# Official WhatsApp API vs unofficial APIs (WAHA, Baileys…)

URL: https://wa.genuka.com/en/docs/compare/unofficial-whatsapp-apis
Language: English

> Whapi.Cloud, WAHA, Green API, Baileys: how unofficial WhatsApp APIs work, their ban and reliability risks, and what changes with the official API.

An unofficial WhatsApp API (Whapi.Cloud, WAHA, Green API, Evolution API in Baileys mode, Baileys,
whatsapp-web.js) drives a WhatsApp account the way WhatsApp Web does, after you scan a QR code. It
is quick and needs no approval from Meta, but it breaks WhatsApp's Terms of Service and the number
can be banned. The official API goes through Meta's Cloud API.

*Last updated October 8, 2026*

> [!NOTE]
> **How this page was written**
>
> Genuka sells access to the official API, so we have a stake in this comparison. To keep it fair,
> every claim about a tool comes from that tool's own documentation, and every WhatsApp rule from
> WhatsApp's own texts, read on the date above and listed under [Sources](#sources). We found no
> published ban rate, from WhatsApp or from these projects, so we quote none.

## How does an unofficial WhatsApp API work?

WhatsApp lets you link secondary devices to an account: that is how WhatsApp Web works. An
unofficial API poses as one of those devices. You scan a QR code from **Linked devices** on your
phone, or enter a pairing code, and the tool sends and receives the account's messages the way a
browser would.

There are two techniques:

* **Drive the real WhatsApp Web in a browser.** whatsapp-web.js and WAHA's WEBJS and WPP engines
  launch Chromium with Puppeteer and call WhatsApp Web's internal functions.
* **Speak the WhatsApp Web protocol directly.** Baileys, and WAHA's NOWEB and GOWS engines, open a
  WebSocket connection with no browser.

On top of that, some projects add an HTTP API and webhooks: WAHA and Evolution API run on your own
server, while Green API and Whapi.Cloud are hosted services that keep the session for you.

| Tool            | Type                                                                                                                      | How it connects to WhatsApp                                                              | Listed price                                                                                      | What the project says                                                  |
| --------------- | ------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------- |
| Baileys         | TypeScript library, MIT license                                                                                           | WebSocket, QR code or pairing code                                                       | Free                                                                                              | "not affiliated \[…] with WhatsApp"; "Do not spam people with this"    |
| whatsapp-web.js | Node.js library, Apache 2.0 license                                                                                       | WhatsApp Web driven by Puppeteer                                                         | Free                                                                                              | "it is not guaranteed you will not be blocked by using this method"    |
| WAHA            | Self-hosted HTTP server (Docker), Apache 2.0 license                                                                      | Browser (WEBJS, WPP) or WebSocket (NOWEB, GOWS), QR code                                 | Free; optional $5 a month support tier                                                            | "WhatsApp does not allow bots or unofficial clients on their platform" |
| Evolution API   | Self-hosted REST server, Apache 2.0 license with extra conditions (usage notice required, otherwise a commercial license) | Your choice: Baileys (WhatsApp Web) or Meta's official Cloud API                         | Free                                                                                              | Baileys mode "may have limitations compared to official APIs"          |
| Green API       | Hosted service                                                                                                            | QR code through Linked devices; the phone stays charged and online, or is hosted by them | Developer free, Business $12 a month, Chatbot $24 a month                                         | "The decision to block an account is made by WhatsApp"                 |
| Whapi.Cloud     | Hosted service                                                                                                            | Linked-device session, QR code or pairing code                                           | Limited free Sandbox; Developer Premium at $29 a month per number (shown struck through from $40) | "Any automation can carry a risk of WhatsApp restrictions"             |

Evolution API is only unofficial in Baileys mode: its Cloud API connector goes through Meta's
platform, under the same rules as Genuka WA.

