# WhatsApp Business Platform (Cloud API) > Meta's WhatsApp Business Platform Cloud API sends and receives WhatsApp messages for a business phone number through the Graph API, with inbound messages and status updates arriving by webhook. Access uses a Meta developer app and OAuth access tokens. - Canonical: https://www.anchorterminal.com/tools/whatsapp-cloud-api - Markdown: https://www.anchorterminal.com/tools/whatsapp-cloud-api.md (~9,050 tokens) - Slim: https://www.anchorterminal.com/tools/whatsapp-cloud-api.min.md (~2,230 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/whatsapp-cloud-api.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade B · 67.1/100 · rank #218 of 722 · #5 in Messaging APIs · not agent-ready · confidence medium** More from Meta Platforms, Inc., listed separately because each is its own product: [Meta Marketing API](https://www.anchorterminal.com/tools/meta-marketing-api.md) (Advertising & campaign operations). ## Assessment The first-party WhatsApp API has a public OpenAPI document, Markdown docs with llms.txt, numeric rate limits and a test number that sends without a payment method. Setup needs a person in three Meta dashboards, no idempotency key was found for sends, and Meta's terms restrict general-purpose AI assistants on the platform. ## Facts | Field | Value | | --- | --- | | Vendor | Meta Platforms, Inc. (https://developers.facebook.com) | | Kind | HTTP API | | Category | Messaging APIs (https://www.anchorterminal.com/categories/messaging) | | Transport | HTTP | | Endpoint | `https://graph.facebook.com` | | Auth | OAuth · Every call needs a Bearer access token from a Meta developer app with the WhatsApp use case. Access is self-serve for a business using its own account, with no App Review. A person creates the app, a business portfolio and a system user in Meta's dashboards, then generates a system user token with `whatsapp_business_messaging` and `whatsapp_business_management`. Apps that act for other businesses need Advanced access through App Review and onboard customers with Embedded Signup. Business verification raises the messaging limit above 250 recipients a day. | | Pricing | Pay per use (Pay per use) · Charged per delivered message, by category (marketing, utility, authentication, service) and recipient country, with no platform or per-number fee found. Meta publishes rate cards as CSV and PDF in 16 currencies. We couldn't read the files, and the one rate we saw in prose is 0.68 US cents for a utility or authentication message to Brazil. Service messages are charged from 1 October 2026 per Meta's timeline. A test account and test number send without a payment method, so an agent can start without a contract (checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the WhatsApp documentation, the llms.txt indexes, the pricing pages or the OpenAPI document (checked 2026-10-08). | | Licence | Proprietary service under the Meta Terms for WhatsApp Business Platform. The OpenAPI document in facebook/openapi is MIT | | Source | https://github.com/facebook/openapi | | Docs | https://developers.facebook.com/documentation/business-messaging/whatsapp/overview | | llms.txt | https://developers.facebook.com/documentation/business-messaging/whatsapp/llms.txt | | Last release | 2026-08-11 | | API | Graph API at https://graph.facebook.com/. Cloud API for messages, media, calling and groups, and the Business Management API for accounts, phone numbers, templates and analytics. The reference index lists 66 pages | | Versions | Graph API v26.0 from 29 July 2026, v25.0 from 18 February 2026. Each version stays available for about two years (v23.0 until 8 October 2027). Docs examples use v17.0, v23.0 and v25.0 | | Access | A Meta developer app with the WhatsApp use case, a business portfolio and a WhatsApp Business account. Direct developers need no App Review. Apps acting for other businesses need Advanced access through App Review and Embedded Signup | | Credentials | System user access tokens with a chosen expiry, business integration system user tokens per onboarded customer, and short-lived user tokens. Permissions `whatsapp_business_messaging`, `whatsapp_business_management` and `business_management`. Partial or full asset access per WhatsApp Business account | | Message rules | Free-form messages only within 24 hours of the user's last message. Outside that window only templates, which Meta reviews and places in the marketing, utility or authentication category. Users must have opted in | | Rate limits | 80 messages a second per number (1,000 by automatic upgrade, 20 for numbers shared with the WhatsApp Business app). One message every 6 seconds to the same user, with bursts of 45. Management endpoints 200 requests an hour per app and account, 5,000 for active accounts | | Messaging limits | Unique users reachable outside service windows in a moving 24 hours, per business portfolio. 250 at first, then 2,000 after business verification or 2,000 good-quality sends in 30 days, then 10,000, 100,000 and unlimited | | Webhooks | Inbound messages and delivery statuses arrive only by webhook. HMAC-SHA256 signature in `X-Hub-Signature-256`, optional mutual TLS, batches of up to 1,000 updates, retries with backoff for up to 7 days, and no API for past webhook data | | Errors | JSON error object with `code`, `message`, `error_data.details` and `fbtrace_id`. Throttling codes 4, 80007, 130429, 131048 and 131056. Some errors arrive only in the `messages` webhook | | Pricing model | Per delivered message, by category and recipient country, with volume tiers for utility and authentication. Rate cards as CSV and PDF in 16 currencies. Rates may change on the first day of a quarter, with one month's notice for rates and six for a model change | | Test resources | A test WhatsApp Business account and test number are created with the app, have relaxed limits and need no payment method to send template messages | | Data handling | Meta is processor for Cloud API. Messages kept at most 30 days, media 30 days, encrypted at rest. Local storage keeps message content at rest in a chosen region, and a no-storage option was added on 1 December 2025 | | MCP server | https://mcp.facebook.com/whatsapp_business_tools, streamable HTTP, OAuth with the three WhatsApp permissions, 18 documented tools for accounts, numbers, templates, webhooks and sending. Beta, rolling out gradually. The send tool asks for confirmation | | SDKs and tools | No current official SDK for Cloud API. The WhatsApp Node.js SDK (npm `whatsapp` 0.0.5-Alpha, April 2023) is archived. An official Postman collection and an API playground in the reference | | Certifications | SOC 2 Type II, SOC 3, ISO 27001, GDPR and LGPD documents for Cloud API listed in the Business Messaging Compliance Centre. Bug bounty at bugbounty.meta.com | | Status | metastatus.com/whatsapp-business-api, with components for Cloud API, localised storage, account management, Embedded Signup and the Marketing Messages API, availability and latency figures for Cloud API, and a JSON and RSS history | | Capabilities | messaging.whatsapp, messaging.inbound | | Tags | hosted, usage-based, oauth, openapi, llms-txt, webhooks, whatsapp, mcp, sandbox, status-page, bug-bounty, soc2 | | JSON | https://www.anchorterminal.com/api/v1/tools/whatsapp-cloud-api.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 80 | 16.0 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 82 | 13.3 | | Agent ergonomics | 13% | 16.2 | 67 | 10.9 | | Security & auth | 14% | 17.5 | 67 | 11.7 | | Payments & pricing | 10% | 12.5 | 40 | 5.0 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 34 | 3.0 | | Transparency & trust (editorial 70, provenance 94) | 7% | 8.8 | 82 | 7.2 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **67.1 → B** | ### Why each score - Reliability 80: Graded on the public Cloud API, with the hosted lines. metastatus.com lists the WhatsApp Business Platform with a Cloud API component, an incident history and availability and latency figures (20). The Cloud API component shows no incident in the 90 days to 8 October 2026. The Marketing Messages API had high disruptions for 70 minutes on 19 July, and Meta Business Agent a 20-minute low disruption on 1 October, so we