Meta approval and BSP readiness
What Meta requires before a WhatsApp Cloud API product can serve customers at scale, and how to work through it.
1. Meta Business verification
- Verify your company in Meta Business Manager using registration documents, a business email and a business phone number.
- The entity must be legally registered; the name on the documents must match the Business Manager profile.
- Verify your business domain via a DNS TXT record, a meta tag, or an HTML file upload.
- Verification typically takes a few business days; rejections are usually caused by mismatched or low-quality documents.
2. WhatsApp Business Account (WABA) setup
- 1Create a Meta app of type Business and add the WhatsApp product to it.
- 2Create or attach a WhatsApp Business Account under your verified business.
- 3Register a phone number that is not currently active on the WhatsApp consumer or Business app.
- 4Submit a display name that matches your brand — generic names and misleading names are rejected.
- 5Add a payment method: Meta bills conversations directly, and sending stops once the free tier is exhausted.
Messaging tiers
New numbers start at 250 unique recipients per day and scale to 1k, 10k, 100k and unlimited as quality stays green and volume grows.
3. App review and permissions
A multi-tenant product needs advanced access to the WhatsApp permissions. Each one is requested in App Review with a screencast showing real usage.
| Permission | Why it is needed |
|---|---|
| whatsapp_business_messaging | Send and receive messages on behalf of a customer's WABA. |
| whatsapp_business_management | Create and manage templates, phone numbers and WABA settings. |
| business_management | Read the connected business assets during embedded signup. |
- Record a screencast of the full flow: a tenant signs up, connects their WhatsApp account, creates a template and sends a message.
- Provide test credentials so the reviewer can reproduce the flow.
- Publish a privacy policy URL, terms of service URL and a data deletion instructions URL.
- Complete the Data Use Checkup annually to keep advanced access.
4. Embedded signup
- Embedded signup is the supported way for tenants to connect their own WhatsApp Business Account without sharing tokens.
- It requires the Facebook Login for Business configuration attached to your app, with a configuration ID.
- Tokens returned by embedded signup are exchanged server-side and stored encrypted per tenant.
- Wappr exposes this in Settings → WhatsApp; if it is not configured, tenants can still paste credentials manually.
5. Templates and policy compliance
- Every conversation started outside the 24-hour service window uses a template approved by Meta.
- Categorise correctly: Marketing, Utility or Authentication. Promotional content filed as Utility is rejected.
- Give a real example value for each variable, and never leave placeholders unexplained.
- Document opt-in: you must be able to show where and how a customer agreed to be messaged.
- Honour opt-outs and unsubscribe keywords; block and report rates drive number quality down fast.
- Check the WhatsApp Business Policy and Commerce Policy for prohibited industries and products.
6. Tech Provider / Solution Partner status
- Selling WhatsApp messaging to other businesses makes you a Tech Provider; advanced access plus business verification is the minimum.
- Meta Business Partner (Solution Partner) status is a separate application with revenue, support and volume requirements.
- As a Tech Provider you can onboard tenants through embedded signup while Meta bills each tenant directly.
- As a Solution Partner you can be billed for your tenants' conversations and resell with markup.
Full positioning, approved marketing wording and the Business Partner readiness matrix live on Tech Provider vs Solution Partner.
7. Go-live checklist
- 1Business verified and domain verified in Business Manager.
- 2WABA created, phone number registered, display name approved.
- 3Payment method added to the WABA.
- 4Advanced access granted for the WhatsApp permissions after App Review.
- 5Embedded signup configured so tenants self-connect.
- 6Core templates submitted and approved.
- 7Privacy policy, terms and data deletion URLs live and reachable.
- 8Opt-in capture and opt-out handling in place for every messaging surface.
Track it in the app
Workspace owners can track all of this in Onboarding & Meta readiness inside the app, which detects the setup steps automatically and lets you tick off the Meta ones.