## Why do developers pick an unofficial API?

* **Start in minutes.** A QR code scan is enough: no Meta business portfolio, no Embedded Signup,
  no template to get approved.
* **Message anyone, any time.** Whapi.Cloud advertises "No templates or approvals". On the official
  API, a message sent outside the 24-hour window must be a template approved by Meta.
* **A flat price, no per-message fees.** Whapi.Cloud charges "no per-message, per-conversation, or
  per-request fees"; WAHA is free, with no limit on messages. On the official API, Meta charges for
  templates and, since October 1, 2026, for free-form replies beyond 1,000 free service messages per
  number per month.
* **Groups, Channels and Status.** Whapi.Cloud and WAHA expose them. Genuka WA's API does not
  handle groups.
* **Keep your phone.** The session is added next to your existing devices; the app keeps working as
  before.

These are real reasons. The question is what they cost.

## What are the risks of an unofficial WhatsApp API?

### What do WhatsApp's Terms of Service say?

WhatsApp's Terms of Service forbid communications that involve "bulk messaging, auto-messaging,
auto-dialing, and the like", as well as any "non-personal use of our Services unless otherwise
authorized by us". They also forbid exploiting the service "through automated or other means" in
unauthorized ways, and to "create software or APIs that function substantially the same as our
Services and offer them for use by third parties in an unauthorized manner". When the terms are
breached, WhatsApp may "modify, suspend, or terminate your access".

The projects say so themselves: whatsapp-web.js and WAHA write that WhatsApp does not allow bots or
unofficial clients, and Baileys' maintainers state they do not condone any use that violates
WhatsApp's Terms of Service.

### Can my number get banned?

Yes, and none of these tools claims otherwise. Green API writes that the decision to block an
account belongs to WhatsApp and does not depend on its service. It lists signs of automation,
complaints from recipients and the response ratio, recommends warming up a new number for at least
10 days, and advises messaging no more than 200 customers a day. Whapi.Cloud acknowledges that any
automation carries a risk of restrictions. On the Baileys repository, users still report accounts
banned after bulk sends (issue opened October 7, 2026).

A ban does not only cost you the integration: it costs you the number your customers know, along
with its conversations.

### Why is having no templates a problem?

On the official platform, the WhatsApp Business policy requires the recipient's consent: "You may
only contact people on WhatsApp if: (a) they have given you their mobile phone number \[…]; and (b)
you have received opt-in permission \[…]". Outside the 24-hour window, only a template reviewed by
Meta can go out, and each business portfolio has a messaging limit, shared by its numbers, that rises
when its messages are high quality and at least half of the limit is used.

On an unofficial session, none of these guardrails exists: nothing stops you from messaging a cold
list. And recipient complaints are among the blocking causes Green API lists.

### Can a session disconnect?

Yes. Whapi.Cloud says you usually need to use WhatsApp on the phone at least once every 14 days to
keep the session active, and that WhatsApp may still reset linked sessions and require
re-authorization. Green API reminds you that sending goes through the phone, which must stay
charged and online, unless you rent a phone hosted by them. WAHA warns that API responses and
webhook payloads differ significantly from one engine to another. For order notifications or login
codes, that is a failure point to plan for.

### Who can read your conversations?

A linked device receives the account's conversations, not only the ones your integration cares
about: Baileys even documents fetching the full history. With a hosted service, that provider holds
your number's session.

## When can an unofficial API make sense?

These uses stay outside the framework WhatsApp provides. The risk is the same everywhere; what
varies is what it costs you. It stays bearable when losing the number costs next to nothing:

* **Automating your own account**: personal reminders, archiving your messages, notifications sent
  to yourself.
* **A prototype or a demo**, on a dedicated number you accept to lose, with recipients who know
  they are testing.
* **A low-volume internal tool**, between people who know you and have written to you.

As soon as customers, login codes or payments depend on the number, or you message people who did
not ask to hear from you, the trade-off flips.

