# WhatsApp error 10: permission denied — cause and fix

URL: https://wa.genuka.com/en/docs/errors/10
Language: English

> WhatsApp error 10 "Application does not have permission for this action": a missing permission, or an OTP template on an unverified business.

WhatsApp error 10 means a permission the call needs was never granted or has been removed. On the
Cloud API, the most common case misleads everyone: creating an `AUTHENTICATION` (OTP) template for
a business Meta has not verified returns "Application does not have permission for this action".
The problem is the business, not the application.

## What does error 10 mean?

Meta lists it among the authorization errors:

> "Permission is either not granted or has been removed."
> — [Meta, Cloud API error codes](https://developers.facebook.com/documentation/business-messaging/whatsapp/support/error-codes#authorization-errors)

Meta's suggested fix covers three leads: check in the access token debugger that the app was
granted the permissions the endpoint requires; for WhatsApp Flows with an endpoint, check that the
phone number used to set the business public key is allowlisted; and check the eligibility
requirements of the API you are calling, because an account that is not eligible gets exactly this
code. The general Graph documentation calls code 10 "API Permission Denied"
([Meta, Graph API error handling](https://developers.facebook.com/docs/graph-api/guides/error-handling)).

## When does error 10 happen?

| Situation                                                                     | What you see                                           | Who can fix it                                                                  |
| ----------------------------------------------------------------------------- | ------------------------------------------------------ | ------------------------------------------------------------------------------- |
| Creating an `AUTHENTICATION` template for an unverified business              | "Application does not have permission for this action" | The business: Meta business verification, then a messaging limit moved to 2,000 |
| Token without `whatsapp_business_management` or `whatsapp_business_messaging` | The same message, on any endpoint                      | Whoever owns the token                                                          |
| Feature reserved to eligible accounts                                         | Code 10 on that feature's endpoint                     | Depends on Meta's requirements for that API                                     |
| WhatsApp Flows with an endpoint, number not allowlisted                       | Code 10 when setting the public key                    | The app owner                                                                   |

### The OTP template case

This is the one that costs hours. On the accounts connected to Genuka WA, we see that:

* creating an `AUTHENTICATION` template fails with "Application does not have permission for this
  action" when the business has not passed Meta business verification;
* `MARKETING` and `UTILITY` templates on the same account are created normally;
* the account's health status carries error [141010](https://wa.genuka.com/en/docs/errors/141010), "The Business has not
  passed business verification".

A developer reported the same response on Meta's forum, with `error_subcode: 2388185` and the user
message "This WhatsApp Business account does not have permission to create message template"
([Meta developer forum](https://developers.facebook.com/community/threads/1372007877817645/)). The
message blames the application. No token or permission setting changes anything.

You cannot work around it with a utility template either: when an app offers users one-time
passwords or verification codes over WhatsApp, Meta requires an authentication template
([Meta, Authentication templates](https://developers.facebook.com/documentation/business-messaging/whatsapp/templates/authentication-templates/authentication-templates)).

### Where do you see it in Genuka WA?

Genuka WA puts code 10 in the `config` class: token, permission or registration, nothing a retry
can fix.

| Channel                  | What you get                                                                                                                                                                 |
| ------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `POST /api/v1/templates` | `403`, `"error": "meta_rejected"`, `meta.code: 10`                                                                                                                           |
| `POST /api/v1/messages`  | `409`, `"error": "send_config"`, `meta.code: 10`                                                                                                                             |
| `MARKETING` campaign     | If the Marketing Messages API refuses with this code, Genuka resends the message through the regular `/messages` endpoint; if that refuses too, the recipient turns `failed` |

```json title="403 — POST /api/v1/templates (AUTHENTICATION category)"
{
  "error": "meta_rejected",
  "message": "Application does not have permission for this action",
  "meta": {
    "errorClass": "config",
    "retryable": false,
    "code": 10,
    "traceId": "AbC…"
  }
}
```

