
        "usd": 0.0068,
        "note": "the one rate quoted in prose on Meta's non-template pricing page. Rates vary by country and category, and the rate card files weren't read"
      }
    ],
    "provenance": {
      "legalEntity": "Meta Platforms, Inc.",
      "domain": "facebook.com",
      "domainRegistered": "1997-03-29",
      "endpointOnVendorDomain": true,
      "terms": "https://www.facebook.com/legal/Meta-Terms-for-WhatsApp-Business-Platform",
      "privacy": "https://www.whatsapp.com/legal/business-data-processing-terms",
      "statusPage": "https://metastatus.com/whatsapp-business-api",
      "changelog": "https://developers.facebook.com/documentation/business-messaging/whatsapp/changelog",
      "securityTxt": "valid",
      "checked": "2026-10-08",
      "notes": [
        "The API answers at graph.facebook.com and the MCP server at mcp.facebook.com, both facebook.com subdomains.",
        "www.whatsapp.com/legal/business-solution-terms and /legal/meta-terms-whatsapp-business both redirect to www.facebook.com/legal/Meta-Terms-for-WhatsApp-Business-Platform. That page and the Cloud API hosting terms at www.facebook.com/legal/WhatsApp-Business-Platform-Cloud-API render only with JavaScript, so their text wasn't read.",
        "The privacy field points at the WhatsApp Business Data Processing Terms (last updated 22 August 2025), which we read. Meta's docs name the Cloud API hosting terms as the other data document for Cloud API customers.",
        "The legal entity is taken from the copyright line of the MIT licence in facebook/openapi. The data processing terms name WhatsApp LLC and WhatsApp Ireland Limited as contracting entities.",
        "www.facebook.com/.well-known/security.txt and www.whatsapp.com/.well-known/security.txt name a contact, the bug bounty policy at bugbounty.meta.com and a disclosure policy, and expire on 7 November 2026.",
        "RDAP for facebook.com gives a registration date of 1997-03-29.",
        "The WhatsApp changelog's newest entry is 12 May 2026, and the one before it 8 December 2025."
      ],
      "score": 94,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Meta Platforms, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "facebook.com, registered 1997-03-29 (29 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "graph.facebook.com",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Terms of service",
          "value": "published, but our reader couldn't read it",
          "points": 7,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 4 of the 8 things a reader expects",
          "points": 7,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "metastatus.com/whatsapp-business-api",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "valid",
          "points": 10,
          "max": 10,
          "state": "ok"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.facebook.com/legal/Meta-Terms-for-WhatsApp-Business-Platform",
          "state": "unreadable",
          "reason": "robots.txt asks readers like ours not to fetch it",
          "readAt": "2026-10-08",
          "points": 7,
          "max": 10
        },
        {
          "kind": "privacy",
          "url": "https://www.whatsapp.com/legal/business-data-processing-terms",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2025-08-22",
          "words": 1196,
          "points": 7,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Last updated: 22 August 2025",
              "says": "Last updated 2025-08-22"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "the types of Personal Information Processed comprise customer contact information as described in the Business Terms;"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": false
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "WhatsApp may subcontract its Processing obligations under these Data Processing Terms to a sub-processor, who may be based in a country other than the one in which you or WhatsApp are located given the global nature of the WhatsApp service, including the European Economic Area or the United States, only by way of writ…"
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "…to you as a Controller to respond to requests from Data Subjects regarding the exercise of their Data Subject rights;"
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": false
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": false
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The customer authorises WhatsApp to engage other Meta Companies and third parties as sub-processors, and a customer who objects to a change may stop using the Business Services.",
              "quote": "If you reasonably object to such changes, you may inform WhatsApp in writing and stop using our Business Services; and"
            },
            {
              "date": "2026-10-08",
              "text": "When the Business Terms end, WhatsApp stops processing the personal information and deletes it within the period the Business Terms set, with exceptions for legal storage duties and independent rights.",
              "quote": "Upon termination of the Business Terms, WhatsApp shall cease Processing Personal Information and shall delete it within the time period set forth in the Business Terms"
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/whatsapp-cloud-api.json",
    "live": {
      "slug": "whatsapp-cloud-api",
      "probe": {
        "target": "https://graph.facebook.com",
        "method": "get",
        "lastAt": "2026-10-08T19:53:06.486229417Z",
        "lastOk": true,
        "lastStatus": 400,
        "lastMs": 113,
        "authRequired": false,
        "uptime24h": 100,
        "uptime30d": 100,
        "p50ms24h": 111,
        "p95ms24h": 118,
        "samples24h": 27,
        "samples30d": 27,
        "days": [
          {
            "date": "2026-10-08",
            "probes": 27,
            "ok": 27
          }
        ]
      },
      "vendorStatus": {
        "page": "https://metastatus.com/whatsapp-business-api",
        "indicator": "unknown",
        "summary": "no machine-readable status found",
        "checkedAt": "2026-10-08T19:39:20.381545782Z"
      },
      "pages": [
        {
          "url": "https://developers.facebook.com/documentation/business-messaging/whatsapp/changelog",
          "kind": "changelog",
          "status": 200,
          "checkedAt": "2026-10-08T18:17:37.55658412Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "c1607719e42e"
        },
        {
          "url": "https://www.whatsapp.com/legal/business-data-processing-terms",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-08T18:31:35.269938621Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "3a883fb460c8"
        },
        {
          "url": "https://www.facebook.com/legal/Meta-Terms-for-WhatsApp-Business-Platform",
          "kind": "terms",
          "status": 0,
          "checkedAt": "2026-10-08T18:27:43.250256264Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "blockedByRobots": true
        }
      ],
      "updatedAt": "2026-10-08T19:53:06.486229417Z"
    }
  }
}
