WhatsApp Business Platform (Cloud API)

by Meta Platforms, Inc. HTTP API in Messaging APIs

Hosted

Meta Platforms, Inc. · facebook.com since 1997 · status page · who's behind it

Meta's WhatsApp Business Platform Cloud API sends and receives WhatsApp messages for a business phone number through the Graph API, with inbound messages and status updates arriving by webhook. Access uses a Meta developer app and OAuth access tokens.

Good for The direct route to WhatsApp for a business messaging its own customers, with no reseller fee.

Is this your product? Claim this listing or verify it

More from Meta Platforms, Inc. Meta Marketing API (Advertising)

Assessment. The first-party WhatsApp API has a public OpenAPI document, Markdown docs with llms.txt, numeric rate limits and a test number that sends without a payment method. Setup needs a person in three Meta dashboards, no idempotency key was found for sends, and Meta's terms restrict general-purpose AI assistants on the platform.

Facts

Transport
HTTP
Endpoint
https://graph.facebook.com
Auth
OAuth
Pricing
Pay per use · Pay per use
x402
No
Licence
Proprietary service under the Meta Terms for WhatsApp Business Platform. The OpenAPI document in facebook/openapi is MIT
llms.txt
published
Last release
API
Graph API at https://graph.facebook.com/<version>. Cloud API for messages, media, calling and groups, and the Business Management API for accounts, phone numbers, templates and analytics. The reference index lists 66 pages
Versions
Graph API v26.0 from 29 July 2026, v25.0 from 18 February 2026. Each version stays available for about two years (v23.0 until 8 October 2027). Docs examples use v17.0, v23.0 and v25.0
Access
A Meta developer app with the WhatsApp use case, a business portfolio and a WhatsApp Business account. Direct developers need no App Review. Apps acting for other businesses need Advanced access through App Review and Embedded Signup
Credentials
System user access tokens with a chosen expiry, business integration system user tokens per onboarded customer, and short-lived user tokens. Permissions whatsapp_business_messaging, whatsapp_business_management and business_management. Partial or full asset access per WhatsApp Business account
Message rules
Free-form messages only within 24 hours of the user's last message. Outside that window only templates, which Meta reviews and places in the marketing, utility or authentication category. Users must have opted in
Rate limits
80 messages a second per number (1,000 by automatic upgrade, 20 for numbers shared with the WhatsApp Business app). One message every 6 seconds to the same user, with bursts of 45. Management endpoints 200 requests an hour per app and account, 5,000 for active accounts
Messaging limits
Unique users reachable outside service windows in a moving 24 hours, per business portfolio. 250 at first, then 2,000 after business verification or 2,000 good-quality sends in 30 days, then 10,000, 100,000 and unlimited
Webhooks
Inbound messages and delivery statuses arrive only by webhook. HMAC-SHA256 signature in X-Hub-Signature-256, optional mutual TLS, batches of up to 1,000 updates, retries with backoff for up to 7 days, and no API for past webhook data
Errors
JSON error object with code, message, error_data.details and fbtrace_id. Throttling codes 4, 80007, 130429, 131048 and 131056. Some errors arrive only in the messages webhook
Pricing model
Per delivered message, by category and recipient country, with volume tiers for utility and authentication. Rate cards as CSV and PDF in 16 currencies. Rates may change on the first day of a quarter, with one month's notice for rates and six for a model change
Test resources
A test WhatsApp Business account and test number are created with the app, have relaxed limits and need no payment method to send template messages
Data handling
Meta is processor for Cloud API. Messages kept at most 30 days, media 30 days, encrypted at rest. Local storage keeps message content at rest in a chosen region, and a no-storage option was added on 1 December 2025
MCP server
https://mcp.facebook.com/whatsapp_business_tools, streamable HTTP, OAuth with the three WhatsApp permissions, 18 documented tools for accounts, numbers, templates, webhooks and sending. Beta, rolling out gradually. The send tool asks for confirmation
SDKs and tools
No current official SDK for Cloud API. The WhatsApp Node.js SDK (npm whatsapp 0.0.5-Alpha, April 2023) is archived. An official Postman collection and an API playground in the reference
Certifications
SOC 2 Type II, SOC 3, ISO 27001, GDPR and LGPD documents for Cloud API listed in the Business Messaging Compliance Centre. Bug bounty at bugbounty.meta.com
Status
metastatus.com/whatsapp-business-api, with components for Cloud API, localised storage, account management, Embedded Signup and the Marketing Messages API, availability and latency figures for Cloud API, and a JSON and RSS history

Facts verified 2026-10-08 from vendor docs, repositories and package registries. JSON · Markdown

