WhatsApp Cloud API developer guide · 2026
WhatsApp Business API Key in 2026: Why Meta Gives You an Access Token Instead
Searching for your WhatsApp Business API key? Here's the short version: Meta's official Cloud API doesn't hand out a single "API key." What you need is an access token, the right permissions, your WABA ID and your Phone Number ID. This guide shows where each one lives and how to stop your integration from breaking a week after launch.
By On Cloud API team · Updated · Checked against Meta's access token documentation on the same date
Authorization: Bearer header. This is your "API key".- Quick answer
- API key vs access token
- The 3 token types Meta uses
- Permissions you need
- Where to find your WhatsApp API key
- How to get a permanent token
- Test your credentials
- Token not working? Error codes
- Keeping the token safe
- Is there a free WhatsApp API key?
- Node.js, PHP, Laravel, Python, n8n
- FAQs
Quick answer
There is no standalone WhatsApp Business API key. Meta's WhatsApp Cloud API authenticates every request with a Meta access token. For testing you use a short-lived user token; for production you use a system user access token (or, if you connect through a Tech Provider, a business integration system user token). The token proves who you are. The WABA ID and Phone Number ID tell Meta which account and number to use.
We see this question almost every week. A developer creates a Meta app, adds the WhatsApp product, opens the API Setup page and looks for a field called API Key. It isn't there. Instead there's a token, a Phone Number ID, a WhatsApp Business Account ID and a few other numbers.
Then the CRM, WordPress plugin or n8n node they're connecting asks for a "WhatsApp API key", and the obvious question comes up: which of these values is it?
Nine times out of ten, it's the access token.
WhatsApp Business API key vs access token
Not every value in Meta Business Suite or Meta for Developers is a credential. Here's what each one actually does:
| Value | What it does | Secret? | Common mistake |
|---|---|---|---|
| Access token | Authenticates Graph API requests | Yes | This is what apps mean by "WhatsApp API key" |
| WABA ID | Identifies your WhatsApp Business Account | No | It's an ID, not something you can authenticate with |
| Phone Number ID | Identifies your sender number in API endpoints | No | It is not your visible WhatsApp number |
| App ID | Identifies your Meta app | No | Not a token |
| App Secret | App-level security (e.g. signing, token exchange) | Yes | Pasting it where a Bearer token is expected |
| Webhook verify token | A string you choose to verify your webhook URL | Keep private | It can't send messages |
Simple rule: whatever goes after Authorization: Bearer in your request is your access token, and that's the thing people call the WhatsApp API key.
Why does Meta use access tokens at all?
WhatsApp Cloud API runs on Meta's Graph API. A single request can involve an app, a user or system user, a set of permissions and specific business assets. A plain API key only says "this project called you". A token also carries who is calling and what they're allowed to touch:
Meta App → User / System User → Permissions → WABA / Number → API call
That's also why a token can be perfectly valid and one request can still fail. The token authenticates fine, but the system user behind it may not have been given access to that WABA, that phone number or that permission.
The 3 WhatsApp access token types Meta uses
Meta's access token documentation currently lists three types. Picking the wrong one is the most common reason a WhatsApp integration stops working after going live.
| Token type | Who uses it | What to know |
|---|---|---|
| User access token | Testing and first setup | Short-lived. Meta says you'll need a new one every few hours. Never deploy it. |
| System user access token | Businesses and developers building their own integration | Long-lived and made for backend software. Admin system users see the whole portfolio; employee system users need access granted per WABA. |
| Business integration system user token | Tech Providers and solution partners | Scoped to one onboarded customer. Generated through Embedded Signup by exchanging the code Meta returns. |
This is the real problem behind searches like WhatsApp Business API permanent token, WhatsApp access token expired and WhatsApp Business API credentials not working.
Which WhatsApp Business API permissions do you need?
For a system user token, Meta lists three permissions:
business_management whatsapp_business_management whatsapp_business_messaging
whatsapp_business_messagingcovers sending and receiving messages.whatsapp_business_managementcovers managing the WABA: phone numbers, message templates and settings.business_managementcovers Business Portfolio-level access that system user setups depend on.
Grant what the integration needs and nothing more. Assign the right WABA and phone number to the system user, and keep every ID from the same Meta setup. Mixing an App ID from one portfolio with a WABA ID from another is a surprisingly common cause of permission errors.
Where to find your WhatsApp Business API key (and IDs)
| What you need | Where to find it |
|---|---|
| Test access token | Meta for Developers → your app → WhatsApp → API Setup |
| Production access token | Meta Business Settings → Users → System users → Generate new token |
| Phone Number ID | API Setup page, or the /<WABA_ID>/phone_numbers endpoint |
| WABA ID | API Setup page, or WhatsApp Manager → account overview |
| App ID and App Secret | Meta for Developers → your app → App settings → Basic |
Menu names move around now and then, but the logic doesn't: a test WhatsApp Business API token comes from the app dashboard, and a production token comes from a system user.