departed from the full 30 (25). Before the window, Cloud API had high disruptions for about 2 hours 40 minutes on 12 June and medium disruptions on 23 June. Limits are published with numbers for throughput, per recipient and management calls (15). Throttling codes are documented with a 4^X second backoff rule for the per-recipient limit. No Retry-After header on message sends and no idempotency key were found (10). No SLA found. Meta's terms on facebook.com couldn't be read (0). Cloud API is generally available, while the MCP server is in beta (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 82: A public OpenAPI 3.1 document in facebook/openapi with 78 paths, 113 operations and 369 schemas. It is pinned to v23.0 while the Graph API is at v26.0, so 3 off (22). llms.txt indexes and a Markdown copy of every guide and reference page (10). Guides explain when a template is required, when the service window applies and which token type suits which developer. Reference text is thin in places, and the send endpoint's description reads only Send Message (13). Request schemas carry types, required marks and 201 enum lists, with templates and interactive messages as nested objects (12). Request examples on most pages, example webhook payloads and an error code reference. Examples mix v17.0, v23.0 and v25.0 (13). Graph API versions with a dated table, and a WhatsApp changelog whose only 2026 entry is 12 May (12). - Agent ergonomics 67: Graph API reads take `fields` and `limit`, and one field, `health_status`, summarises whether a number can send. The MCP server isn't what we graded (20). Cursor paging on list edges and filters on template and analytics reads. Inbound messages can't be listed or paged and arrive only by webhook (18). Errors carry `code`, `error_data.details` and `fbtrace_id`, and the reference maps codes to causes and fixes. Some failures arrive only by webhook (18). No idempotency key for sends was found in the docs or the OpenAPI document, and webhook receivers must deduplicate. The MCP send tool asks for confirmation (5). A text send needs four fields. Receiving needs a public HTTPS server, and Meta has no current SDK for Cloud API since archiving its Node.js one (6). - Security & auth 67: OAuth access tokens with permissions that separate messaging from account management, revocable, with a chosen expiry on system user tokens. The documented `debug_token` call passes the token to inspect as a query parameter, which costs 10 (20). System users can hold partial, view-only access to one WhatsApp Business account, and Meta reviews templates before they can be sent. The API has no approval step before a send (13). Inbound user messages are untrusted content. Meta's MCP documentation warns about prompt injection from webhook payloads and advises against write scopes for agents that read untrusted input. The Cloud API docs carry no such guidance (8). No audit log of API calls was found. Per-message status webhooks, `fbtrace_id`, and messaging and pricing analytics give partial visibility (7). security.txt valid to 7 November 2026, a bug bounty, SOC 2 Type II and ISO 27001 reports for Cloud API, HMAC-signed webhooks and optional mutual TLS (19). - Payments & pricing 40: No x402, MPP or L402 (0). Per-message pricing is public without a login, as CSV and PDF rate cards in 16 currencies and an interactive table on whatsappbusiness.com. We couldn't open the rate files and scored the line on the public pages that list them (20). A test WhatsApp Business account and number send template messages with no payment method (20). A person has to create a Meta account, a developer app and a system user in a browser (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 34: Closed service. The newest dated API change we found is the OpenAPI document's update on 11 August 2026, 58 days ago, after Graph API v26.0 on 29 July (20). Two dated changes in the 90 days to 8 October, and the WhatsApp changelog's last entry is 12 May 2026, so the three-entry line isn't met (0). A changelog, developer support, a community forum, bug reports and Direct Support with a 24-hour