Genuka WA docs

WhatsApp error 10: permission denied — cause and fix

WhatsApp error 10 "Application does not have permission for this action": a missing permission, or an OTP template on an unverified business.

WhatsApp error 10 means a permission the call needs was never granted or has been removed. On the Cloud API, the most common case misleads everyone: creating an AUTHENTICATION (OTP) template for a business Meta has not verified returns "Application does not have permission for this action". The problem is the business, not the application.

What does error 10 mean?

Meta lists it among the authorization errors:

"Permission is either not granted or has been removed." — Meta, Cloud API error codes

Meta's suggested fix covers three leads: check in the access token debugger that the app was granted the permissions the endpoint requires; for WhatsApp Flows with an endpoint, check that the phone number used to set the business public key is allowlisted; and check the eligibility requirements of the API you are calling, because an account that is not eligible gets exactly this code. The general Graph documentation calls code 10 "API Permission Denied" (Meta, Graph API error handling).

When does error 10 happen?

SituationWhat you seeWho can fix it
Creating an AUTHENTICATION template for an unverified business"Application does not have permission for this action"The business: Meta business verification, then a messaging limit moved to 2,000
Token without whatsapp_business_management or whatsapp_business_messagingThe same message, on any endpointWhoever owns the token
Feature reserved to eligible accountsCode 10 on that feature's endpointDepends on Meta's requirements for that API
WhatsApp Flows with an endpoint, number not allowlistedCode 10 when setting the public keyThe app owner

The OTP template case

This is the one that costs hours. On the accounts connected to Genuka WA, we see that:

  • creating an AUTHENTICATION template fails with "Application does not have permission for this action" when the business has not passed Meta business verification;
  • MARKETING and UTILITY templates on the same account are created normally;
  • the account's health status carries error 141010, "The Business has not passed business verification".

A developer reported the same response on Meta's forum, with error_subcode: 2388185 and the user message "This WhatsApp Business account does not have permission to create message template" (Meta developer forum). The message blames the application. No token or permission setting changes anything.

You cannot work around it with a utility template either: when an app offers users one-time passwords or verification codes over WhatsApp, Meta requires an authentication template (Meta, Authentication templates).

Where do you see it in Genuka WA?

Genuka WA puts code 10 in the config class: token, permission or registration, nothing a retry can fix.

ChannelWhat you get
POST /api/v1/templates403, "error": "meta_rejected", meta.code: 10
POST /api/v1/messages409, "error": "send_config", meta.code: 10
MARKETING campaignIf the Marketing Messages API refuses with this code, Genuka resends the message through the regular /messages endpoint; if that refuses too, the recipient turns failed
403 — POST /api/v1/templates (AUTHENTICATION category)
{
  "error": "meta_rejected",
  "message": "Application does not have permission for this action",
  "meta": {
    "errorClass": "config",
    "retryable": false,
    "code": 10,
    "traceId": "AbC…"
  }
}

How do I fix error 10?

On an authentication template

Confirm the cause. In Meta Business Suite, Security Center > Business Verification shows the verification status of the portfolio that owns the WhatsApp account. If you call Graph yourself, GET /{WABA_ID}?fields=business_verification_status,health_status answers in one request: business_verification_status is described in the WhatsApp Business Account reference, health_status in Health status.

Get the business verified. It starts from Meta Business Suite, on the portfolio that owns the WhatsApp account (Meta, Verify your business). Details are on the error 141010 page.

Recreate the template once the business is verified and the limit has moved to 2,000 (WhatsApp Manager, Account tools > Messaging limits). The same POST /api/v1/templates, with "category": "AUTHENTICATION" — see the OTP codes from Node.js guide.

On a missing permission

  • If you own the token: open it in the access token debugger, check whatsapp_business_management and whatsapp_business_messaging, and regenerate it with both if one is missing (Meta, WhatsApp support).
  • If you go through Genuka WA: you have no Meta token to fix. A code 10 outside an authentication template is Genuka's to handle: contact support with the x-request-id header and meta.traceId.

How do I prevent error 10?

  • Get the business verified before planning WhatsApp OTPs. It is a Meta prerequisite, not a Genuka option.
  • Test the authentication flow on a verified account before you announce the feature: an unverified test account will always fail.
  • Keep both WhatsApp permissions on any token you generate yourself.
  • 141010: the business has not passed Meta business verification.
  • 200: the token has no access to the account, or a permission is missing (200 to 299).
  • 3: capability or permission missing for this endpoint.
  • 190: the token has expired.

FAQ

Why does Meta blame the application when my token is fine?

Because the message is generic. On an AUTHENTICATION template we see it when the business is not verified, while the token and its permissions are correct: marketing and utility templates on the same account go through.

Can I send OTP codes with a utility template in the meantime?

No. Meta requires an authentication template for one-time codes. Until verification is done, send your codes through another channel, SMS or email.

Should I regenerate my Genuka API key?

No. Your Genuka key plays no part in Meta permissions. A key problem produces a Genuka 401, never a code 10.

Does code 10 also block my sends?

Not in the OTP template case: only creating AUTHENTICATION templates is refused. Your approved marketing and utility templates keep going out.

Sources

On this page