Your Phone Number ID is not your phone number
This one catches almost everyone once. Your customers see something like +92 300 1234567. The Cloud API endpoint wants something like 123456789012345. They're not interchangeable. If you put +92…, +971… or +91… in the URL path, the request will fail.
How to get a WhatsApp Business API key that doesn't expire
If you searched "how to get WhatsApp Business API key", this is the production flow you actually want:
- Set up your Meta app and add the WhatsApp product. Know which app and which Business Portfolio the integration belongs to. On Cloud API also has a guide on getting WhatsApp Business API in Pakistan, including the documents Meta asks for.
- Confirm the WhatsApp Business Account. Write down its WABA ID.
- Note the Phone Number ID of the number you'll send from.
- Create a system user in Business Settings. It represents your backend, not a person.
- Assign assets. Give the system user your app and the WhatsApp account.
- Generate the token with
whatsapp_business_messaging,whatsapp_business_managementandbusiness_management. Business Settings asks you to pick an expiry; many teams choose a non-expiring token and rotate it on their own schedule. - Store it on the server, in an environment variable or a secrets manager.
- Test one small request before connecting the token to a CRM, chatbot or automation.
How to test your WhatsApp access token
Before debugging your whole app, try the smallest authenticated request you can.
1. List the phone numbers on your WABA
curl -X GET \ "https://graph.facebook.com/<GRAPH_API_VERSION>/<WABA_ID>/phone_numbers" \ -H "Authorization: Bearer <ACCESS_TOKEN>"
If this returns your numbers, four things are confirmed at once: the token works, the WABA ID is right, the system user can see that WABA, and you now have the Phone Number ID you need.
2. Send a template message
curl -X POST \
"https://graph.facebook.com/<GRAPH_API_VERSION>/<PHONE_NUMBER_ID>/messages" \
-H "Authorization: Bearer <ACCESS_TOKEN>" \
-H "Content-Type: application/json" \
-d '{
"messaging_product": "whatsapp",
"to": "<RECIPIENT_NUMBER>",
"type": "template",
"template": {
"name": "<APPROVED_TEMPLATE_NAME>",
"language": { "code": "<LANGUAGE_CODE>" }
}
}'
Replace <GRAPH_API_VERSION> with a current version from Meta's Graph API changelog (for example v25.0). The WhatsApp Business API endpoint URL always starts with https://graph.facebook.com/.
So where do you put your WhatsApp API key? In the Authorization header, as a Bearer token. That's it.
WhatsApp API token not working? Check these error codes
Not every authentication error means the token is broken. Debug in this order:
Access token → Permissions → WABA access → Phone Number ID → Message request
| What you see | Likely cause | What to check |
|---|---|---|
Error 190 (OAuthException) | Token expired or invalid | Did you deploy a user/testing token? Was the token revoked or regenerated? |
Error 200 or 10 | Missing permission | Is the right WhatsApp permission granted to this system user? |
Error 100 | Invalid parameter | Wrong Phone Number ID or WABA ID, or a phone number in the URL |
| Token valid but WABA request fails | Asset not assigned | Has the system user been given access to that WABA? |
| Webhook verifies, sending fails | Wrong credential | Are you sending the webhook verify token instead of the access token? |
Working through these layers one by one is much faster than regenerating every credential at once and then debugging a brand-new setup.
Treat your WhatsApp access token like a password
A production token can send messages from your business number. Keep it out of anywhere it could leak.
Do this (server-side .env):
WHATSAPP_ACCESS_TOKEN=your_secret_access_token WHATSAPP_WABA_ID=your_waba_id WHATSAPP_PHONE_NUMBER_ID=your_phone_number_id
Not this (hard-coded in your code):
const token = "EAA...REAL_PRODUCTION_TOKEN...";
- Keep it on your backend. Never in browser JavaScript or a mobile app bundle.
- Never commit it to GitHub, even in a private repo.
- Don't log the full token, and don't share it in screenshots or support chats.
- Give the system user only the assets and permissions it needs.
- If a token leaks, revoke it and generate a new one straight away.
Access token vs webhook verify token vs App Secret
All three often sit in the same .env file, which is exactly why they get mixed up. The access token authorizes API calls. The webhook verify token is a string you make up so Meta can confirm your callback URL during WhatsApp Business API webhook setup. The App Secret belongs to your Meta app and is used for app-level security such as validating webhook signatures. None of them can stand in for another.
Is there a free WhatsApp Business API key?
No, and there's no paid one either. An access token is just a credential. It isn't a plan and it doesn't come with free messages. Searches like free WhatsApp Business API key or WhatsApp Business API key price mix up three separate things:
Authentication (free) ≠ Meta message charges ≠ Platform subscription
- Authentication: generating a token costs nothing.
