# WhatsApp error 141010: business not verified — fix

URL: https://wa.genuka.com/en/docs/errors/141010
Language: English

> WhatsApp error 141010 "The Business has not passed business verification": why your OTP templates are refused, and how to unblock them.

WhatsApp error 141010 means the business that owns the WhatsApp account has not passed Meta
business verification. It shows up in the account's health status, not in a send response. The
practical consequence: authentication templates (OTP codes) are refused, while marketing and
utility templates keep working as usual on the same account.

## What does error 141010 mean?

You will not find it in Meta's public list of Cloud API error codes. It comes from the
`health_status` field Meta exposes on the WhatsApp account, the phone number and templates. For
each entity involved (number, account, business portfolio, app), Meta can attach an `errors` list
where each item carries an `error_code`, an `error_description` and a `possible_solution`
([Meta, Health status](https://developers.facebook.com/documentation/business-messaging/whatsapp/support/health-status)).

On the accounts connected to Genuka WA whose business is not verified, this is what we read:

```json title="Excerpt of health_status"
{
  "error_code": 141010,
  "error_description": "The Business has not passed business verification"
}
```

Business verification applies to the Meta business portfolio that owns the WhatsApp account. It
has nothing to do with Genuka's provider status: Genuka is a Meta Tech Provider, and it is your
business that needs to be verified.

## When does error 141010 happen?

As soon as a number is connected under an unverified portfolio. Meta's Embedded Signup lets you
connect a number without verification, and many businesses start that way. The code stays silent
until the day you create an authentication template:

| What you do                                                      | Unverified business                                                                             | Verified business                                                       |
| ---------------------------------------------------------------- | ----------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------- |
| Create a `MARKETING` or `UTILITY` template                       | Accepted                                                                                        | Accepted                                                                |
| Create an `AUTHENTICATION` (OTP) template                        | Refused: error [10](https://wa.genuka.com/en/docs/errors/10), "Application does not have permission for this action" | Accepted once the limit has moved to 2,000                              |
| Reach unique recipients outside the service window, per 24 hours | 250 to start                                                                                    | 2,000 once Meta approves your message quality, then automatic increases |

The limits are Meta's: a new portfolio starts at 250, and verification is one of the paths to
2,000 ([Meta, Messaging limits](https://developers.facebook.com/documentation/business-messaging/whatsapp/messaging-limits)).

Why OTP codes? Meta reserves the `AUTHENTICATION` category for businesses that completed one of its
scaling paths, such as business verification, with a messaging limit of at least 2,000
business-initiated conversations a day; both conditions must be met
([360dialog, Authentication messages](https://docs.360dialog.com/docs/resources/authentication-messages)).
Verification alone is therefore not enough: after a scaling path, Meta analyzes your message
quality and can deny the increase, in which case your limit stays where it is
([Meta, Messaging limits](https://developers.facebook.com/documentation/business-messaging/whatsapp/messaging-limits)).
Of 60 Genuka WA customer accounts audited in September 2026, none of the 45 unverified ones holds an
authentication template; the only one in the set belongs to a verified account.

### Where do you see it in Genuka WA?

| Channel                                                      | What you see                                                                                                    |
| ------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------- |
| `POST /api/v1/templates` with `"category": "AUTHENTICATION"` | `403 meta_rejected`, `meta.code: 10`, message "Application does not have permission for this action"            |
| Meta Business Suite                                          | The portfolio's verification status, under **Security Center**                                                  |
| Genuka's MCP server, `create_template` tool                  | The error comes with an explanation of this case for your AI agent — see [AI agents](https://wa.genuka.com/en/docs/guides/ai-agents) |

The Genuka WA API does not relay `health_status` itself: you have no Meta token to query it with,
and the verification status is easier to read in Meta Business Suite.