first-response aim for partners. The changelog has one entry in 2026 (8). No current official SDK. The Node.js SDK is archived at 0.0.5-Alpha from April 2023, and the MCP server isn't in the official MCP registry. A Postman collection and the OpenAPI document exist (3). The OpenAPI repository is active but still at v23.0 (3). - Transparency & trust 82: Editorial half only. Closed service with named terms and policies and an MIT OpenAPI document. The Meta Terms for WhatsApp Business Platform render only with JavaScript and weren't read (15). The docs state Meta is processor for Cloud API, messages are kept at most 30 days and encrypted at rest, and the data processing terms of 22 August 2025 agree on processor duties, breach notice and deletion on termination (25). Graph API versions carry end dates about two years out, the pricing calendar fixes one, three and six months' notice, and deprecated fields are flagged in the docs (20). Processing is in Meta data centres with optional in-country storage. The data processing terms allow Meta companies and third parties as sub-processors, and the list is said to be in the hosting terms, which we couldn't read (10). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (21 items): https://www.anchorterminal.com/fixes/whatsapp-cloud-api.md (JSON https://www.anchorterminal.com/fixes/whatsapp-cloud-api.json) ### What we couldn't check - unchecked: the Meta Terms for WhatsApp Business Platform and the Cloud API hosting terms on www.facebook.com render only with JavaScript, so the terms, any SLA, the sub-processor list and the wording of the AI Providers clause weren't read - unchecked: the rate card CSV and PDF files. The docs' Markdown copy drops their links, and the interactive table on whatsappbusiness.com loads rates from an endpoint that needs a page token, which we didn't use - unchecked: GitHub stars and open issues for facebook/openapi. The GitHub API refused us for its rate limit - unchecked: the MCP server's tool schemas and annotations, which need a signed-in Meta account to list. Tool names come from the documentation - unchecked: the official Postman workspace, which renders only with JavaScript - unchecked: WhatsApp entries in the Graph API v26.0 changelog page, which wasn't opened - The main pricing page says non-template messages are free, while the non-template pricing page says service messages are charged from 1 October 2026. We recorded the later page's timeline - provenance.privacy points at the WhatsApp Business Data Processing Terms, which we read. Whether the Cloud API hosting terms are the better governing document couldn't be settled without reading them - The AI Providers restriction is taken from Meta's pricing page describing the terms. An operator running a general-purpose assistant should read the terms before building - No idempotency key, no Retry-After header on message sends and no SLA were found in the reviewed documentation - Not tested with a live account, as we had no Meta developer app - The lead held up. The docs have moved from /docs/whatsapp/cloud-api to /documentation/business-messaging/whatsapp, and the lead didn't mention the OpenAPI document or the beta MCP server ### Sources - developer llms.txt: (seen 2026-10-08) - WhatsApp docs index: (seen 2026-10-08) - API reference index: (seen 2026-10-08) - get started guide: (seen 2026-10-08) - about the platform, rate limits: (seen 2026-10-08) - access tokens: (seen 2026-10-08) - permissions and App Review: (seen 2026-10-08) - pricing: (seen 2026-10-08) - pricing for non-template messages: (seen 2026-10-08) - AI Providers pricing policy: (seen 2026-10-08) - interactive pricing page: (seen 2026-10-08) - throughput: (seen 2026-10-08) - messaging limits: (seen 2026-10-08) - sending messages and service windows: (seen 2026-10-08) - error codes: (seen 2026-10-08) - webhook endpoint requirements: (seen 2026-10-08) - health status: (seen 2026-10-08) - data privacy and security: (seen 2026-10-08) - local storage: (seen 2026-10-08) - support channels: (seen 2026-10-08) - policy enforcement: (seen 2026-10-08) - WhatsApp changelog: (seen 