Genuka WA docs

Official WhatsApp API vs unofficial APIs (WAHA, Baileys…)

Whapi.Cloud, WAHA, Green API, Baileys: how unofficial WhatsApp APIs work, their ban and reliability risks, and what changes with the official API.

An unofficial WhatsApp API (Whapi.Cloud, WAHA, Green API, Evolution API in Baileys mode, Baileys, whatsapp-web.js) drives a WhatsApp account the way WhatsApp Web does, after you scan a QR code. It is quick and needs no approval from Meta, but it breaks WhatsApp's Terms of Service and the number can be banned. The official API goes through Meta's Cloud API.

Last updated October 8, 2026

How this page was written

Genuka sells access to the official API, so we have a stake in this comparison. To keep it fair, every claim about a tool comes from that tool's own documentation, and every WhatsApp rule from WhatsApp's own texts, read on the date above and listed under Sources. We found no published ban rate, from WhatsApp or from these projects, so we quote none.

How does an unofficial WhatsApp API work?

WhatsApp lets you link secondary devices to an account: that is how WhatsApp Web works. An unofficial API poses as one of those devices. You scan a QR code from Linked devices on your phone, or enter a pairing code, and the tool sends and receives the account's messages the way a browser would.

There are two techniques:

  • Drive the real WhatsApp Web in a browser. whatsapp-web.js and WAHA's WEBJS and WPP engines launch Chromium with Puppeteer and call WhatsApp Web's internal functions.
  • Speak the WhatsApp Web protocol directly. Baileys, and WAHA's NOWEB and GOWS engines, open a WebSocket connection with no browser.

On top of that, some projects add an HTTP API and webhooks: WAHA and Evolution API run on your own server, while Green API and Whapi.Cloud are hosted services that keep the session for you.

ToolTypeHow it connects to WhatsAppListed priceWhat the project says
BaileysTypeScript library, MIT licenseWebSocket, QR code or pairing codeFree"not affiliated […] with WhatsApp"; "Do not spam people with this"
whatsapp-web.jsNode.js library, Apache 2.0 licenseWhatsApp Web driven by PuppeteerFree"it is not guaranteed you will not be blocked by using this method"
WAHASelf-hosted HTTP server (Docker), Apache 2.0 licenseBrowser (WEBJS, WPP) or WebSocket (NOWEB, GOWS), QR codeFree; optional $5 a month support tier"WhatsApp does not allow bots or unofficial clients on their platform"
Evolution APISelf-hosted REST server, Apache 2.0 license with extra conditions (usage notice required, otherwise a commercial license)Your choice: Baileys (WhatsApp Web) or Meta's official Cloud APIFreeBaileys mode "may have limitations compared to official APIs"
Green APIHosted serviceQR code through Linked devices; the phone stays charged and online, or is hosted by themDeveloper free, Business $12 a month, Chatbot $24 a month"The decision to block an account is made by WhatsApp"
Whapi.CloudHosted serviceLinked-device session, QR code or pairing codeLimited free Sandbox; Developer Premium at $29 a month per number (shown struck through from $40)"Any automation can carry a risk of WhatsApp restrictions"

Evolution API is only unofficial in Baileys mode: its Cloud API connector goes through Meta's platform, under the same rules as Genuka WA.

Why do developers pick an unofficial API?

  • Start in minutes. A QR code scan is enough: no Meta business portfolio, no Embedded Signup, no template to get approved.
  • Message anyone, any time. Whapi.Cloud advertises "No templates or approvals". On the official API, a message sent outside the 24-hour window must be a template approved by Meta.
  • A flat price, no per-message fees. Whapi.Cloud charges "no per-message, per-conversation, or per-request fees"; WAHA is free, with no limit on messages. On the official API, Meta charges for templates and, since October 1, 2026, for free-form replies beyond 1,000 free service messages per number per month.
  • Groups, Channels and Status. Whapi.Cloud and WAHA expose them. Genuka WA's API does not handle groups.
  • Keep your phone. The session is added next to your existing devices; the app keeps working as before.

These are real reasons. The question is what they cost.

What are the risks of an unofficial WhatsApp API?

What do WhatsApp's Terms of Service say?

WhatsApp's Terms of Service forbid communications that involve "bulk messaging, auto-messaging, auto-dialing, and the like", as well as any "non-personal use of our Services unless otherwise authorized by us". They also forbid exploiting the service "through automated or other means" in unauthorized ways, and to "create software or APIs that function substantially the same as our Services and offer them for use by third parties in an unauthorized manner". When the terms are breached, WhatsApp may "modify, suspend, or terminate your access".