Strengths

  • A test WhatsApp Business account and test number are created with the app and send template messages with no payment method on file
  • OpenAPI 3.1 document under MIT in facebook/openapi (78 paths, 113 operations), plus llms.txt indexes and a Markdown copy of each docs page
  • Limits are published with numbers, including 80 messages a second per number, 5,000 requests an hour per active account and one message every 6 seconds per recipient
  • Message data is kept for at most 30 days, with local storage and no-storage options per phone number, and SOC 2 Type II and ISO 27001 reports for Cloud API
  • Webhook payloads are signed with HMAC-SHA256 in X-Hub-Signature-256, and mutual TLS is available

Weaknesses

  • A person has to create a Meta account, a developer app, a business portfolio and a system user in a browser before any token exists
  • No idempotency key for message sends was found in the reviewed documentation or the OpenAPI document, so a retried send can reach the user twice
  • Meta's pricing page says the 15 January 2026 terms permit general-purpose AI assistants only where Meta is legally required to allow them
  • Outside the 24-hour customer service window only pre-approved templates can be sent, and a new business portfolio is limited to 250 recipients in 24 hours
  • Meta archived its Node.js SDK, and the published OpenAPI document is pinned to v23.0 while the Graph API is at v26.0

Before you call it notes for agents

  1. Check when the user last wrote. Free-form messages are accepted only within 24 hours of the user's last message. After that, send an approved template.
  2. Record the message id from each send and match it to messages webhook statuses. Many failures arrive only by webhook, and no idempotency key was found.
  3. On error 130429 or 131056 wait and retry. Meta's guidance for the per-recipient limit is 4^X seconds, with X rising by one per failure.
  4. Verify X-Hub-Signature-256 with the app secret on every webhook, and deduplicate, because failed deliveries are retried for up to 7 days.
  5. Request health_status on the phone number before a campaign to see whether the app, business, account, number and template can send.

Who's behind it provenance 94/100

  • Legal entity namedMeta Platforms, Inc.20/20
  • Domain agefacebook.com, registered 1997-03-29 (29 years)15/15
  • Endpoint on the vendor's domaingraph.facebook.com15/15
  • Terms of servicepublished, but our reader couldn't read it7/10
  • Privacy policyread, states 4 of the 8 things a reader expects7/10
  • Status pagemetastatus.com/whatsapp-business-api10/10
  • Changelogpublished10/10
  • security.txtvalid10/10

Terms and privacy, as read

Terms of service our reader couldn't read it

TL;DR Our reader couldn't read it, so nothing here is checked. The document is published and scores 7 of 10 until we can.

robots.txt asks readers like ours not to fetch it.

The document · read 2026-10-08

Privacy policy dated 2025-08-22, states 4 of 8

TL;DR Dated 2025-08-22. States 4 of the 8 things a reader expects, and we didn't find how long data is kept, whether data is sold, a privacy contact or where data goes. The rules found no clause to flag.

Gives the date it was last updated Last updated 2025-08-22
Last updated: 22 August 2025

Without a date nobody can tell which version applied when data was collected.

Says what personal data is collected
the types of Personal Information Processed comprise customer contact information as described in the Business Terms;

The basic statement a privacy policy exists to make.

Says how long data is kept

Not found in the text.

Says when data sent to the service is deleted.

Says who else receives the data
WhatsApp may subcontract its Processing obligations under these Data Processing Terms to a sub-processor, who may be based in a country other than the one in which you or WhatsApp are located given the global nature of the WhatsApp service, including the European Economic Area or the United States, only by way of writ…

Names the sub-processors or service providers the data is passed to, or where they are listed.

Says whether personal data is sold or shared for advertising

Not found in the text.

A plain statement either way.

Says what rights people have over their data
…to you as a Controller to respond to requests from Data Subjects regarding the exercise of their Data Subject rights;

Access, correction, deletion and objection, and how to use them.

Gives a privacy contact

Not found in the text.

An address or officer to send a request to.

Says where data is transferred or stored

Not found in the text.

The countries data goes to and the safeguard used.

The customer authorises WhatsApp to engage other Meta Companies and third parties as sub-processors, and a customer who objects to a change may stop using the Business Services.
If you reasonably object to such changes, you may inform WhatsApp in writing and stop using our Business Services; and

Noted by a second reader on 2026-10-08.

When the Business Terms end, WhatsApp stops processing the personal information and deletes it within the period the Business Terms set, with exceptions for legal storage duties and independent rights.
Upon termination of the Business Terms, WhatsApp shall cease Processing Personal Information and shall delete it within the time period set forth in the Business Terms

Noted by a second reader on 2026-10-08.

The document · read 2026-10-08 · 1,196 words

A reading by a fixed set of rules, each answered with the vendor's own sentence. It isn't legal advice, a rule can miss a clause or misread one, and the document itself is what binds. How it's read and scored.

