Configuring WhatsApp Webhook

The Webhook tab is used to connect or reconfigure your WhatsApp Business Cloud API account. It contains the webhook details you need to copy into Meta, plus the API credentials required for the platform to communicate with your WhatsApp Business Account.

Use this page carefully because incorrect credentials can stop incoming messages, delivery events, and WhatsApp API communication.


📍 Where to Find the Webhook Tab #

Go to:

Settings → WhatsApp Settings → Webhook

This tab is available for users with Integration View permission.

To validate and save credentials, your user must have Integration Edit permission.


🧩 What the Webhook Tab Includes #

The tab is divided into two main sections:

  • 🔗 Webhook
  • 🔐 WhatsApp API Credentials

The Webhook section is mainly used for Meta configuration.

The API Credentials section is used to validate and link the WhatsApp Business Cloud API account to the platform.


🔗 Webhook Section #

The Webhook section shows two important values:

  • Callback URL
  • Verify Token

These values are used when configuring the webhook inside Meta for Developers.


🌐 Callback URL #

The Callback URL is the endpoint Meta uses to send WhatsApp events to your platform.

Meta sends events such as:

  • Incoming customer messages
  • Message delivery updates
  • Message read updates
  • Template status updates
  • WhatsApp account events

Click the copy icon beside the Callback URL to copy it quickly.

Use this value in Meta when setting up the WhatsApp webhook callback endpoint.


🔑 Verify Token #

The Verify Token is used by Meta to confirm that the webhook belongs to your system.

When Meta verifies the webhook, it sends a verification request to the Callback URL and checks the token.

Click the copy icon beside the Verify Token to copy it.

The Verify Token entered in Meta must exactly match the value shown in this tab.


🔐 WhatsApp API Credentials Section #

The WhatsApp API Credentials section contains the account details required to connect your WhatsApp Business Cloud API account.

Required fields include:

  • ☎️ Phone Number ID
  • 🏢 WhatsApp Business Account ID
  • 🔒 Meta App Secret
  • 🔑 Permanent Access Token
  • 🌍 Time Zone

☎️ Phone Number ID #

The Phone Number ID identifies the WhatsApp phone number used by the Cloud API.

This is not always the same as the visible phone number customers see.

Use the Phone Number ID from your Meta WhatsApp Business setup.

This field is required.


🏢 WhatsApp Business Account ID #

The WhatsApp Business Account ID identifies the WABA connected to your Meta Business account.

The system uses this ID to validate the WhatsApp Business Account and confirm that registered phone numbers exist.

This field is required.


🔒 Meta App Secret #

The Meta App Secret is used for webhook and API security.

This field is required.

Important warning:

  • Entering an incorrect App Secret can stop messages and events from Meta webhooks.
  • The App Secret is hidden for security.
  • Once saved, it cannot be retrieved from the field.

Only update this value when you are sure it is correct.


🔑 Permanent Access Token #

The Permanent Access Token allows the platform to call the WhatsApp Cloud API.

This token is required for actions such as:

  • Sending messages
  • Reading account details
  • Updating WhatsApp profile data
  • Syncing phone number information
  • Checking messaging limits

This field is required.

The page includes a link to Meta documentation for creating a permanent token.


🌍 Time Zone #

The Time Zone field controls the time zone used for the WhatsApp integration.

Choose the time zone that matches your business operations.

This helps keep message-related times, reports, and account configuration aligned with your business location.


✅ Validate and Link Account #

After entering the required credentials, click:

Validate and link the account

The system then checks the credentials with Meta.

During validation, the platform:

  • Builds a WhatsApp API configuration using the entered token and Phone Number ID.
  • Checks the WhatsApp Business Account ID.
  • Confirms that the account has at least one registered phone number.
  • Saves the account configuration.
  • Retrieves the phone messaging limit.
  • Updates the current company session with the connected WhatsApp account details.
  • Starts background synchronization for WhatsApp business account data.

If everything is valid, the system shows:

API credentials validated and saved successfully.


⚠️ Validation Errors #

You may see an error if:

  • The Permanent Access Token is invalid.
  • The WhatsApp Business Account ID is incorrect.
  • The Phone Number ID does not belong to the account.
  • There is no business phone number registered.
  • Meta rejects the credentials.
  • The App Secret is incorrect.
  • The token does not have the required permissions.

Example error messages include:

  • There is no business phone number registered.
  • Invalid API credentials. There was an error fetching business phone number details.

🧪 Recommended Setup Steps #

  1. Copy the Callback URL from the Webhook tab.
  2. Copy the Verify Token from the Webhook tab.
  3. Add both values to your Meta webhook configuration.
  4. Enter the Phone Number ID.
  5. Enter the WhatsApp Business Account ID.
  6. Enter the Meta App Secret.
  7. Enter the Permanent Access Token.
  8. Select the correct Time Zone.
  9. Click Validate and link the account.
  10. Confirm that the success message appears.

🔎 Common Issues #

🚫 Webhook Verification Fails in Meta #

Check that:

  • The Callback URL was copied correctly.
  • The Verify Token matches exactly.
  • There are no extra spaces before or after the token.
  • Your website is reachable from Meta.
  • The webhook endpoint is active.

❌ API Credentials Validation Fails #

Check that:

  • The Permanent Access Token is still valid.
  • The token belongs to the correct Meta Business account.
  • The WhatsApp Business Account ID is correct.
  • The Phone Number ID is correct.
  • The WhatsApp phone number is registered in Meta.
  • The token has the required WhatsApp permissions.

🔒 Messages Stop After Updating App Secret #

The Meta App Secret may be incorrect.

Re-enter the correct App Secret and validate the account again.


📵 No Business Phone Number Registered #

This means Meta did not return a phone number for the WhatsApp Business Account.

Check your WhatsApp Business Account setup in Meta and confirm that the phone number is connected.


🧠 Best Practices #

  • ✅ Copy webhook values using the copy icon to avoid typing mistakes.
  • 🔐 Store the Meta App Secret and Permanent Access Token securely.
  • 👥 Limit access to this tab to technical admins only.
  • 🧪 Validate credentials immediately after updating them.
  • ⚠️ Avoid changing credentials during active campaigns.
  • 🌍 Keep the Time Zone aligned with your business location.
  • 🔁 Revalidate the account after rotating tokens or app secrets.
  • 📌 Confirm incoming messages still arrive after webhook changes.

✅ Summary #

The Webhook tab connects your platform to the WhatsApp Business Cloud API. It provides the Callback URL and Verify Token for Meta webhook setup, and it stores the API credentials needed to send and receive WhatsApp messages.

Use this tab carefully. Correct webhook and API configuration is required for incoming messages, delivery updates, customer replies, profile updates, and other WhatsApp Cloud API features to work properly.

What are your feelings

Updated on May 31, 2026