# WhatsApp Business Platform (Cloud API) (slim) > Meta's WhatsApp Business Platform Cloud API sends and receives WhatsApp messages for a business phone number through the Graph API, with inbound messages and status updates arriving by webhook. Access uses a Meta developer app and OAuth access tokens. - Full: https://www.anchorterminal.com/tools/whatsapp-cloud-api.md (~9,050 tokens) · this version ~2,230 tokens · JSON https://www.anchorterminal.com/tools/whatsapp-cloud-api.json · canonical https://www.anchorterminal.com/tools/whatsapp-cloud-api - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 67.1/100 · rank #218 of 722 · #5 in Messaging APIs · not agent-ready · confidence medium** Assessment: The first-party WhatsApp API has a public OpenAPI document, Markdown docs with llms.txt, numeric rate limits and a test number that sends without a payment method. Setup needs a person in three Meta dashboards, no idempotency key was found for sends, and Meta's terms restrict general-purpose AI assistants on the platform. ## Facts - Kind: HTTP API · vendor: Meta Platforms, Inc. · category: Messaging APIs · legal entity: Meta Platforms, Inc. · provenance 94/100 - Endpoint: `https://graph.facebook.com` (HTTP) - Auth: OAuth · pricing: Pay per use · x402: no · licence: Proprietary service under the Meta Terms for WhatsApp Business Platform. The OpenAPI document in facebook/openapi is MIT - Probe metrics: not measured yet (probes haven't run) - API: Graph API at https://graph.facebook.com/. Cloud API for messages, media, calling and groups, and the Business Management API for accounts, phone numbers, templates and analytics. The reference index lists 66 pages - Versions: Graph API v26.0 from 29 July 2026, v25.0 from 18 February 2026. Each version stays available for about two years (v23.0 until 8 October 2027). Docs examples use v17.0, v23.0 and v25.0 - Access: A Meta developer app with the WhatsApp use case, a business portfolio and a WhatsApp Business account. Direct developers need no App Review. Apps acting for other businesses need Advanced access through App Review and Embedded Signup - Credentials: System user access tokens with a chosen expiry, business integration system user tokens per onboarded customer, and short-lived user tokens. Permissions `whatsapp_business_messaging`, `whatsapp_business_management` and `business_management`. Partial or full asset access per WhatsApp Business account - Message rules: Free-form messages only within 24 hours of the user's last message. Outside that window only templates, which Meta reviews and places in the marketing, utility or authentication category. Users must have opted in - Rate limits: 80 messages a second per number (1,000 by automatic upgrade, 20 for numbers shared with the WhatsApp Business app). One message every 6 seconds to the same user, with bursts of 45. Management endpoints 200 requests an hour per app and account, 5,000 for active accounts - Messaging limits: Unique users reachable outside service windows in a moving 24 hours, per business portfolio. 250 at first, then 2,000 after business verification or 2,000 good-quality sends in 30 days, then 10,000, 100,000 and unlimited - Webhooks: Inbound messages and delivery statuses arrive only by webhook. HMAC-SHA256 signature in `X-Hub-Signature-256`, optional mutual TLS, batches of up to 1,000 updates, retries with backoff for up to 7 days, and no API for past webhook data - Errors: JSON error object with `code`, `message`, `error_data.details` and `fbtrace_id`. Throttling codes 4, 80007, 130429, 131048 and 131056. Some errors arrive only in the `messages` webhook - Pricing model: Per delivered message, by category and recipient country, with volume tiers for utility and authentication. Rate cards as CSV and PDF in 16 currencies. Rates may change on the first day of a quarter, with one month's notice for rates and six for a model change - Test resources: A test WhatsApp Business account and test number are created with the app, have relaxed limits and need no payment method to send template messages - Data handling: Meta is processor for Cloud API. Messages kept at most 30 days, media 30 days, encrypted at rest. Local storage keeps message content at rest in a chosen region, and a no-storage