## How is the official API through Genuka WA different?

The Cloud API is the path Meta provides for businesses. Genuka is a Meta Tech Provider: you connect
your own WhatsApp Business number through Meta's Embedded Signup, then send notifications, one-time
codes and campaigns over HTTP, without applying to Meta as a provider yourself.

|                            | Official API, through Genuka WA                                                                            | Unofficial API                                                        |
| -------------------------- | ---------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------- |
| Allowed by WhatsApp        | Yes, it is the platform built for businesses                                                               | No: the Terms of Service forbid unauthorized automated access         |
| Connecting the number      | Meta's Embedded Signup, on your own WhatsApp Business Account (WABA)                                       | QR code scan, like a linked device                                    |
| Messaging a customer first | A Meta-approved template                                                                                   | Any message                                                           |
| Volume                     | 250 unique recipients per 24 hours for a new business portfolio, then 2,000, 10,000, 100,000 and unlimited | No published cap; Green API advises staying under 200 customers a day |
| Throughput                 | Meta's ceiling of 80 messages per second per number by default, 20 in coexistence                          | Whatever the session allows                                           |
| Groups, Channels, Status   | Not supported by Genuka WA                                                                                 | Yes, depending on the tool                                            |
| Delivery statuses          | Webhooks signed with HMAC-SHA256, retried, replayable                                                      | The tool's webhooks                                                   |
| Cost                       | Meta's per-message fees, billed to your WABA, plus a Genuka subscription per number                        | A flat subscription, or free when self-hosted                         |
| Main risk                  | A rejected template; a lower quality rating if recipients complain                                         | A banned number, a dropped session                                    |

What you give up, honestly:

* You cannot message first without a Meta-approved template.
* Volume starts low: 250 unique recipients per 24 hours. It rises to 2,000 after Meta verifies the
  business, or after 2,000 messages delivered outside the window within 30 days using high-quality
  templates, then scales up automatically. See
  [what works without Meta verification](https://wa.genuka.com/en/docs/guides/without-meta-verification).
* Templates have a Meta cost, by category and recipient country. Since October 1, 2026, Meta also
  charges for the free-form replies sent inside the 24-hour window, beyond 1,000 free service
  messages per number per month.
* Genuka WA does not send to groups, Channels or Status.

What you get:

* You are inside the framework WhatsApp provides. The remaining risk is quality: messages people do
  not want lower the number's rating, and Meta can restrict it.
* No phone, browser or QR code to keep alive.
* Replies and statuses (`sent`, `delivered`, `read`, `failed`) arrive on
  [signed webhooks](https://wa.genuka.com/en/docs/webhooks), retried 5 times and replayable from the log.
* Marketing opt-outs are enforced: Genuka WA refuses a marketing template it knows about when it is
  aimed at an opted-out contact (`403 recipient_opted_out`), and a marketing campaign skips those
  contacts (status `skipped`).
* Meta bills your messages directly, with no Genuka markup. The subscription starts at 5,000 FCFA
  or $19 a month per number, with a 7-day trial and no card. See the [pricing page](https://wa.genuka.com/en#pricing).

## How do I move from an unofficial API to the official API?

1. ### Find out which app runs the number

   * **The number runs on the WhatsApp Business app**: keep it. This is Meta's **coexistence**: the
     app keeps working one-to-one and the chat history syncs. You need app version 2.24.17 or later,
     and the history sync must happen within 24 hours. When you connect, Meta unlinks every companion
     device from the account, the unofficial session included: do not link it again afterwards.
   * **The number is registered on regular WhatsApp**: it must be freed first, by deleting the
     WhatsApp account on that number, or you use another number.

   In coexistence, Meta states that group chats are not synchronized and that the app's broadcast
   lists are disabled. The details are in the [Coexistence](https://wa.genuka.com/en/docs/guides/coexistence) guide.

2. ### Connect the number to Genuka WA

   Create an account: onboarding offers to connect a number. After that it is **Numbers** > **Add a
   number** > **Connect WhatsApp**, which opens Meta's Embedded Signup. The number, its WABA and its
   templates show up in your workspace. Add a payment method to the WhatsApp Business account: Meta is
   the one billing the messages. See [Connecting a number](https://wa.genuka.com/en/docs/onboarding).

3. ### Submit your templates

   Every message you send first (order confirmation, reminder, promotion) becomes a template that Meta
   must approve: submit them early. One-time codes use the `AUTHENTICATION` category, which is reserved
   for businesses that passed Meta business verification (or another of Meta's scaling paths): see
   [send a WhatsApp OTP from Node.js](https://wa.genuka.com/en/docs/guides/whatsapp-otp-nodejs).

