On Cloud API
WhatsApp Business API Platform
Ready100%
Platform FeaturesEverything you need across WhatsApp, Instagram & Messenger
WhatsApp Team InboxOne number, many agents — zero missed chats
Instagram InboxDMs, story replies & comments in one place
Messenger InboxPage DMs & post comments as conversations
AI Agent (RAG)A smart agent trained on your own business data
Multiple Human Live ChatHandle chats from several agents at once
Ask AIAI-powered smart replies & suggestions
Chatbot Flow BuilderBuild automated reply flows, no coding needed
Retarget Users on WhatsAppRe-engage past contacts with targeted messages
WhatsApp SchedulerSchedule messages for the perfect moment
Import, Broadcast & TrackBulk send campaigns & monitor delivery rates
Ads that Click to WhatsAppTurn ad clicks directly into WhatsApp chats
Multi-Agent Live ChatOne number, many agents — zero missed chats
Connect No Code A.I. ChatbotsPlug in AI bots with zero lines of code
Broadcast CampaignsNo campaign cap from us — Meta’s messaging limits apply
Official, Not a Grey ToolMeta-approved Cloud API — no unofficial workarounds
See all features & pricing
Industries We PowerPurpose-built WhatsApp automation for every sector
Education & EdtechCoaching, Institutes & Online Learning
Banking & FintechDigital Payments, Lending & Finance
HealthcareClinics, Hospitals & Wellness
Events & WebinarConferences, Meetups & Live Events
EcommerceOnline Stores, D2C & Marketplaces
Real EstateAgents, Developers & Property Listings
IT Services & InternetTech Support, SaaS & Web Services
Offline & RetailStores, Outlets & Local Businesses
HR & RecruitmentHiring, Onboarding & Talent Acquisition
Spas & SalonsBookings, Promotions & Client Loyalty
AutomobileDealerships, Service Centers & Rentals
Travel & TourismBookings, Tours & Hospitality
Marketing AgenciesCampaigns, Leads & Client Updates
GovernmentPublic Services & Citizen Engagement
Gym & Fitness CentersMemberships, Classes & Reminders
Blogs
All Blogs/Article
Article

Temporary vs Permanent WhatsApp Access Token: Which One Should You Use?

On Cloud API TeamSeptember 27, 202610 min read17 views

Both tokens go in the same header and call the same endpoints. One is built to get your first message out in five minutes. The other is built to keep a business running for years. Mixing them up is one of the most common reasons WhatsApp integrations "randomly" break.

Temporary vs Permanent WhatsApp Access Token: Which One Should You Use?

WhatsApp Cloud API · Token decision guide · 2026

Temporary vs Permanent WhatsApp Access Token: Which One Should You Use?

Both tokens go in the same header and call the same endpoints. One is built to get your first message out in five minutes. The other is built to keep a business running for years. Mixing them up is one of the most common reasons WhatsApp integrations "randomly" break.

By On Cloud API team · Updated · Checked against Meta's access token documentation on the same date

Quick answer

Use the temporary user access token from your app's WhatsApp → API Setup page only for testing. Meta says it expires in less than 24 hours. For anything that has to keep running (a CRM, chatbot, n8n workflow, order alerts), use a system user access token, which you can generate with a 60-day expiry or no expiry at all. Both need the right permissions and access to your WhatsApp Business Account. A longer life doesn't fix a missing permission.

Every developer we've helped with this has the same story. The test token worked, so it went live. A day later, messages stopped. The code was fine; the token had simply done what it was designed to do and expired.

Temporary vs permanent WhatsApp token: side by side

Temporary (user) tokenPermanent (system user) token
Where you get itMeta for Developers → your app → WhatsApp → API Setup, or Graph API ExplorerMeta Business Settings → Users → System users → Generate token
LifetimeUnder 24 hours; Meta says you'll regenerate it every few hours60 days or Never, chosen when you generate it
RepresentsYou, the logged-in personYour backend software
Setup effortOne clickCreate system user, assign app and WABA, pick permissions
Right forFirst API call, Postman tests, template checksProduction, persistent staging, automations
Permissions neededYesYes: business_management, whatsapp_business_management, whatsapp_business_messaging
Safe in frontend code?NoNo, and it's even riskier because it doesn't expire

What doesn't change: the endpoint, the Authorization: Bearer header, your WABA ID and your Phone Number ID. Switching tokens changes who is calling, not where the call goes.

Which WhatsApp token for which job?