option was added on 1 December 2025 - MCP server: https://mcp.facebook.com/whatsapp_business_tools, streamable HTTP, OAuth with the three WhatsApp permissions, 18 documented tools for accounts, numbers, templates, webhooks and sending. Beta, rolling out gradually. The send tool asks for confirmation - SDKs and tools: No current official SDK for Cloud API. The WhatsApp Node.js SDK (npm `whatsapp` 0.0.5-Alpha, April 2023) is archived. An official Postman collection and an API playground in the reference - Certifications: SOC 2 Type II, SOC 3, ISO 27001, GDPR and LGPD documents for Cloud API listed in the Business Messaging Compliance Centre. Bug bounty at bugbounty.meta.com - Status: metastatus.com/whatsapp-business-api, with components for Cloud API, localised storage, account management, Embedded Signup and the Marketing Messages API, availability and latency figures for Cloud API, and a JSON and RSS history - Prices: Utility or authentication template, Brazil $0.0068 per message - Scores: Reliability 80, Performance pending, Schema & documentation 82, Agent ergonomics 67, Security & auth 67, Payments & pricing 40, Task success pending, Maintenance & community 34, Transparency & trust 82 · total over the 7 assessed categories - Why: Reliability, Graded on the public Cloud API, with the hosted lines. · Schema & documentation, A public OpenAPI 3.1 document in facebook/openapi with 78 paths, 113 operations and 369 schemas. · Agent ergonomics, Graph API reads take `fields` and `limit`, and one field, `health_status`, summarises whether a number can send. · Security & auth, OAuth access tokens with permissions that separate messaging from account management, revocable, with a chosen expiry on system user tokens. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, Closed service. · Transparency & trust, Editorial half only. - Sources: 37, open questions: 12, both in the full twin - Capabilities: messaging.whatsapp, messaging.inbound - JSON: https://www.anchorterminal.com/api/v1/tools/whatsapp-cloud-api.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/whatsapp-cloud-api.svg` or a link to https://www.anchorterminal.com/tools/whatsapp-cloud-api from a page on developers.facebook.com or one of its subdomains, or the README of github.com/facebook/openapi, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Check when the user last wrote. Free-form messages are accepted only within 24 hours of the user's last message. After that, send an approved template. 2. Record the message id from each send and match it to `messages` webhook statuses. Many failures arrive only by webhook, and no idempotency key was found. 3. On error 130429 or 131056 wait and retry. Meta's guidance for the per-recipient limit is 4^X seconds, with X rising by one per failure. 4. Verify `X-Hub-Signature-256` with the app secret on every webhook, and deduplicate, because failed deliveries are retried for up to 7 days. 5. Request `health_status` on the phone number before a campaign to see whether the app, business, account, number and template can send. ## Connect ```bash curl 'https://graph.facebook.com/v23.0//messages' \ -H 'Content-Type: application/json' \ -H 'Authorization: Bearer ' \ -d '{"messaging_product":"whatsapp","recipient_type":"individual","to":"","type":"text","text":{"body":"Hello!"}}' ``` ```bash claude mcp add --transport http whatsapp_business_tools https://mcp.facebook.com/whatsapp_business_tools ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/whatsapp-cloud-api ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Twilio API + MCP | A | 80.4 | messaging.whatsapp, messaging.inbound | https://www.anchorterminal.com/tools/twilio.min.md | | Bird API + MCP | BB | 76.5 | messaging.whatsapp, messaging.inbound | https://www.anchorterminal.com/tools/bird.min.md | | AWS End User Messaging | BB | 74.3 | messaging.whatsapp, messaging.inbound | https://www.anchorterminal.com/tools/aws-end-user-messaging.min.md | | Telnyx API + MCP | BB | 73.6 | messaging.whatsapp, messaging.inbound | https://www.anchorterminal.com/tools/telnyx.min.md | | Vonage Messages API + MCP | B | 66.8 | messaging.whatsapp, messaging.inbound | https://www.anchorterminal.com/tools/vonage.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)