The API answers at graph.facebook.com and the MCP server at mcp.facebook.com, both facebook.com subdomains.

www.whatsapp.com/legal/business-solution-terms and /legal/meta-terms-whatsapp-business both redirect to www.facebook.com/legal/Meta-Terms-for-WhatsApp-Business-Platform. That page and the Cloud API hosting terms at www.facebook.com/legal/WhatsApp-Business-Platform-Cloud-API render only with JavaScript, so their text wasn't read.

The privacy field points at the WhatsApp Business Data Processing Terms (last updated 22 August 2025), which we read. Meta's docs name the Cloud API hosting terms as the other data document for Cloud API customers.

The legal entity is taken from the copyright line of the MIT licence in facebook/openapi. The data processing terms name WhatsApp LLC and WhatsApp Ireland Limited as contracting entities.

www.facebook.com/.well-known/security.txt and www.whatsapp.com/.well-known/security.txt name a contact, the bug bounty policy at bugbounty.meta.com and a disclosure policy, and expire on 7 November 2026.

RDAP for facebook.com gives a registration date of 1997-03-29.

The WhatsApp changelog's newest entry is 12 May 2026, and the one before it 8 December 2025.

Checked 2026-10-08 against the vendor's own pages and the domain registry. Provenance is half of Transparency & trust.

Live watched around the clock · updated 2026-10-08 19:09 UTC

Right nowUpHTTP 400 · 124 ms · 2 minutes ago
Uptime 24h100.0%19 probes
Uptime 30 days100.0%19 probes
p50 24h111 msget
p95 24h124 msopen endpoint

Probed every five minutes at https://graph.facebook.com. A probe counts as up when the endpoint answers without a server error, including a 401 that asks for credentials.

  • Vendor status page unknown, no machine-readable status found · 1 hour ago

Pages we watch

PageKindLast checkedLast changed
developers.facebook.com/documentation/business-messaging/wh…changelog53 minutes ago · 200no change seen
www.whatsapp.com/legal/business-data-processing-termsprivacy39 minutes ago · 200no change seen
www.facebook.com/legal/Meta-Terms-for-WhatsApp-Business-Pla…termsrobots.txt says nono change seen

Live data comes from our pollers, trackers and scrapers and doesn't change the score until a benchmark run. What we watch · /api/v1/live/whatsapp-cloud-api.json

Notable

  • Cloud API allows 80 messages a second per business phone number by default and 1,000 by automatic upgrade, and returns error 130429 above that source
  • A new business portfolio can message 250 unique users in a moving 24 hours outside customer service windows, rising to 2,000, 10,000, 100,000 and unlimited source
  • Meta's timeline says service messages and utility templates sent inside the 24-hour window are charged per message from 1 October 2026, after being free since November 2024 and July 2025 source
  • The AI Providers pricing page says that from 15 January 2026 the terms permit general-purpose AI assistants on the platform only where Meta is legally required to allow them source
  • Meta hosts a WhatsApp Business Tools MCP server at https://mcp.facebook.com/whatsapp_business_tools, in beta and rolling out gradually, with 18 documented tools and OAuth sign-in source
  • The OpenAPI 3.1 document in facebook/openapi covers 78 paths and 113 operations at v23.0, MIT licensed, last changed on 11 August 2026 source
  • The status history lists no Cloud API incident between 24 June and 8 October 2026. On 12 June 2026 Cloud API had high disruptions for about 2 hours 40 minutes source
  • Messages are kept for at most 30 days, and Meta says it has SOC 2 Type II and ISO 27001 reports for Cloud API source

Reviews by the Anchor panel

Every review here is a desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. The outcome says whether the reviewer's questions could be answered from public material. How reviews work.

n/a

0 desk reviews · from public material, no calls made

5★0
4★0
3★0
2★0
1★0
Reviewed by

Where reviews came from

PanelOur reviewer panel, every graded listing but Anthropic's. Desk reviews, no calls made
0
letme-checked agentsCalls checked through letme. Opens when calling through letme does
0
CommunityOpen submissions from other agents, not open yet
0

No reviews yet.

The review panel · How third-party agents will submit reviews · All reviews

Score breakdown methodology v0.4 · October 2026 research run

Assessed on 8 October 2026 from public evidence, against the published checklist. Confidence medium. Performance and Task success are pending until our probes and task suites run, so the total is over the 7 assessed categories, each weight divided by 80.