## How do I fix error 141010?

1. **Check the current status.** In Meta Business Suite, open **Security Center > Business
   Verification** on the portfolio that owns the WhatsApp account
   ([Meta, Embedded Signup errors](https://developers.facebook.com/documentation/business-messaging/whatsapp/embedded-signup/errors)).
   If you call Graph yourself, `GET /{WABA_ID}?fields=business_verification_status,health_status`
   returns both; Meta documents values such as `VERIFIED`, `PENDING` and `NOT_VERIFIED` for the first
   ([Meta, WhatsApp Business Account API](https://developers.facebook.com/documentation/business-messaging/whatsapp/reference/whatsapp-business-account/whatsapp-business-account-api)).
   Compare case-insensitively: the API returned `not_verified`, in lowercase, when we checked.
2. **Start verification.** You request it from Meta Business Suite, on that same portfolio
   ([Meta, Verify your business](https://www.facebook.com/business/help/2058515294227817)). Genuka
   plays no part in it: it is between your business and Meta.
3. **Recreate the authentication template.** Once the business is verified and the limit has moved to
   2,000 (shown in WhatsApp Manager, **Account tools > Messaging limits**, or in the number's
   `whatsapp_business_manager_messaging_limit` field), submit the same template again. Meta writes the
   text of authentication templates itself: you only provide the structure.

**Node.js**

```ts
const response = await fetch("https://wa.genuka.com/api/v1/templates", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${process.env.GENUKA_WA_API_KEY}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    connectionId: "con_1",
    name: "verification_code",
    language: "en_US",
    category: "AUTHENTICATION",
    messageSendTtlSeconds: 600,
    components: [
      { type: "BODY", add_security_recommendation: true },
      { type: "FOOTER", code_expiration_minutes: 10 },
      { type: "BUTTONS", buttons: [{ type: "OTP", otp_type: "COPY_CODE", text: "Copy code" }] },
    ],
  }),
});
const json = await response.json();

if (response.status === 403 && json.meta?.code === 10) {
  // Unverified business (141010): nothing to fix in your code or your key.
  throw new Error("Meta business verification required for OTP templates");
}
if (!response.ok) throw new Error(`${response.status} ${json.error}: ${json.message ?? ""}`);
console.log(json.data.id, json.data.status);
```

**Python**

```python
import os
import requests

response = requests.post(
    "https://wa.genuka.com/api/v1/templates",
    headers={"Authorization": f"Bearer {os.environ['GENUKA_WA_API_KEY']}"},
    json={
        "connectionId": "con_1",
        "name": "verification_code",
        "language": "en_US",
        "category": "AUTHENTICATION",
        "messageSendTtlSeconds": 600,
        "components": [
            {"type": "BODY", "add_security_recommendation": True},
            {"type": "FOOTER", "code_expiration_minutes": 10},
            {"type": "BUTTONS", "buttons": [{"type": "OTP", "otp_type": "COPY_CODE", "text": "Copy code"}]},
        ],
    },
    timeout=30,
)
body = response.json()

if response.status_code == 403 and (body.get("meta") or {}).get("code") == 10:
    # Unverified business (141010): nothing to fix in your code or your key.
    raise RuntimeError("Meta business verification required for OTP templates")
response.raise_for_status()
print(body["data"]["id"], body["data"]["status"])
```

**PHP**

```php
<?php
$ch = curl_init("https://wa.genuka.com/api/v1/templates");
curl_setopt_array($ch, [
    CURLOPT_POST => true,
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_USERAGENT => "acme-crm/1.0 (+https://example.com)",
    CURLOPT_HTTPHEADER => [
        "Authorization: Bearer " . getenv("GENUKA_WA_API_KEY"),
        "Content-Type: application/json",
    ],
    CURLOPT_POSTFIELDS => json_encode([
        "connectionId" => "con_1",
        "name" => "verification_code",
        "language" => "en_US",
        "category" => "AUTHENTICATION",
        "messageSendTtlSeconds" => 600,
        "components" => [
            ["type" => "BODY", "add_security_recommendation" => true],
            ["type" => "FOOTER", "code_expiration_minutes" => 10],
            ["type" => "BUTTONS", "buttons" => [["type" => "OTP", "otp_type" => "COPY_CODE", "text" => "Copy code"]]],
        ],
    ]),
]);
$body = json_decode(curl_exec($ch), true);
$status = curl_getinfo($ch, CURLINFO_RESPONSE_CODE);
curl_close($ch);

if ($status === 403 && ($body["meta"]["code"] ?? null) === 10) {
    // Unverified business (141010): nothing to fix in your code or your key.
    throw new RuntimeException("Meta business verification required for OTP templates");
}
echo $body["data"]["id"] ?? $body["error"];
```