2026-10-08) - Marketing Messages API changelog: (seen 2026-10-08) - Graph API changelog and version table: (seen 2026-10-08) - status page documentation: (seen 2026-10-08) - status history: (seen 2026-10-08) - OpenAPI repository: (seen 2026-10-08) - Meta MCP overview: (seen 2026-10-08) - WhatsApp Business Tools MCP: (seen 2026-10-08) - MCP protected resource metadata: (seen 2026-10-08) - official MCP registry search: (seen 2026-10-08) - archived Node.js SDK: (seen 2026-10-08) - Node.js SDK on npm: (seen 2026-10-08) - WhatsApp Business Data Processing Terms: (seen 2026-10-08) - Business Messaging Compliance Centre: (seen 2026-10-08) - security.txt: (seen 2026-10-08) - RDAP for facebook.com: (seen 2026-10-08) ## Who's behind it (provenance 94/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Meta Platforms, Inc. | 20/20 | | Domain age | facebook.com, registered 1997-03-29 (29 years) | 15/15 | | Endpoint on the vendor's domain | graph.facebook.com | 15/15 | | Terms of service | published, but our reader couldn't read it | 7/10 | | Privacy policy | read, states 4 of the 8 things a reader expects | 7/10 | | Status page | metastatus.com/whatsapp-business-api | 10/10 | | Changelog | published | 10/10 | | security.txt | valid | 10/10 | The API answers at graph.facebook.com and the MCP server at mcp.facebook.com, both facebook.com subdomains. www.whatsapp.com/legal/business-solution-terms and /legal/meta-terms-whatsapp-business both redirect to www.facebook.com/legal/Meta-Terms-for-WhatsApp-Business-Platform. That page and the Cloud API hosting terms at www.facebook.com/legal/WhatsApp-Business-Platform-Cloud-API render only with JavaScript, so their text wasn't read. The privacy field points at the WhatsApp Business Data Processing Terms (last updated 22 August 2025), which we read. Meta's docs name the Cloud API hosting terms as the other data document for Cloud API customers. The legal entity is taken from the copyright line of the MIT licence in facebook/openapi. The data processing terms name WhatsApp LLC and WhatsApp Ireland Limited as contracting entities. www.facebook.com/.well-known/security.txt and www.whatsapp.com/.well-known/security.txt name a contact, the bug bounty policy at bugbounty.meta.com and a disclosure policy, and expire on 7 November 2026. RDAP for facebook.com gives a registration date of 1997-03-29. The WhatsApp changelog's newest entry is 12 May 2026, and the one before it 8 December 2025. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service** (https://www.facebook.com/legal/Meta-Terms-for-WhatsApp-Business-Platform), read 2026-10-08. Our reader couldn't read it (robots.txt asks readers like ours not to fetch it). **Privacy policy** (https://www.whatsapp.com/legal/business-data-processing-terms), read 2026-10-08, dated 2025-08-22, states 4 of the 8 things a reader expects. - Gives the date it was last updated. Last updated 2025-08-22. - Not found in the text. Says how long data is kept. - Not found in the text. Says whether personal data is sold or shared for advertising. - Not found in the text. Gives a privacy contact. - Not found in the text. Says where data is transferred or stored. - Also in the text (2026-10-08). The customer authorises WhatsApp to engage other Meta Companies and third parties as sub-processors, and a customer who objects to a change may stop using the Business Services. "If you reasonably object to such changes, you may inform WhatsApp in writing and stop using our Business Services; and" - Also in the text (2026-10-08). When the Business Terms end, WhatsApp stops processing the personal information and deletes it within the period the Business Terms set, with exceptions for legal storage duties and independent rights. "Upon termination of the Business Terms, WhatsApp shall cease Processing Personal Information and shall delete it within the time period set forth in the Business Terms" ## Live (updated 2026-10-08 19:53 UTC) - Right now: up, HTTP 400, 113 ms, checked 2026-10-08 19:53 UTC (get on `https://graph.facebook.com`) - Uptime 24h 100.0% (27 probes) · 30 days 100.0% (27 probes) · p50 111 ms · p95 118 ms - Vendor status page: unknown, no machine-readable status found - Watching changelog - Watching privacy - Watching terms - Always current: https://www.anchorterminal.com/api/v1/live/whatsapp-cloud-api.