What you're doingUse
Sending your first test message or trying the Postman collectionTemporary token
A local prototype you'll throw away todayTemporary token
A staging server with automated tests that run every nightSeparate system user token
Production CRM, support inbox, order or OTP notificationsSystem user token
An n8n, Make or Zapier workflow that runs on a scheduleSystem user token, saved in the tool's credential store
Your company requires credentials to be rotatedSystem user token with 60-day expiry + a rotation reminder
Calling WhatsApp from browser JavaScript or a mobile appNeither. Call your own backend, and let the backend call Meta.
A SaaS where many customers connect their own numbersEmbedded Signup (see below)

Permanent or 60 days? The trade-off nobody mentions

"Permanent" sounds like the obvious choice because nothing expires. But token lifetime is also a security decision.

ChoiceGood whenThe catch
Never expiresSmall team, one integration, no rotation processIf it leaks, it works for an attacker until you notice and revoke it
60 daysYou already rotate secrets, or compliance requires itForget to renew and production stops on day 60

Our rule of thumb: if you have a calendar reminder and a documented swap process, 60 days is safer. If you don't, a non-expiring token plus strict secret handling is more reliable than a 60-day token nobody remembers to renew.

Also, "permanent" means no scheduled expiry. The token still dies if someone revokes it, removes the system user's access to the WABA or app, or deletes the system user.

How to tell which token you're currently using

Inherited an integration and not sure what's in the .env file? Don't guess from how the string looks. Both token types look alike.

  1. Paste it into Meta's Access Token Debugger.
  2. Check Type: "User" means a temporary token; "System User" means a production token.
  3. Check Expires: a time within the next day is a test token; "Never" or a date about 60 days out is a system user token.
  4. Check Scopes for the three WhatsApp-related permissions.
Red flag: if the Debugger says "User" and the token is in your production server's config, you've found the reason messages stop every day.

Should staging and production share one token?

Ideally, no. A shared token is quicker to set up, but a staging mistake (a leaked log, a debug screenshot, a teammate's laptop) then exposes your production credential too. Give staging its own system user and token, preferably on a test number. You'll also be able to tell from Meta's logs which environment sent what.

Building a SaaS? Neither token is the right answer

If you're building a platform where customers connect their own WhatsApp numbers, don't ask each customer to generate a system user token and paste it into your app. That's fragile and hard to support.

Meta's route for this is Embedded Signup. The customer connects their WhatsApp account through a Meta popup inside your app, and you receive a business integration system user token scoped to that one customer. On Cloud API works as a Meta Verified Tech Provider on the official Cloud API; you can read more in the On Cloud API overview.

Symptoms of using the wrong token

What you seeProbably means
Works in the morning, fails by the next dayA temporary token is in production
Error 190 (OAuthException)Token expired, revoked or invalid
Works in Postman, fails on the serverServer still has the old token cached; restart workers and containers
New permanent token, same error as beforeNot a token problem: check WABA assignment, permissions and Phone Number ID
Stopped exactly 60 days after launchThe system user token was generated with a 60-day expiry

The same logic applies whether you're working in Laravel, PHP, Node.js, Python or n8n. The language doesn't change the token rules. For n8n specifically, our WhatsApp Business API + n8n guide shows where to store the credential so a token swap is a one-field change.

Frequently asked questions

What is the difference between a temporary and a permanent WhatsApp access token?

The temporary token is a user access token from your app's API Setup page, meant for testing, and Meta says it expires in less than 24 hours. The permanent token is a system user access token created in Meta Business Settings for backend software, and you can set it to expire in 60 days or never.

Which WhatsApp access token should I use in production?

A system user access token, with the app and WhatsApp Business Account assigned to the system user and the business_management, whatsapp_business_management and whatsapp_business_messaging permissions selected.

Can I use the temporary WhatsApp token in production?

It will work until it expires, which is less than a day. After that every API call fails, so it should never be used for a live integration.

Is a 60-day token safer than a permanent token?

It limits how long a leaked token stays useful, but production stops if nobody renews it. A 60-day token suits teams with a rotation process; a non-expiring token with strict secret handling suits teams without one.

Does a permanent WhatsApp token ever stop working?

Yes, if it is revoked, the system user is deleted, or the system user loses access to the app, the WhatsApp Business Account or a required permission. Permanent only means it has no scheduled expiry.

How can I check whether my WhatsApp token is temporary or permanent?

Paste it into Meta's Access Token Debugger. A type of User with an expiry within a day is a temporary token; a type of System User with an expiry of Never or about 60 days is a production token.

Should staging and production use the same WhatsApp token?

It is better to give staging its own system user and token so a leak or mistake in staging does not expose the production credential.

How do SaaS platforms get tokens for their customers' WhatsApp numbers?

Through Meta's Embedded Signup. The customer connects their WhatsApp account in a Meta popup and the platform receives a business integration system user token scoped to that customer, so nobody copies tokens by hand.

Ready to Start with WhatsApp Business API?

Join 5,000+ businesses. Meta Verified. 0% markup on Meta rates. Live in 10 minutes.