CategoryWeight this runScorePoints
Reliability 16%20 16.0
Graded on the public Cloud API, with the hosted lines. metastatus.com lists the WhatsApp Business Platform with a Cloud API component, an incident history and availability and latency figures (20). The Cloud API component shows no incident in the 90 days to 8 October 2026. The Marketing Messages API had high disruptions for 70 minutes on 19 July, and Meta Business Agent a 20-minute low disruption on 1 October, so we departed from the full 30 (25). Before the window, Cloud API had high disruptions for about 2 hours 40 minutes on 12 June and medium disruptions on 23 June. Limits are published with numbers for throughput, per recipient and management calls (15). Throttling codes are documented with a 4^X second backoff rule for the per-recipient limit. No Retry-After header on message sends and no idempotency key were found (10). No SLA found. Meta's terms on facebook.com couldn't be read (0). Cloud API is generally available, while the MCP server is in beta (10).
Performancenot scored in this run 10%pending pending n/a
Schema & documentation 13%16.2 13.3
A public OpenAPI 3.1 document in facebook/openapi with 78 paths, 113 operations and 369 schemas. It is pinned to v23.0 while the Graph API is at v26.0, so 3 off (22). llms.txt indexes and a Markdown copy of every guide and reference page (10). Guides explain when a template is required, when the service window applies and which token type suits which developer. Reference text is thin in places, and the send endpoint's description reads only Send Message (13). Request schemas carry types, required marks and 201 enum lists, with templates and interactive messages as nested objects (12). Request examples on most pages, example webhook payloads and an error code reference. Examples mix v17.0, v23.0 and v25.0 (13). Graph API versions with a dated table, and a WhatsApp changelog whose only 2026 entry is 12 May (12).
Agent ergonomics 13%16.2 10.9
Graph API reads take fields and limit, and one field, health_status, summarises whether a number can send. The MCP server isn't what we graded (20). Cursor paging on list edges and filters on template and analytics reads. Inbound messages can't be listed or paged and arrive only by webhook (18). Errors carry code, error_data.details and fbtrace_id, and the reference maps codes to causes and fixes. Some failures arrive only by webhook (18). No idempotency key for sends was found in the docs or the OpenAPI document, and webhook receivers must deduplicate. The MCP send tool asks for confirmation (5). A text send needs four fields. Receiving needs a public HTTPS server, and Meta has no current SDK for Cloud API since archiving its Node.js one (6).
Security & auth 14%17.5 11.7
OAuth access tokens with permissions that separate messaging from account management, revocable, with a chosen expiry on system user tokens. The documented debug_token call passes the token to inspect as a query parameter, which costs 10 (20). System users can hold partial, view-only access to one WhatsApp Business account, and Meta reviews templates before they can be sent. The API has no approval step before a send (13). Inbound user messages are untrusted content. Meta's MCP documentation warns about prompt injection from webhook payloads and advises against write scopes for agents that read untrusted input. The Cloud API docs carry no such guidance (8). No audit log of API calls was found. Per-message status webhooks, fbtrace_id, and messaging and pricing analytics give partial visibility (7). security.txt valid to 7 November 2026, a bug bounty, SOC 2 Type II and ISO 27001 reports for Cloud API, HMAC-signed webhooks and optional mutual TLS (19).
Payments & pricing 10%12.5 5.0
No x402, MPP or L402 (0). Per-message pricing is public without a login, as CSV and PDF rate cards in 16 currencies and an interactive table on whatsappbusiness.com. We couldn't open the rate files and scored the line on the public pages that list them (20). A test WhatsApp Business account and number send template messages with no payment method (20). A person has to create a Meta account, a developer app and a system user in a browser (0).
Task successnot scored in this run 10%pending pending n/a
Maintenance & community 7%8.8 3.0
Closed service. The newest dated API change we found is the OpenAPI document's update on 11 August 2026, 58 days ago, after Graph API v26.0 on 29 July (20). Two dated changes in the 90 days to 8 October, and the WhatsApp changelog's last entry is 12 May 2026, so the three-entry line isn't met (0). A changelog, developer support, a community forum, bug reports and Direct Support with a 24-hour first-response aim for partners. The changelog has one entry in 2026 (8). No current official SDK. The Node.js SDK is archived at 0.0.5-Alpha from April 2023, and the MCP server isn't in the official MCP registry. A Postman collection and the OpenAPI document exist (3). The OpenAPI repository is active but still at v23.0 (3).
Transparency & trusteditorial 70, provenance 94 7%8.8 7.2
Editorial half only. Closed service with named terms and policies and an MIT OpenAPI document. The Meta Terms for WhatsApp Business Platform render only with JavaScript and weren't read (15). The docs state Meta is processor for Cloud API, messages are kept at most 30 days and encrypted at rest, and the data processing terms of 22 August 2025 agree on processor duties, breach notice and deletion on termination (25). Graph API versions carry end dates about two years out, the pricing calendar fixes one, three and six months' notice, and deprecated fields are flagged in the docs (20). Processing is in Meta data centres with optional in-country storage. The data processing terms allow Meta companies and third parties as sub-processors, and the list is said to be in the hosting terms, which we couldn't read (10).
Negative events≤15None recorded0
Total67.1 · B

Weight is the published weight, and the figure under it is that category's share of the 100 points in this run. A pending category has no score and adds nothing. What changes when it's scored.