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | Utility or authentication template, Brazil | $0.0068 | per message | the one rate quoted in prose on Meta's non-template pricing page. Rates vary by country and category, and the rate card files weren't read | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - A test WhatsApp Business account and test number are created with the app and send template messages with no payment method on file - OpenAPI 3.1 document under MIT in facebook/openapi (78 paths, 113 operations), plus llms.txt indexes and a Markdown copy of each docs page - Limits are published with numbers, including 80 messages a second per number, 5,000 requests an hour per active account and one message every 6 seconds per recipient - Message data is kept for at most 30 days, with local storage and no-storage options per phone number, and SOC 2 Type II and ISO 27001 reports for Cloud API - Webhook payloads are signed with HMAC-SHA256 in `X-Hub-Signature-256`, and mutual TLS is available ## Weaknesses - A person has to create a Meta account, a developer app, a business portfolio and a system user in a browser before any token exists - No idempotency key for message sends was found in the reviewed documentation or the OpenAPI document, so a retried send can reach the user twice - Meta's pricing page says the 15 January 2026 terms permit general-purpose AI assistants only where Meta is legally required to allow them - Outside the 24-hour customer service window only pre-approved templates can be sent, and a new business portfolio is limited to 250 recipients in 24 hours - Meta archived its Node.js SDK, and the published OpenAPI document is pinned to v23.0 while the Graph API is at v26.0 ## Before you call it (notes for agents) 1. Check when the user last wrote. Free-form messages are accepted only within 24 hours of the user's last message. After that, send an approved template. 2. Record the message id from each send and match it to `messages` webhook statuses. Many failures arrive only by webhook, and no idempotency key was found. 3. On error 130429 or 131056 wait and retry. Meta's guidance for the per-recipient limit is 4^X seconds, with X rising by one per failure. 4. Verify `X-Hub-Signature-256` with the app secret on every webhook, and deduplicate, because failed deliveries are retried for up to 7 days. 5. Request `health_status` on the phone number before a campaign to see whether the app, business, account, number and template can send. ## Connect First request: ```bash curl 'https://graph.facebook.com/v23.0//messages' \ -H 'Content-Type: application/json' \ -H 'Authorization: Bearer ' \ -d '{"messaging_product":"whatsapp","recipient_type":"individual","to":"","type":"text","text":{"body":"Hello!"}}' ``` Claude Code: ```bash claude mcp add --transport http whatsapp_business_tools https://mcp.facebook.com/whatsapp_business_tools ``` Through letme (picks today, calling later): https://letme.dev/whatsapp-cloud-api. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Twilio API + MCP | A | 80.4 | 8 | messaging.whatsapp, messaging.inbound | no | https://www.anchorterminal.com/tools/twilio.md | | Bird API + MCP | BB | 76.5 | 27 | messaging.whatsapp, messaging.inbound | no | https://www.anchorterminal.com/tools/bird.md | | AWS End User Messaging | BB | 74.3 | 64 | messaging.whatsapp, messaging.inbound | no | https://www.anchorterminal.com/tools/aws-end-user-messaging.md | | Telnyx API + MCP | BB | 73.6 | 76 | messaging.whatsapp, messaging.inbound | no | https://www.anchorterminal.com/tools/telnyx.md | | Vonage Messages API + MCP | B | 66.8 | 227 | messaging.whatsapp, messaging.inbound | no | https://www.anchorterminal.com/tools/vonage.md | | Sinch Messaging APIs + MCP | B | 63.2 | 315 | messaging.whatsapp, messaging.inbound | no | https://www.anchorterminal.com/tools/sinch.