## How do I fix error 10?

### On an authentication template

1. **Confirm the cause.** In Meta Business Suite, **Security Center > Business Verification** shows
   the verification status of the portfolio that owns the WhatsApp account. If you call Graph
   yourself, `GET /{WABA_ID}?fields=business_verification_status,health_status` answers in one
   request: `business_verification_status` is described in the
   [WhatsApp Business Account reference](https://developers.facebook.com/documentation/business-messaging/whatsapp/reference/whatsapp-business-account/whatsapp-business-account-api),
   `health_status` in [Health status](https://developers.facebook.com/documentation/business-messaging/whatsapp/support/health-status).
2. **Get the business verified.** It starts from Meta Business Suite, on the portfolio that owns the
   WhatsApp account ([Meta, Verify your business](https://www.facebook.com/business/help/2058515294227817)).
   Details are on the [error 141010](https://wa.genuka.com/en/docs/errors/141010) page.
3. **Recreate the template once the business is verified and the limit has moved to 2,000**
   (WhatsApp Manager, **Account tools > Messaging limits**). The same `POST /api/v1/templates`, with
   `"category": "AUTHENTICATION"` — see the [OTP codes from Node.js](https://wa.genuka.com/en/docs/guides/whatsapp-otp-nodejs)
   guide.

### On a missing permission

* **If you own the token**: open it in the
  [access token debugger](https://developers.facebook.com/tools/debug/accesstoken/), check
  `whatsapp_business_management` and `whatsapp_business_messaging`, and regenerate it with both if
  one is missing
  ([Meta, WhatsApp support](https://developers.facebook.com/documentation/business-messaging/whatsapp/support#authentication-authorization)).
* **If you go through Genuka WA**: you have no Meta token to fix. A code 10 outside an
  authentication template is Genuka's to handle: contact support with the `x-request-id` header
  and `meta.traceId`.

## How do I prevent error 10?

* **Get the business verified before planning WhatsApp OTPs.** It is a Meta prerequisite, not a
  Genuka option.
* **Test the authentication flow on a verified account** before you announce the feature: an
  unverified test account will always fail.
* **Keep both WhatsApp permissions** on any token you generate yourself.

## Related error codes

* [141010](https://wa.genuka.com/en/docs/errors/141010): the business has not passed Meta business verification.
* [200](https://wa.genuka.com/en/docs/errors/200): the token has no access to the account, or a permission is missing (200 to 299).
* [3](https://wa.genuka.com/en/docs/errors/3): capability or permission missing for this endpoint.
* [190](https://wa.genuka.com/en/docs/errors/190): the token has expired.

## FAQ

### Why does Meta blame the application when my token is fine?

Because the message is generic. On an `AUTHENTICATION` template we see it when the business is not
verified, while the token and its permissions are correct: marketing and utility templates on the
same account go through.

### Can I send OTP codes with a utility template in the meantime?

No. Meta requires an authentication template for one-time codes. Until verification is done, send
your codes through another channel, SMS or email.

### Should I regenerate my Genuka API key?

No. Your Genuka key plays no part in Meta permissions. A key problem produces a Genuka `401`, never
a code 10.

### Does code 10 also block my sends?

Not in the OTP template case: only creating `AUTHENTICATION` templates is refused. Your approved
marketing and utility templates keep going out.

## Sources

* [Meta — Error codes](https://developers.facebook.com/documentation/business-messaging/whatsapp/support/error-codes)
* [Meta — Graph API, Handling errors](https://developers.facebook.com/docs/graph-api/guides/error-handling)
* [Meta — Authentication templates](https://developers.facebook.com/documentation/business-messaging/whatsapp/templates/authentication-templates/authentication-templates)
* [Meta — Health status](https://developers.facebook.com/documentation/business-messaging/whatsapp/support/health-status)
* [Meta — WhatsApp Business Account API](https://developers.facebook.com/documentation/business-messaging/whatsapp/reference/whatsapp-business-account/whatsapp-business-account-api)
* [Meta — Messaging limits](https://developers.facebook.com/documentation/business-messaging/whatsapp/messaging-limits)
* [Meta — WhatsApp support, authentication and authorization errors](https://developers.facebook.com/documentation/business-messaging/whatsapp/support#authentication-authorization)
* [Meta — Verify your business in Meta Business Suite](https://www.facebook.com/business/help/2058515294227817)
* [Meta developer forum — error 10 on an authentication template](https://developers.facebook.com/community/threads/1372007877817645/)