4. ### Collect your contacts' consent

   Only message people who agreed to hear from you on WhatsApp, and stop as soon as they opt out: the
   opt-out reaches you by webhook.

5. ### Replace the send call and wire up webhooks

   Create an API key, replace your send call (see below), then register your
   [webhook](https://wa.genuka.com/en/docs/webhooks) URL and verify the signature before processing anything: see
   [receive replies and statuses via webhook](https://wa.genuka.com/en/docs/guides/receive-messages-webhooks).

### What changes in the send code?

Before, with a WAHA session, a free-form message goes to any number:

```bash
curl -X POST https://waha.example.com/api/sendText \
  -H "X-Api-Key: $WAHA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "session": "default",
    "chatId": "237699001122@c.us",
    "text": "Hi Awa, your order #1042 has shipped."
  }'
```

With Genuka WA, the same message becomes an approved template, and you only pass its variables:

**curl**

```bash
curl -X POST https://wa.genuka.com/api/v1/messages \
  -H "Authorization: Bearer $GENUKA_WA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "connectionId": "cnx_...",
    "to": "+237699001122",
    "template": {
      "name": "order_shipped",
      "language": "en_US",
      "variables": ["Awa", "#1042"]
    }
  }'

# { "data": { "messageId": "wamid.HBg..." } }
```

**Node.js**

```js
const res = await fetch("https://wa.genuka.com/api/v1/messages", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${process.env.GENUKA_WA_API_KEY}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    connectionId: "cnx_...",
    to: "+237699001122",
    template: {
      name: "order_shipped",
      language: "en_US",
      variables: ["Awa", "#1042"],
    },
  }),
});

const body = await res.json();
if (!res.ok) {
  // For example 403 recipient_opted_out, 402 plan_limit_messages; `message` is optional
  throw new Error(`${res.status} ${body.error}${body.message ? `: ${body.message}` : ""}`);
}
console.log(body.data.messageId); // "wamid.HBg..."
```

**Python**

```python
import os
import requests

res = requests.post(
    "https://wa.genuka.com/api/v1/messages",
    headers={"Authorization": f"Bearer {os.environ['GENUKA_WA_API_KEY']}"},
    json={
        "connectionId": "cnx_...",
        "to": "+237699001122",
        "template": {
            "name": "order_shipped",
            "language": "en_US",
            "variables": ["Awa", "#1042"],
        },
    },
    timeout=10,
)
res.raise_for_status()
print(res.json()["data"]["messageId"])  # "wamid.HBg..."
```

**PHP**

```php
<?php
$ch = curl_init("https://wa.genuka.com/api/v1/messages");
curl_setopt_array($ch, [
    CURLOPT_POST => true,
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_HTTPHEADER => [
        "Authorization: Bearer " . getenv("GENUKA_WA_API_KEY"),
        "Content-Type: application/json",
        "User-Agent: my-shop/1.0",
    ],
    CURLOPT_POSTFIELDS => json_encode([
        "connectionId" => "cnx_...",
        "to" => "+237699001122",
        "template" => [
            "name" => "order_shipped",
            "language" => "en_US",
            "variables" => ["Awa", "#1042"],
        ],
    ]),
]);

$body = json_decode(curl_exec($ch), true);
$status = curl_getinfo($ch, CURLINFO_HTTP_CODE);
curl_close($ch);

if ($status !== 200) {
    $msg = $body['message'] ?? '';
    throw new RuntimeException(trim("$status {$body['error']} $msg"));
}
echo $body["data"]["messageId"]; // "wamid.HBg..."
```

To answer a customer who wrote to you within the last 24 hours, swap `template` for `text`: a
free-form message is enough. Outside that window the API still answers `200`, with a `warning` field
(`outside_service_window`, or `unverified_service_window` when no inbound message from that contact
is on record). Meta does not deliver the message, and usually reports it later as a `failed` status
with error [`131047`](https://wa.genuka.com/en/docs/errors/131047) on your webhooks. Every message type is described in
[Sending messages](https://wa.genuka.com/en/docs/messages).