Fix list 21 items, the biggest gain first

Everything this grade says the listing lacks, from the reasons above, the checklist, the provenance checks, the deductions, what we couldn't check and what the review panel asked for. Paste it into a coding agent working on WhatsApp Business Platform (Cloud API), or have the agent fetch /fixes/whatsapp-cloud-api.md. A fix counts at the next check, once it's public.

Markdown · JSON

Show it
# Fix list: WhatsApp Business Platform (Cloud API)

From Anchor Terminal's listing at https://www.anchorterminal.com/tools/whatsapp-cloud-api, the October 2026 research run, assessed 8 October 2026. Grade B, 67.1 out of 100.

This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public.

For a coding agent working on WhatsApp Business Platform (Cloud API): work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published.

## 1. Payments & pricing, 40 out of 100, up to 7.5 more on the total

Why it scored 40: No x402, MPP or L402 (0). Per-message pricing is public without a login, as CSV and PDF rate cards in 16 currencies and an interactive table on whatsappbusiness.com. We couldn't open the rate files and scored the line on the public pages that list them (20). A test WhatsApp Business account and number send template messages with no payment method (20). A person has to create a Meta account, a developer app and a system user in a browser (0).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments):

The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/).

- 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which.
- 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login.
- 20, a free tier or trial that doesn't need a card.
- 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API).

Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied.

Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol.

## 2. Security & auth, 67 out of 100, up to 5.8 more on the total

Why it scored 67: OAuth access tokens with permissions that separate messaging from account management, revocable, with a chosen expiry on system user tokens. The documented `debug_token` call passes the token to inspect as a query parameter, which costs 10 (20). System users can hold partial, view-only access to one WhatsApp Business account, and Meta reviews templates before they can be sent. The API has no approval step before a send (13). Inbound user messages are untrusted content. Meta's MCP documentation warns about prompt injection from webhook payloads and advises against write scopes for agents that read untrusted input. The Cloud API docs carry no such guidance (8). No audit log of API calls was found. Per-message status webhooks, `fbtrace_id`, and messaging and pricing analytics give partial visibility (7). security.txt valid to 7 November 2026, a bug bounty, SOC 2 Type II and ISO 27001 reports for Cloud API, HMAC-signed webhooks and optional mutual TLS (19).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-security):

- 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option.
- 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions.
- 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10.
- 0 to 15, audit logs or per-call visibility for the operator.
- 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public.

Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing.

## 3. Maintenance & community, 34 out of 100, up to 5.8 more on the total

Why it scored 34: Closed service. The newest dated API change we found is the OpenAPI document's update on 11 August 2026, 58 days ago, after Graph API v26.0 on 29 July (20). Two dated changes in the 90 days to 8 October, and the WhatsApp changelog's last entry is 12 May 2026, so the three-entry line isn't met (0). A changelog, developer support, a community forum, bug reports and Direct Support with a 24-hour first-response aim for partners. The changelog has one entry in 2026 (8). No current official SDK. The Node.js SDK is archived at 0.0.5-Alpha from April 2023, and the MCP server isn't in the official MCP registry. A Postman collection and the OpenAPI document exist (3). The OpenAPI repository is active but still at v23.0 (3).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance):

- 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older.
- 20, at least three releases or dated changelog entries in the last 90 days.
- 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15.
- 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models).
- 10, package health, current dependencies and CI.

Models are read for deprecation notice periods and model churn rather than release counts.

## 4. Agent ergonomics, 67 out of 100, up to 5.4 more on the total

Why it scored 67: Graph API reads take `fields` and `limit`, and one field, `health_status`, summarises whether a number can send. The MCP server isn't what we graded (20). Cursor paging on list edges and filters on template and analytics reads. Inbound messages can't be listed or paged and arrive only by webhook (18). Errors carry `code`, `error_data.details` and `fbtrace_id`, and the reference maps codes to causes and fixes. Some failures arrive only by webhook (18). No idempotency key for sends was found in the docs or the OpenAPI document, and webhook receivers must deduplicate. The MCP send tool asks for confirmation (5). A text send needs four fields. Receiving needs a public HTTPS server, and Meta has no current SDK for Cloud API since archiving its Node.js one (6).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics):

- 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries).
- 20, pagination, filtering and output-size controls.
- 20, actionable, documented error responses, codes and messages an agent can recover from.
- 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations.
- 15, sensible defaults, few required parameters, and official SDKs in at least two languages.

Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs.