The projects say so themselves: whatsapp-web.js and WAHA write that WhatsApp does not allow bots or unofficial clients, and Baileys' maintainers state they do not condone any use that violates WhatsApp's Terms of Service.

Can my number get banned?

Yes, and none of these tools claims otherwise. Green API writes that the decision to block an account belongs to WhatsApp and does not depend on its service. It lists signs of automation, complaints from recipients and the response ratio, recommends warming up a new number for at least 10 days, and advises messaging no more than 200 customers a day. Whapi.Cloud acknowledges that any automation carries a risk of restrictions. On the Baileys repository, users still report accounts banned after bulk sends (issue opened October 7, 2026).

A ban does not only cost you the integration: it costs you the number your customers know, along with its conversations.

Why is having no templates a problem?

On the official platform, the WhatsApp Business policy requires the recipient's consent: "You may only contact people on WhatsApp if: (a) they have given you their mobile phone number […]; and (b) you have received opt-in permission […]". Outside the 24-hour window, only a template reviewed by Meta can go out, and each business portfolio has a messaging limit, shared by its numbers, that rises when its messages are high quality and at least half of the limit is used.

On an unofficial session, none of these guardrails exists: nothing stops you from messaging a cold list. And recipient complaints are among the blocking causes Green API lists.

Can a session disconnect?

Yes. Whapi.Cloud says you usually need to use WhatsApp on the phone at least once every 14 days to keep the session active, and that WhatsApp may still reset linked sessions and require re-authorization. Green API reminds you that sending goes through the phone, which must stay charged and online, unless you rent a phone hosted by them. WAHA warns that API responses and webhook payloads differ significantly from one engine to another. For order notifications or login codes, that is a failure point to plan for.

Who can read your conversations?

A linked device receives the account's conversations, not only the ones your integration cares about: Baileys even documents fetching the full history. With a hosted service, that provider holds your number's session.

When can an unofficial API make sense?

These uses stay outside the framework WhatsApp provides. The risk is the same everywhere; what varies is what it costs you. It stays bearable when losing the number costs next to nothing:

  • Automating your own account: personal reminders, archiving your messages, notifications sent to yourself.
  • A prototype or a demo, on a dedicated number you accept to lose, with recipients who know they are testing.
  • A low-volume internal tool, between people who know you and have written to you.

As soon as customers, login codes or payments depend on the number, or you message people who did not ask to hear from you, the trade-off flips.

How is the official API through Genuka WA different?

The Cloud API is the path Meta provides for businesses. Genuka is a Meta Tech Provider: you connect your own WhatsApp Business number through Meta's Embedded Signup, then send notifications, one-time codes and campaigns over HTTP, without applying to Meta as a provider yourself.

Official API, through Genuka WAUnofficial API
Allowed by WhatsAppYes, it is the platform built for businessesNo: the Terms of Service forbid unauthorized automated access
Connecting the numberMeta's Embedded Signup, on your own WhatsApp Business Account (WABA)QR code scan, like a linked device
Messaging a customer firstA Meta-approved templateAny message
Volume250 unique recipients per 24 hours for a new business portfolio, then 2,000, 10,000, 100,000 and unlimitedNo published cap; Green API advises staying under 200 customers a day
ThroughputMeta's ceiling of 80 messages per second per number by default, 20 in coexistenceWhatever the session allows
Groups, Channels, StatusNot supported by Genuka WAYes, depending on the tool
Delivery statusesWebhooks signed with HMAC-SHA256, retried, replayableThe tool's webhooks
CostMeta's per-message fees, billed to your WABA, plus a Genuka subscription per numberA flat subscription, or free when self-hosted
Main riskA rejected template; a lower quality rating if recipients complainA banned number, a dropped session

What you give up, honestly:

  • You cannot message first without a Meta-approved template.
  • Volume starts low: 250 unique recipients per 24 hours. It rises to 2,000 after Meta verifies the business, or after 2,000 messages delivered outside the window within 30 days using high-quality templates, then scales up automatically. See what works without Meta verification.
  • Templates have a Meta cost, by category and recipient country. Since October 1, 2026, Meta also charges for the free-form replies sent inside the 24-hour window, beyond 1,000 free service messages per number per month.
  • Genuka WA does not send to groups, Channels or Status.