## FAQ

### Is an unofficial WhatsApp API legal?

It breaches WhatsApp's Terms of Service, which WhatsApp enforces by suspending or terminating access
to the service. Beyond that, rules such as data protection or direct marketing law in your country
apply whatever tool you use.

### Will my number definitely get banned?

No, but nobody can promise you otherwise, and we found no published ban rate. The tools themselves
name the factors that raise the risk: a new number, bulk sends, recipients who do not reply or who
complain.

### Can I keep my number when I move to the official API?

Yes if the number runs on the WhatsApp Business app: Meta's coexistence connects it to the Cloud API
without touching the app. A number registered on regular WhatsApp must be freed first. Either way,
the unofficial session has to go.

### Can the official API post in WhatsApp groups?

Yes, to a point: Meta offers a Groups API on the Cloud API, open to Official Business Accounts, with
at most 8 participants per group, who join through an invite link. It is not available on a number
that also runs the WhatsApp Business app. Genuka WA does not expose it: it sends one-to-one
messages, templates and campaigns. In coexistence, the app's group chats are not synchronized.

### How much does the official API cost with Genuka WA?

Two layers: Meta bills your paid messages to your WhatsApp Business Account, by category and
recipient country, and Genuka charges a subscription per number, from 5,000 FCFA or $19 a month, with no
markup on messages. See [Plans & billing](https://wa.genuka.com/en/docs/billing).

## Sources

Read on October 8, 2026.

* [WhatsApp, Terms of Service](https://www.whatsapp.com/legal/terms-of-service)
* [WhatsApp, WhatsApp Business Messaging Policy](https://whatsappbusiness.com/policy/)
* [Baileys, GitHub repository and README](https://github.com/WhiskeySockets/Baileys)
* [Baileys, issue #2850: accounts banned after bulk sends](https://github.com/WhiskeySockets/Baileys/issues/2850)
* [whatsapp-web.js, GitHub repository and README](https://github.com/pedroslopez/whatsapp-web.js)
* [WAHA, overview](https://waha.devlike.pro/)
* [WAHA, engines](https://waha.devlike.pro/docs/how-to/engines/)
* [WAHA, sending messages](https://waha.devlike.pro/docs/how-to/send-messages/)
* [Evolution API, GitHub repository and README](https://github.com/EvolutionAPI/evolution-api)
* [Green API, overview and pricing](https://green-api.com/en/)
* [Green API, before you start](https://green-api.com/en/docs/before-start/)
* [Green API, how to protect a number from ban](https://green-api.com/en/docs/faq/how-to-protect-number-from-ban/)
* [Whapi.Cloud, overview and FAQ](https://whapi.cloud/)
* [Whapi.Cloud, pricing](https://whapi.cloud/price)
* [Meta, message templates](https://developers.facebook.com/documentation/business-messaging/whatsapp/templates/overview)
* [Meta, messaging limits](https://developers.facebook.com/documentation/business-messaging/whatsapp/messaging-limits)
* [Meta, about the WhatsApp Business Platform (Cloud API)](https://developers.facebook.com/documentation/business-messaging/whatsapp/about-the-platform)
* [Meta, Groups API](https://developers.facebook.com/documentation/business-messaging/whatsapp/groups/)
* [Meta, onboarding WhatsApp Business app users (coexistence)](https://developers.facebook.com/documentation/business-messaging/whatsapp/embedded-signup/onboarding-business-app-users)
* [Meta, WhatsApp Business Platform pricing](https://developers.facebook.com/documentation/business-messaging/whatsapp/pricing)
* [Meta, billing of service messages from October 1, 2026](https://developers.facebook.com/documentation/business-messaging/whatsapp/pricing/non-template-messages)
* [WATI, Understanding Wati's pricing structure (1,000 free service messages per number per month)](https://support.wati.io/en/articles/11462993-understanding-wati-s-pricing-structure)
* [Trengo, WhatsApp pricing changes from October 1, 2026](https://help.trengo.com/article/whatsapp-pricing-changes-from-1-october-2026)