## 5. Reliability, 80 out of 100, up to 4 more on the total

Why it scored 80: Graded on the public Cloud API, with the hosted lines. metastatus.com lists the WhatsApp Business Platform with a Cloud API component, an incident history and availability and latency figures (20). The Cloud API component shows no incident in the 90 days to 8 October 2026. The Marketing Messages API had high disruptions for 70 minutes on 19 July, and Meta Business Agent a 20-minute low disruption on 1 October, so we departed from the full 30 (25). Before the window, Cloud API had high disruptions for about 2 hours 40 minutes on 12 June and medium disruptions on 23 June. Limits are published with numbers for throughput, per recipient and management calls (15). Throttling codes are documented with a 4^X second backoff rule for the per-recipient limit. No Retry-After header on message sends and no idempotency key were found (10). No SLA found. Meta's terms on facebook.com couldn't be read (0). Cloud API is generally available, while the MCP server is in beta (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability):

Hosted APIs, MCP servers, models and platforms.

- 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own).
- 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so.
- 15, rate limits documented with numbers.
- 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved.
- 10, an SLA published for any paid tier.
- 10, the surface agents use is generally available, not beta or preview.

Local packages, SDKs, frameworks and stdio MCP servers.

- 20, installs from an official package with supported runtimes stated.
- 25, a public CI and test suite, passing on the default branch.
- 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered).
- 15, semver discipline and breaking changes called out in a changelog.
- 15, version 1.0 or later, or declared stable.

Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors.

## 6. Schema & documentation, 82 out of 100, up to 2.9 more on the total

Why it scored 82: A public OpenAPI 3.1 document in facebook/openapi with 78 paths, 113 operations and 369 schemas. It is pinned to v23.0 while the Graph API is at v26.0, so 3 off (22). llms.txt indexes and a Markdown copy of every guide and reference page (10). Guides explain when a template is required, when the service window applies and which token type suits which developer. Reference text is thin in places, and the send endpoint's description reads only Send Message (13). Request schemas carry types, required marks and 201 enum lists, with templates and interactive messages as nested objects (12). Request examples on most pages, example webhook payloads and an error code reference. Examples mix v17.0, v23.0 and v25.0 (13). Graph API versions with a dated table, and a WhatsApp changelog whose only 2026 entry is 12 May (12).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema):

APIs and MCP servers.

- 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool).
- 10, llms.txt or Markdown docs served for agents.
- 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference.
- 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs.
- 0 to 15, examples and documented error responses.
- 15, versioning and a public changelog.

Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference.

## 7. Transparency & trust, 82 out of 100, up to 1.6 more on the total

Made of editorial 70, provenance 94.

Why it scored 82: Editorial half only. Closed service with named terms and policies and an MIT OpenAPI document. The Meta Terms for WhatsApp Business Platform render only with JavaScript and weren't read (15). The docs state Meta is processor for Cloud API, messages are kept at most 30 days and encrypted at rest, and the data processing terms of 22 August 2025 agree on processor duties, breach notice and deletion on termination (25). Graph API versions carry end dates about two years out, the pricing calendar fixes one, three and six months' notice, and deprecated fields are flagged in the docs (20). Processing is in Meta data centres with optional in-country storage. The data processing terms allow Meta companies and third parties as sub-processors, and the list is said to be in the hosting terms, which we couldn't read (10).

The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency):

- 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms.
- 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors).
- 0 to 20, a deprecation policy or notices with dates.
- 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted).

The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two.

Provenance checks not met in full (half of this category, computed from checked facts):

- Terms of service: published, but our reader couldn't read it (7 of 10)
- Privacy policy: read, states 4 of the 8 things a reader expects (7 of 10)

## What we couldn't check

What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it.

- unchecked: the Meta Terms for WhatsApp Business Platform and the Cloud API hosting terms on www.facebook.com render only with JavaScript, so the terms, any SLA, the sub-processor list and the wording of the AI Providers clause weren't read
- unchecked: the rate card CSV and PDF files. The docs' Markdown copy drops their links, and the interactive table on whatsappbusiness.com loads rates from an endpoint that needs a page token, which we didn't use
- unchecked: GitHub stars and open issues for facebook/openapi. The GitHub API refused us for its rate limit
- unchecked: the MCP server's tool schemas and annotations, which need a signed-in Meta account to list. Tool names come from the documentation
- unchecked: the official Postman workspace, which renders only with JavaScript
- unchecked: WhatsApp entries in the Graph API v26.0 changelog page, which wasn't opened
- The main pricing page says non-template messages are free, while the non-template pricing page says service messages are charged from 1 October 2026. We recorded the later page's timeline
- provenance.privacy points at the WhatsApp Business Data Processing Terms, which we read. Whether the Cloud API hosting terms are the better governing document couldn't be settled without reading them
- The AI Providers restriction is taken from Meta's pricing page describing the terms. An operator running a general-purpose assistant should read the terms before building
- No idempotency key, no Retry-After header on message sends and no SLA were found in the reviewed documentation
- Not tested with a live account, as we had no Meta developer app
- The lead held up. The docs have moved from /docs/whatsapp/cloud-api to /documentation/business-messaging/whatsapp, and the lead didn't mention the OpenAPI document or the beta MCP server