- Meta message charges: Meta bills per message by category and country. Some service messages are free, and Meta's rules change, so check the current rate card.
- Platform fee: if you use a dashboard like On Cloud API for a shared inbox, chatbot and campaigns, that's a separate subscription. You can see On Cloud API pricing here. For Pakistan-specific rates, read our guide on WhatsApp Business API pricing in Pakistan.
Node.js, PHP, Laravel, Python, Java and n8n all use the same token
The language changes your HTTP client, not Meta's authentication. Laravel keeps credentials in .env. Node.js and JavaScript use fetch or Axios. Python uses requests. Java uses its HTTP client. An n8n workflow uses an HTTP Request node, and Postman uses the Authorization tab (Meta also publishes an official WhatsApp Cloud API Postman collection). Underneath, it's always the same request:
POST https://graph.facebook.com/<GRAPH_API_VERSION>/<PHONE_NUMBER_ID>/messages Authorization: Bearer <ACCESS_TOKEN> Content-Type: application/json
The same goes for country. There's no separate WhatsApp API key for Pakistan, the UAE, India, Bangladesh, Saudi Arabia or the UK. The authentication model is the same everywhere. What changes by country is message pricing, local rules and consent requirements.
Where On Cloud API fits
On Cloud API is a Meta Verified Tech Provider built on the official WhatsApp Cloud API. If you'd rather not build tokens, webhooks, templates and an inbox yourself, the platform gives you a shared team inbox, chatbot and AI agent builder, broadcast campaigns, a REST API and integrations on top of Meta's API.
Learn more about On Cloud API, compare plans and pricing, or browse more WhatsApp Business API guides, like WhatsApp chatbot vs AI agent.
WhatsApp API credentials checklist
- You know which Meta app and Business Portfolio the integration uses.
- You have the right WABA ID and Phone Number ID, from the same setup.
- You're using a system user token (or a Tech Provider's integration token), not a testing token.
- The system user has access to the WABA and phone number.
- The token has
whatsapp_business_messaging,whatsapp_business_managementandbusiness_management. - Requests use
Authorization: Bearer <TOKEN>. - The token stays on the server. The webhook verify token and App Secret are stored separately.
Frequently asked questions
Does WhatsApp Business API have an API key?
No. Meta's official WhatsApp Cloud API doesn't issue a standalone API key. Every request is authenticated with a Meta access token sent as a Bearer token in the Authorization header.
How do I get a WhatsApp Business API key?
What you need is an access token. Use the short-lived token from your app's API Setup page for testing, then create a system user in Meta Business Settings, assign it your app and WhatsApp account, and generate a system user access token for production.
Where do I find my WhatsApp Business API key?
A test token is on the WhatsApp API Setup page in Meta for Developers. A production token is generated under Business Settings, System users. Your WABA ID and Phone Number ID are shown on the API Setup page, but they are IDs, not the key.
How do I get a permanent WhatsApp Business API access token?
Generate a system user access token instead of using the testing token. When you generate it in Business Settings you choose an expiry, and many teams pick a non-expiring token and rotate it on their own schedule.
What permissions does a WhatsApp system user token need?
Meta lists business_management, whatsapp_business_management and whatsapp_business_messaging for system user access tokens. The system user also needs access to the right WhatsApp Business Account and phone number.
What is a business integration system user access token?
It's a token scoped to a single onboarded customer, used by Tech Providers and solution partners. It is generated through Embedded Signup by exchanging the code Meta returns, so customers of a Tech Provider usually don't copy a token themselves.
Is my Phone Number ID the same as my WhatsApp number?
No. The Phone Number ID is a Meta-assigned identifier used in Cloud API endpoints. Your visible WhatsApp number, such as +92 300 1234567, is a different value and won't work in the endpoint URL.
Is the webhook verify token the same as the access token?
No. The webhook verify token is a string you choose so Meta can verify your callback URL. It cannot authorize API calls; only the access token can.
Why does my WhatsApp token work in testing and then stop?
You most likely deployed the short-lived user access token from the API Setup page. Error code 190 usually means the token has expired or is invalid. Switch to a system user token and check permissions and asset access.
Is there a free WhatsApp Business API key?
There is no free or paid API key product. Generating an access token costs nothing. Meta's per-message charges and any platform subscription, such as On Cloud API's plans, are separate from authentication.
Can I put my WhatsApp access token in frontend JavaScript?
No. Keep the token on your server or in a secrets manager. Never expose it in browser code, mobile app bundles, public repositories or screenshots.
Skip the token setup
Connect your number to On Cloud API and start sending from a shared inbox, with 0% markup on Meta's message rates.
Sign up free View pricing