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - Cloud API allows 80 messages a second per business phone number by default and 1,000 by automatic upgrade, and returns error 130429 above that (source: ) - A new business portfolio can message 250 unique users in a moving 24 hours outside customer service windows, rising to 2,000, 10,000, 100,000 and unlimited (source: ) - Meta's timeline says service messages and utility templates sent inside the 24-hour window are charged per message from 1 October 2026, after being free since November 2024 and July 2025 (source: ) - The AI Providers pricing page says that from 15 January 2026 the terms permit general-purpose AI assistants on the platform only where Meta is legally required to allow them (source: ) - Meta hosts a WhatsApp Business Tools MCP server at https://mcp.facebook.com/whatsapp_business_tools, in beta and rolling out gradually, with 18 documented tools and OAuth sign-in (source: ) - The OpenAPI 3.1 document in facebook/openapi covers 78 paths and 113 operations at v23.0, MIT licensed, last changed on 11 August 2026 (source: ) - The status history lists no Cloud API incident between 24 June and 8 October 2026. On 12 June 2026 Cloud API had high disruptions for about 2 hours 40 minutes (source: ) - Messages are kept for at most 30 days, and Meta says it has SOC 2 Type II and ISO 27001 reports for Cloud API (source: ) ## Compare - [360dialog WhatsApp API + MCP vs WhatsApp Business Platform (Cloud API)](https://www.anchorterminal.com/compare/360dialog-vs-whatsapp-cloud-api.md): D 52 vs B 67.1 - [AWS End User Messaging vs WhatsApp Business Platform (Cloud API)](https://www.anchorterminal.com/compare/aws-end-user-messaging-vs-whatsapp-cloud-api.md): BB 74.3 vs B 67.1 - [Bird API + MCP vs WhatsApp Business Platform (Cloud API)](https://www.anchorterminal.com/compare/bird-vs-whatsapp-cloud-api.md): BB 76.5 vs B 67.1 - [Infobip API + MCP vs WhatsApp Business Platform (Cloud API)](https://www.anchorterminal.com/compare/infobip-vs-whatsapp-cloud-api.md): C 59.1 vs B 67.1 - [Plivo API vs WhatsApp Business Platform (Cloud API)](https://www.anchorterminal.com/compare/plivo-vs-whatsapp-cloud-api.md): C 60.3 vs B 67.1 - [Sinch Messaging APIs + MCP vs WhatsApp Business Platform (Cloud API)](https://www.anchorterminal.com/compare/sinch-vs-whatsapp-cloud-api.md): B 63.2 vs B 67.1 - [Telnyx API + MCP vs WhatsApp Business Platform (Cloud API)](https://www.anchorterminal.com/compare/telnyx-vs-whatsapp-cloud-api.md): BB 73.6 vs B 67.1 - [Twilio API + MCP vs WhatsApp Business Platform (Cloud API)](https://www.anchorterminal.com/compare/twilio-vs-whatsapp-cloud-api.md): A 80.4 vs B 67.1 - [Vonage Messages API + MCP vs WhatsApp Business Platform (Cloud API)](https://www.anchorterminal.com/compare/vonage-vs-whatsapp-cloud-api.md): B 66.8 vs B 67.1 - [Bandwidth Messaging API + MCP vs WhatsApp Business Platform (Cloud API)](https://www.anchorterminal.com/compare/bandwidth-vs-whatsapp-cloud-api.md): B 64.3 vs B 67.1 - [ClickSend SMS API + MCP vs WhatsApp Business Platform (Cloud API)](https://www.anchorterminal.com/compare/clicksend-vs-whatsapp-cloud-api.md): D 47.7 vs B 67.1 - [Sendblue vs WhatsApp Business Platform (Cloud API)](https://www.anchorterminal.com/compare/sendblue-vs-whatsapp-cloud-api.md): C 61.7 vs B 67.1 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on developers.facebook.com or one of its subdomains, or the README of github.com/facebook/openapi. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "whatsapp-cloud-api", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html WhatsApp Business Platform (Cloud API) on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![WhatsApp Business Platform (Cloud API) on Anchor Terminal](https://www.anchorterminal.com/badges/whatsapp-cloud-api.svg)](https://www.anchorterminal.com/tools/whatsapp-cloud-api) ``` Plain link: ```html WhatsApp Business Platform (Cloud API) on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say WhatsApp Business Platform (Cloud API) is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/whatsapp-cloud-api-dark.png - Light: https://www.anchorterminal.com/assets/share/whatsapp-cloud-api-light.png