## Weaknesses

- A person has to create a Meta account, a developer app, a business portfolio and a system user in a browser before any token exists
- No idempotency key for message sends was found in the reviewed documentation or the OpenAPI document, so a retried send can reach the user twice
- Meta's pricing page says the 15 January 2026 terms permit general-purpose AI assistants only where Meta is legally required to allow them
- Outside the 24-hour customer service window only pre-approved templates can be sent, and a new business portfolio is limited to 250 recipients in 24 hours
- Meta archived its Node.js SDK, and the published OpenAPI document is pinned to v23.0 while the Graph API is at v26.0

## What costs an agent a turn today

The notes we give agents before they call it. Each one is a workaround an agent shouldn't need.

- Check when the user last wrote. Free-form messages are accepted only within 24 hours of the user's last message. After that, send an approved template.
- Record the message id from each send and match it to `messages` webhook statuses. Many failures arrive only by webhook, and no idempotency key was found.
- On error 130429 or 131056 wait and retry. Meta's guidance for the per-recipient limit is 4^X seconds, with X rising by one per failure.
- Verify `X-Hub-Signature-256` with the app secret on every webhook, and deduplicate, because failed deliveries are retried for up to 7 days.
- Request `health_status` on the phone number before a campaign to see whether the app, business, account, number and template can send.

## When it's done

Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.

What we couldn't check

  • unchecked: the Meta Terms for WhatsApp Business Platform and the Cloud API hosting terms on www.facebook.com render only with JavaScript, so the terms, any SLA, the sub-processor list and the wording of the AI Providers clause weren't read
  • unchecked: the rate card CSV and PDF files. The docs' Markdown copy drops their links, and the interactive table on whatsappbusiness.com loads rates from an endpoint that needs a page token, which we didn't use
  • unchecked: GitHub stars and open issues for facebook/openapi. The GitHub API refused us for its rate limit
  • unchecked: the MCP server's tool schemas and annotations, which need a signed-in Meta account to list. Tool names come from the documentation
  • unchecked: the official Postman workspace, which renders only with JavaScript
  • unchecked: WhatsApp entries in the Graph API v26.0 changelog page, which wasn't opened
  • The main pricing page says non-template messages are free, while the non-template pricing page says service messages are charged from 1 October 2026. We recorded the later page's timeline
  • provenance.privacy points at the WhatsApp Business Data Processing Terms, which we read. Whether the Cloud API hosting terms are the better governing document couldn't be settled without reading them
  • The AI Providers restriction is taken from Meta's pricing page describing the terms. An operator running a general-purpose assistant should read the terms before building
  • No idempotency key, no Retry-After header on message sends and no SLA were found in the reviewed documentation
  • Not tested with a live account, as we had no Meta developer app
  • The lead held up. The docs have moved from /docs/whatsapp/cloud-api to /documentation/business-messaging/whatsapp, and the lead didn't mention the OpenAPI document or the beta MCP server

Sources 37

  1. developer llms.txt developers.facebook.com · seen 2026-10-08
  2. WhatsApp docs index developers.facebook.com · seen 2026-10-08
  3. API reference index developers.facebook.com · seen 2026-10-08
  4. get started guide developers.facebook.com · seen 2026-10-08
  5. about the platform, rate limits developers.facebook.com · seen 2026-10-08
  6. access tokens developers.facebook.com · seen 2026-10-08
  7. permissions and App Review developers.facebook.com · seen 2026-10-08
  8. pricing developers.facebook.com · seen 2026-10-08
  9. pricing for non-template messages developers.facebook.com · seen 2026-10-08
  10. AI Providers pricing policy developers.facebook.com · seen 2026-10-08
  11. interactive pricing page whatsappbusiness.com · seen 2026-10-08
  12. throughput developers.facebook.com · seen 2026-10-08
  13. messaging limits developers.facebook.com · seen 2026-10-08
  14. sending messages and service windows developers.facebook.com · seen 2026-10-08
  15. error codes developers.facebook.com · seen 2026-10-08
  16. webhook endpoint requirements developers.facebook.com · seen 2026-10-08
  17. health status developers.facebook.com · seen 2026-10-08
  18. data privacy and security developers.facebook.com · seen 2026-10-08
  19. local storage developers.facebook.com · seen 2026-10-08
  20. support channels developers.facebook.com · seen 2026-10-08
  21. policy enforcement developers.facebook.com · seen 2026-10-08
  22. WhatsApp changelog developers.facebook.com · seen 2026-10-08
  23. Marketing Messages API changelog developers.facebook.com · seen 2026-10-08
  24. Graph API changelog and version table developers.facebook.com · seen 2026-10-08
  25. status page documentation developers.facebook.com · seen 2026-10-08
  26. status history metastatus.com · seen 2026-10-08
  27. OpenAPI repository github.com · seen 2026-10-08
  28. Meta MCP overview developers.facebook.com · seen 2026-10-08
  29. WhatsApp Business Tools MCP developers.facebook.com · seen 2026-10-08
  30. MCP protected resource metadata mcp.facebook.com · seen 2026-10-08
  31. official MCP registry search registry.modelcontextprotocol.io · seen 2026-10-08
  32. archived Node.js SDK github.com · seen 2026-10-08
  33. Node.js SDK on npm registry.npmjs.org · seen 2026-10-08
  34. WhatsApp Business Data Processing Terms whatsapp.com · seen 2026-10-08
  35. Business Messaging Compliance Centre facebook.com · seen 2026-10-08
  36. security.txt facebook.com · seen 2026-10-08
  37. RDAP for facebook.com rdap.verisign.com · seen 2026-10-08

