WhatsApp error 10: permission denied — cause and fix
WhatsApp error 10 "Application does not have permission for this action": a missing permission, or an OTP template on an unverified business.
WhatsApp error 10 means a permission the call needs was never granted or has been removed. On the
Cloud API, the most common case misleads everyone: creating an AUTHENTICATION (OTP) template for
a business Meta has not verified returns "Application does not have permission for this action".
The problem is the business, not the application.
What does error 10 mean?
Meta lists it among the authorization errors:
"Permission is either not granted or has been removed." — Meta, Cloud API error codes
Meta's suggested fix covers three leads: check in the access token debugger that the app was granted the permissions the endpoint requires; for WhatsApp Flows with an endpoint, check that the phone number used to set the business public key is allowlisted; and check the eligibility requirements of the API you are calling, because an account that is not eligible gets exactly this code. The general Graph documentation calls code 10 "API Permission Denied" (Meta, Graph API error handling).
When does error 10 happen?
| Situation | What you see | Who can fix it |
|---|---|---|
Creating an AUTHENTICATION template for an unverified business | "Application does not have permission for this action" | The business: Meta business verification, then a messaging limit moved to 2,000 |
Token without whatsapp_business_management or whatsapp_business_messaging | The same message, on any endpoint | Whoever owns the token |
| Feature reserved to eligible accounts | Code 10 on that feature's endpoint | Depends on Meta's requirements for that API |
| WhatsApp Flows with an endpoint, number not allowlisted | Code 10 when setting the public key | The app owner |
The OTP template case
This is the one that costs hours. On the accounts connected to Genuka WA, we see that:
- creating an
AUTHENTICATIONtemplate fails with "Application does not have permission for this action" when the business has not passed Meta business verification; MARKETINGandUTILITYtemplates on the same account are created normally;- the account's health status carries error 141010, "The Business has not passed business verification".
A developer reported the same response on Meta's forum, with error_subcode: 2388185 and the user
message "This WhatsApp Business account does not have permission to create message template"
(Meta developer forum). The
message blames the application. No token or permission setting changes anything.
You cannot work around it with a utility template either: when an app offers users one-time passwords or verification codes over WhatsApp, Meta requires an authentication template (Meta, Authentication templates).
Where do you see it in Genuka WA?
Genuka WA puts code 10 in the config class: token, permission or registration, nothing a retry
can fix.
| Channel | What you get |
|---|---|
POST /api/v1/templates | 403, "error": "meta_rejected", meta.code: 10 |
POST /api/v1/messages | 409, "error": "send_config", meta.code: 10 |
MARKETING campaign | If the Marketing Messages API refuses with this code, Genuka resends the message through the regular /messages endpoint; if that refuses too, the recipient turns failed |
{
"error": "meta_rejected",
"message": "Application does not have permission for this action",
"meta": {
"errorClass": "config",
"retryable": false,
"code": 10,
"traceId": "AbC…"
}
}How do I fix error 10?
On an authentication template
Confirm the cause. In Meta Business Suite, Security Center > Business Verification shows
the verification status of the portfolio that owns the WhatsApp account. If you call Graph
yourself, GET /{WABA_ID}?fields=business_verification_status,health_status answers in one
request: business_verification_status is described in the
WhatsApp Business Account reference,
health_status in Health status.
Get the business verified. It starts from Meta Business Suite, on the portfolio that owns the WhatsApp account (Meta, Verify your business). Details are on the error 141010 page.
Recreate the template once the business is verified and the limit has moved to 2,000
(WhatsApp Manager, Account tools > Messaging limits). The same POST /api/v1/templates, with
"category": "AUTHENTICATION" — see the OTP codes from Node.js
guide.
On a missing permission
- If you own the token: open it in the
access token debugger, check
whatsapp_business_managementandwhatsapp_business_messaging, and regenerate it with both if one is missing (Meta, WhatsApp support). - If you go through Genuka WA: you have no Meta token to fix. A code 10 outside an
authentication template is Genuka's to handle: contact support with the
x-request-idheader andmeta.traceId.
How do I prevent error 10?
- Get the business verified before planning WhatsApp OTPs. It is a Meta prerequisite, not a Genuka option.
- Test the authentication flow on a verified account before you announce the feature: an unverified test account will always fail.
- Keep both WhatsApp permissions on any token you generate yourself.
Related error codes
- 141010: the business has not passed Meta business verification.
- 200: the token has no access to the account, or a permission is missing (200 to 299).
- 3: capability or permission missing for this endpoint.
- 190: the token has expired.
FAQ
Why does Meta blame the application when my token is fine?
Because the message is generic. On an AUTHENTICATION template we see it when the business is not
verified, while the token and its permissions are correct: marketing and utility templates on the
same account go through.
Can I send OTP codes with a utility template in the meantime?
No. Meta requires an authentication template for one-time codes. Until verification is done, send your codes through another channel, SMS or email.
Should I regenerate my Genuka API key?
No. Your Genuka key plays no part in Meta permissions. A key problem produces a Genuka 401, never
a code 10.
Does code 10 also block my sends?
Not in the OTP template case: only creating AUTHENTICATION templates is refused. Your approved
marketing and utility templates keep going out.
Sources
- Meta — Error codes
- Meta — Graph API, Handling errors
- Meta — Authentication templates
- Meta — Health status
- Meta — WhatsApp Business Account API
- Meta — Messaging limits
- Meta — WhatsApp support, authentication and authorization errors
- Meta — Verify your business in Meta Business Suite
- Meta developer forum — error 10 on an authentication template
WhatsApp error 3: capability or permission missing
WhatsApp Cloud API error 3 (Capability or permissions issue): how it differs from errors 0, 10, 190 and 200, and how to fix it.
WhatsApp error 190: access token expired — cause and fix
WhatsApp Cloud API error 190 (access token expired): which token expired, how to replace it for good, and why Genuka WA users never handle Meta tokens.