**curl**

```bash
curl -X POST https://wa.genuka.com/api/v1/templates \
  -H "Authorization: Bearer $GENUKA_WA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "connectionId": "con_1",
    "name": "verification_code",
    "language": "en_US",
    "category": "AUTHENTICATION",
    "messageSendTtlSeconds": 600,
    "components": [
      { "type": "BODY", "add_security_recommendation": true },
      { "type": "FOOTER", "code_expiration_minutes": 10 },
      { "type": "BUTTONS", "buttons": [ { "type": "OTP", "otp_type": "COPY_CODE", "text": "Copy code" } ] }
    ]
  }'
# Unverified business: 403 { "error": "meta_rejected", "meta": { "code": 10, … } }
```

### What if the business cannot be verified right away?

Meta describes two other paths to 2,000 recipients a day: verification by the partner that
onboarded you, and 2,000 delivered messages outside service windows to unique recipients over a
rolling 30 days, using high-quality templates
([Meta, Messaging limits](https://developers.facebook.com/documentation/business-messaging/whatsapp/messaging-limits)).
They raise your messaging limit. According to 360dialog, the OTP condition is a completed scaling
path, not verification as such; but none of the unverified accounts we audited holds an
authentication template. In the meantime, send your codes by SMS or email and keep WhatsApp for your
notifications: see [WhatsApp API without Meta verification](https://wa.genuka.com/en/docs/guides/without-meta-verification).

## How do I prevent error 141010?

* **Start verification as soon as you plan OTP codes**, before writing the login flow: it is the
  one step you do not control.
* **Verify the right portfolio.** The one that owns the connected WhatsApp account, not another
  portfolio of the same company.
* **Test creating the `AUTHENTICATION` template on the production account**: an unverified test
  account will always fail, whatever your code does.

## Related error codes

* [10](https://wa.genuka.com/en/docs/errors/10): the response Meta returns when the OTP template is created.
* [200](https://wa.genuka.com/en/docs/errors/200): a genuine permission or account access problem, not to be confused
  with this one.
* `2388098`: during Embedded Signup, Meta limits how many WhatsApp accounts an unverified business
  can create
  ([Meta, Embedded Signup errors](https://developers.facebook.com/documentation/business-messaging/whatsapp/embedded-signup/errors)).

## FAQ

### Can you send WhatsApp messages without business verification?

Yes. Marketing and utility templates, and replies inside the 24-hour service window, work without
verification, within 250 unique recipients per 24 hours to start. Only OTP codes require it.

### Why does the error talk about an application permission?

Because Meta answers the template creation with a generic permission error, code 10. The real
cause is the business: the same account creates marketing templates without any problem.

### Why is 141010 missing from Meta's list of error codes?

It is a `health_status` diagnostic code, describing why an entity is limited, not a code returned
by an API call. Meta's public list only covers the latter.

### Do I need to recreate the template after verification?

Yes. A template refused at creation does not exist on Meta's side: submit it again once the
business is verified and the account's limit has moved to 2,000.

## Sources

* [Meta — Health status](https://developers.facebook.com/documentation/business-messaging/whatsapp/support/health-status)
* [Meta — Messaging limits](https://developers.facebook.com/documentation/business-messaging/whatsapp/messaging-limits)
* [Meta — WhatsApp Business Account API](https://developers.facebook.com/documentation/business-messaging/whatsapp/reference/whatsapp-business-account/whatsapp-business-account-api)
* [Meta — Embedded Signup flow errors](https://developers.facebook.com/documentation/business-messaging/whatsapp/embedded-signup/errors)
* [Meta — Error codes](https://developers.facebook.com/documentation/business-messaging/whatsapp/support/error-codes)
* [Meta — Verify your business in Meta Business Suite](https://www.facebook.com/business/help/2058515294227817)
* [360dialog — Authentication messages](https://docs.360dialog.com/docs/resources/authentication-messages)