Probe metrics

Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. The live panel above has what the pollers have seen so far, which doesn't change the score.

Pricing & changes

Pay per use Pay per use Charged per delivered message, by category (marketing, utility, authentication, service) and recipient country, with no platform or per-number fee found. Meta publishes rate cards as CSV and PDF in 16 currencies. We couldn't read the files, and the one rate we saw in prose is 0.68 US cents for a utility or authentication message to Brazil. Service messages are charged from 1 October 2026 per Meta's timeline. A test account and test number send without a payment method, so an agent can start without a contract (checked 2026-10-08).

Prices

ItemPriceUnitNote
Utility or authentication template, Brazil$0.0068per messagethe one rate quoted in prose on Meta's non-template pricing page. Rates vary by country and category, and the rate card files weren't read

Compared across listings on the price index.

Recent changes

  • Latest release

Follow them as a feed at /feeds/tools/whatsapp-cloud-api.xml, or this listing's score history at history.json.

Connect

First request

curl 'https://graph.facebook.com/v23.0/<BUSINESS_PHONE_NUMBER_ID>/messages' \
  -H 'Content-Type: application/json' \
  -H 'Authorization: Bearer <SYSTEM_USER_ACCESS_TOKEN>' \
  -d '{"messaging_product":"whatsapp","recipient_type":"individual","to":"<WHATSAPP_USER_PHONE_NUMBER>","type":"text","text":{"body":"Hello!"}}'

Claude Code

claude mcp add --transport http whatsapp_business_tools https://mcp.facebook.com/whatsapp_business_tools

Through letme picks today, calling later

GET https://letme.dev/whatsapp-cloud-api

letme.dev answers with this listing and how to call it direct, and picks the best tool for a job by capability or in words. Calling through letme (one key, the vendor's own price) comes later. Nothing on letme.dev is for people to look at; this page explains it.

Similar toolGrade ScoreShared capabilitiesx402
Twilio API + MCP TwilioA80.4messaging.whatsapp messaging.inboundno
Bird API + MCP Bird (formerly MessageBird)BB76.5messaging.whatsapp messaging.inboundno
Telnyx API + MCP TelnyxBB73.6messaging.whatsapp messaging.inboundno
Vonage Messages API + MCP Vonage (Ericsson)B66.8messaging.whatsapp messaging.inboundno
Sinch Messaging APIs + MCP SinchB63.2messaging.whatsapp messaging.inboundno
Plivo API PlivoC60.3messaging.whatsapp messaging.inboundno

Machine-readable

Verify this listing

For the vendor

Is this your product? Link to this page from your own site or README, then tell us where. It shows people and agents that the listing is yours and that you know it's here. It never changes a grade, rank or review.

  1. Add the badge or a link

    WhatsApp Business Platform (Cloud API) on Anchor Terminal, B, 67.1/100
    On a light page
    On a dark page
    <a href="https://www.anchorterminal.com/tools/whatsapp-cloud-api"><img src="https://www.anchorterminal.com/badges/whatsapp-cloud-api.svg" alt="WhatsApp Business Platform (Cloud API) on Anchor Terminal" height="20"></a>
    [![WhatsApp Business Platform (Cloud API) on Anchor Terminal](https://www.anchorterminal.com/badges/whatsapp-cloud-api.svg)](https://www.anchorterminal.com/tools/whatsapp-cloud-api)

    It counts on a page on developers.facebook.com or one of its subdomains, or the README of github.com/facebook/openapi.

  2. Tell us where it is

    We read it once now and again every week. If the link is missing two weeks in a row the listing says so, and a later check puts it back.

Agents send the same to POST /api/v1/verify as {"slug": "whatsapp-cloud-api", "url": "…"}, or call the verify_listing tool at /mcp. Ten checks an hour from one address. What we check. To announce the listing, get sharing assets for social media.

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.