What you get:

  • You are inside the framework WhatsApp provides. The remaining risk is quality: messages people do not want lower the number's rating, and Meta can restrict it.
  • No phone, browser or QR code to keep alive.
  • Replies and statuses (sent, delivered, read, failed) arrive on signed webhooks, retried 5 times and replayable from the log.
  • Marketing opt-outs are enforced: Genuka WA refuses a marketing template it knows about when it is aimed at an opted-out contact (403 recipient_opted_out), and a marketing campaign skips those contacts (status skipped).
  • Meta bills your messages directly, with no Genuka markup. The subscription starts at 5,000 FCFA or $19 a month per number, with a 7-day trial and no card. See the pricing page.

How do I move from an unofficial API to the official API?

Find out which app runs the number

  • The number runs on the WhatsApp Business app: keep it. This is Meta's coexistence: the app keeps working one-to-one and the chat history syncs. You need app version 2.24.17 or later, and the history sync must happen within 24 hours. When you connect, Meta unlinks every companion device from the account, the unofficial session included: do not link it again afterwards.
  • The number is registered on regular WhatsApp: it must be freed first, by deleting the WhatsApp account on that number, or you use another number.

In coexistence, Meta states that group chats are not synchronized and that the app's broadcast lists are disabled. The details are in the Coexistence guide.

Connect the number to Genuka WA

Create an account: onboarding offers to connect a number. After that it is Numbers > Add a number > Connect WhatsApp, which opens Meta's Embedded Signup. The number, its WABA and its templates show up in your workspace. Add a payment method to the WhatsApp Business account: Meta is the one billing the messages. See Connecting a number.

Submit your templates

Every message you send first (order confirmation, reminder, promotion) becomes a template that Meta must approve: submit them early. One-time codes use the AUTHENTICATION category, which is reserved for businesses that passed Meta business verification (or another of Meta's scaling paths): see send a WhatsApp OTP from Node.js.

Only message people who agreed to hear from you on WhatsApp, and stop as soon as they opt out: the opt-out reaches you by webhook.

Replace the send call and wire up webhooks

Create an API key, replace your send call (see below), then register your webhook URL and verify the signature before processing anything: see receive replies and statuses via webhook.

What changes in the send code?

Before, with a WAHA session, a free-form message goes to any number:

curl -X POST https://waha.example.com/api/sendText \
  -H "X-Api-Key: $WAHA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "session": "default",
    "chatId": "[email protected]",
    "text": "Hi Awa, your order #1042 has shipped."
  }'

With Genuka WA, the same message becomes an approved template, and you only pass its variables:

curl -X POST https://wa.genuka.com/api/v1/messages \
  -H "Authorization: Bearer $GENUKA_WA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "connectionId": "cnx_...",
    "to": "+237699001122",
    "template": {
      "name": "order_shipped",
      "language": "en_US",
      "variables": ["Awa", "#1042"]
    }
  }'

# { "data": { "messageId": "wamid.HBg..." } }

To answer a customer who wrote to you within the last 24 hours, swap template for text: a free-form message is enough. Outside that window the API still answers 200, with a warning field (outside_service_window, or unverified_service_window when no inbound message from that contact is on record). Meta does not deliver the message, and usually reports it later as a failed status with error 131047 on your webhooks. Every message type is described in Sending messages.

FAQ

It breaches WhatsApp's Terms of Service, which WhatsApp enforces by suspending or terminating access to the service. Beyond that, rules such as data protection or direct marketing law in your country apply whatever tool you use.

Will my number definitely get banned?

No, but nobody can promise you otherwise, and we found no published ban rate. The tools themselves name the factors that raise the risk: a new number, bulk sends, recipients who do not reply or who complain.

Can I keep my number when I move to the official API?

Yes if the number runs on the WhatsApp Business app: Meta's coexistence connects it to the Cloud API without touching the app. A number registered on regular WhatsApp must be freed first. Either way, the unofficial session has to go.

Can the official API post in WhatsApp groups?

Yes, to a point: Meta offers a Groups API on the Cloud API, open to Official Business Accounts, with at most 8 participants per group, who join through an invite link. It is not available on a number that also runs the WhatsApp Business app. Genuka WA does not expose it: it sends one-to-one messages, templates and campaigns. In coexistence, the app's group chats are not synchronized.

How much does the official API cost with Genuka WA?

Two layers: Meta bills your paid messages to your WhatsApp Business Account, by category and recipient country, and Genuka charges a subscription per number, from 5,000 FCFA or $19 a month, with no markup on messages. See Plans & billing.

Sources

Read on October 8, 2026.

On this page