# WhatsApp error 0: unable to authenticate — fix

URL: https://wa.genuka.com/en/docs/errors/0
Language: English

> WhatsApp error 0 "We were unable to authenticate the app user": expired or invalidated token, or access cut off. How to fix it, and the Genuka WA case.

WhatsApp error 0 means Meta could not authenticate the user behind the access token. In practice,
the token has expired, been invalidated, or its owner has stopped apps from accessing their data.
You fix it the same way as error 190: with a new token, ideally a system user token that does not
depend on any one person.

## What does error 0 mean?

It is the first row of the Cloud API's authorization errors:

> "We were unable to authenticate the app user."
> — [Meta, Cloud API error codes](https://developers.facebook.com/documentation/business-messaging/whatsapp/support/error-codes#authorization-errors)

Meta explains: "Typically this means the included access token has expired, been invalidated, or
the app user has changed a setting to prevent all apps from accessing their data." The suggested
fix is to get a new access token, pointing to system user tokens. The general Graph documentation
describes the same symptom for `OAuthException` errors without a subcode: the login status or token
has expired, been revoked or is otherwise invalid
([Meta, Graph API error handling](https://developers.facebook.com/docs/graph-api/guides/error-handling)).

### Error 0 or error 190?

|                  | Error 0                                        | Error 190                         |
| ---------------- | ---------------------------------------------- | --------------------------------- |
| Meta's wording   | "We were unable to authenticate the app user." | "Your access token has expired."  |
| What is at fault | The user behind the token, or the token itself | The token, expired or invalidated |
| Meta's remedy    | A new access token                             | A new access token                |

Either way, the same request with the same token will always fail.

## When does error 0 happen?

* **The token expired or was invalidated**, for instance a user token generated from the App
  Dashboard's API Setup page, which Meta expires within a few hours
  ([Meta, Access tokens](https://developers.facebook.com/documentation/business-messaging/whatsapp/access-tokens#user-access-tokens)).
* **The token depends on a person who changed their settings.** A user token is tied to the
  Facebook account of whoever generated it: if they cut off app access to their data, the token
  stops working.
* **The token was revoked** on Meta's side.

### Where do you see it in Genuka WA?

Genuka WA puts error 0 in the `config` class and treats it as a dead credential: in a `MARKETING`
campaign it does not trigger the fallback from the Marketing Messages API to `/messages`, which
would only double the failure and hide the real cause.

```json title="409 — POST /api/v1/messages"
{
  "error": "send_config",
  "message": "We were unable to authenticate the app user.",
  "meta": {
    "errorClass": "config",
    "retryable": false,
    "code": 0,
    "traceId": "AbC…"
  }
}
```

On `POST /api/v1/templates`, the same error comes back as `403 meta_rejected`.

## How do I fix error 0?

### If you go through Genuka WA

You have no Meta token to renew: every call on your number goes out with Genuka's system user
token, which depends on no person and has no expiry date. An error 0 is therefore Genuka's to fix.

1. **Stop retrying.** `retryable: false`: nothing changes until the token does.
2. **Contact Genuka support** with the `x-request-id` header and `meta.traceId`.
3. **Check the number** with `GET /api/v1/connections`. `disconnected` means Meta reported the
   account as no longer shared with Genuka, or deleted, or that you released the number yourself.
   A customer who removed access restores it through the [connect link](https://wa.genuka.com/en/docs/onboarding); a
   released number needs a free slot again; a deleted account, or one disabled by Meta
   ([error 368](https://wa.genuka.com/en/docs/errors/368)), is not restored that way. The `account_update` event
   forwarded to your webhooks tells you which case applies.

### If you call the Cloud API with your own token

1. **Run the token through the debugger.** The
   [access token debugger](https://developers.facebook.com/tools/debug/accesstoken/) shows whether it
   is still valid, who owns it and which permissions it carries.
2. **Replace it with a system user token.** Meta describes them as long-lived and able to represent an
   automated service with no user input, unlike user tokens
   ([Meta, Access tokens](https://developers.facebook.com/documentation/business-messaging/whatsapp/access-tokens#system-user-access-tokens)).
   Generate it with `business_management`, `whatsapp_business_management` and
   `whatsapp_business_messaging`.
3. **Assign it the accounts.** Without access to the WhatsApp account and the Messaging account, the
   new token gets an [error 200](https://wa.genuka.com/en/docs/errors/200) instead of 0.

## How do I prevent error 0?

* **No personal tokens in production.** An employee leaving, a changed password or a privacy
  setting must not be able to stop your sends.
* **Watch the `config` class.** In Genuka WA, a sudden rise of `meta.errorClass: "config"`
  responses across several numbers at once points to a credential problem, not a content problem.
* **Keep the `traceId`.** It is what Meta support asks for, and the Graph documentation says the ID
  expires shortly.

## Related error codes

* [190](https://wa.genuka.com/en/docs/errors/190): the token has expired.
* [200](https://wa.genuka.com/en/docs/errors/200): the token is valid but lacks access to the account or permission.
* [10](https://wa.genuka.com/en/docs/errors/10): permission not granted or removed.
* [3](https://wa.genuka.com/en/docs/errors/3): capability or permission missing for this endpoint.

## FAQ

### Should I retry a call refused with error 0?

No. The token is at fault: the same request will fail identically until it is replaced.

### Is my Genuka API key compromised?

No. Error 0 is about the Meta token, not your `pk_live_…` key. A refused key produces a Genuka
`401 invalid_token`.

### Why did my token work yesterday?

Because a user token expires within hours, or stops working as soon as its owner changes their
settings. A system user token does not have that weakness.

## Sources

* [Meta — Error codes](https://developers.facebook.com/documentation/business-messaging/whatsapp/support/error-codes)
* [Meta — Access tokens](https://developers.facebook.com/documentation/business-messaging/whatsapp/access-tokens)
* [Meta — Graph API, Handling errors](https://developers.facebook.com/docs/graph-api/guides/error-handling)
