WhatsApp error 200: access denied (200-299) — fix
WhatsApp Cloud API error 200: missing token, revoked permission or a system user with no access to the account. How to diagnose and fix it.
WhatsApp error 200, like the whole 200 to 299 range, means the call lacks the rights it needs: no token, a permission never granted or since removed, or a system user with no access to the target WhatsApp account. It has nothing to do with HTTP status 200. You fix it by restoring access, not by retrying.
What does error 200 mean?
Meta lists two entries among its authorization errors (Meta, Cloud API error codes):
| Code | details according to Meta | What Meta recommends |
|---|---|---|
200 | "No access token was provided." The API then answers "Provide valid app ID", on some GET endpoints such as whatsapp_business_profile; other endpoints return 190 or 104 instead | "Ensure your request includes a valid access token." Meta notes this is distinct from 190 |
200 to 299 | "Permission is either not granted or has been removed." | Check in the access token debugger that the app has the permissions the endpoint requires |
Meta's token guide adds the most common production case: most endpoints check that the user behind the token has access to the requested resource, and otherwise refuse with error code 200, "not to be confused with HTTP status code 200" (Meta, Access tokens). Graph calls this range "API Permission" (Meta, Graph API error handling).
When does error 200 happen?
- The system user is not assigned to the account. An "employee" system user needs partial or full access to the WhatsApp account and the Messaging account: access to the latter alone is not enough (same page).
- The token lacks a permission. Deregistering a number without
whatsapp_business_managementreturns 200, for example (Meta, Registration). - The request has no token at all, typically a
GETon the business profile. - The business stopped sharing its account with the partner. Meta then emits a
PARTNER_REMOVEDevent (Meta, account_update webhook), and the partner's system user loses access to the account.
Where do you see it in Genuka WA?
With Genuka WA, the last case is a common one: your customer removed Genuka's access to their
WhatsApp account, in their Business Manager or, for a coexistence number, from the WhatsApp
Business app (Meta, coexistence). Genuka receives the
PARTNER_REMOVED, marks the connection disconnected and forwards the account_update event to
your webhooks. The same situation can also come back as code 100 with
subcode 33, "… cannot be loaded due to missing permissions", see error 100.
Genuka does not put codes 200 to 299 in a dedicated class: the class follows the HTTP status Meta
returned, config on a 401 or 403, unknown otherwise. Either way, the refusal is not retryable.
| Channel | What you get |
|---|---|
POST /api/v1/messages | 409 send_config or 400 send_unknown, with meta.code: 200 |
POST /api/v1/templates | 403 or 422, "error": "meta_rejected" |
GET /api/v1/connections | "status": "disconnected" on the number concerned |
A coexistence number can also turn offboarded: Meta reported that it is no longer linked to the
API, for instance after a device change followed by a re-registration
(Meta, coexistence). Genuka then refuses sends itself, before calling
Meta: 409 send_config, with a message naming the offboarding ("was offboarded by the
merchant…") and no meta.code. A number you released from your plan is refused the same way, as
409 number_released.
How do I fix error 200?
If you go through Genuka WA
Check the number's state.
curl "https://wa.genuka.com/api/v1/connections?companyId=cmp_123" \
-H "Authorization: Bearer $GENUKA_WA_API_KEY"{ "data": [ { "id": "con_1", "companyId": "cmp_123", "displayPhoneNumber": "+237 6 90 …",
"qualityRating": "GREEN", "status": "disconnected" } ] }If it is disconnected, find out why before asking for a reconnection. The status means Meta
reported the account as no longer shared with Genuka, or deleted, or that you released the number
yourself. A customer who removed access goes through the same /connect/{your-slug} link again:
access comes back on the same record, with messages, templates and statistics kept and no new slot
used in your plan (Connect a number). A released number needs a free slot
again. A deleted account, or one disabled by Meta (error 368), is not
restored by reconnecting: the account_update event forwarded to your webhooks tells you which
case applies. If it is offboarded, follow the coexistence guide.
If it still reads connected, contact Genuka support with the response's x-request-id
header and meta.traceId. The status reflects the latest events received from Meta: it does not
prove that access is intact.
If you call the Cloud API with your own token
Assign the system user to both accounts. In Meta Business Suite: portfolio settings, Accounts > WhatsApp accounts, pick the account, People tab, +Add people, then the system user and its access level. Repeat under Accounts > Messaging accounts (Meta, Access tokens).
Check the token's permissions in the
access token debugger:
whatsapp_business_management and whatsapp_business_messaging, plus business_management if
you manage portfolio assets.
Do not rely on the API cascade. Access granted through the API on the Messaging account also applies to the linked WhatsApp account, but Meta calls this behaviour interim, and Meta Business Suite does not do it. Assign both accounts explicitly (same page).
How do I prevent error 200?
- Subscribe an endpoint to
account_update. APARTNER_REMOVEDwarns you the moment a customer removes access, before your sends start failing. - Tell your customers what removal means. Removing Genuka from their Business Manager cuts the API on every number of that WhatsApp account.
- If you manage your own tokens, Meta says an admin system user has access by default to every WhatsApp account owned by or shared with your portfolio; an employee system user has to be assigned account by account.
Related error codes
- 190: the token has expired or was invalidated.
- 10: permission not granted or removed, including OTP templates for an unverified business.
- 3: capability or permission missing for this endpoint.
- 0: Meta could not authenticate the app user.
FAQ
Is error 200 related to HTTP status 200?
Not at all. It is a Meta error code, returned in the code field of a failed response. Meta points
this out in its own documentation.
My customer removed Genuka by mistake: what should they do?
Go through your connect link again. The number comes back on the same record, with its history, and without using an extra slot.
Why does the error only hit some of my numbers?
Because access is granted per WhatsApp account. The numbers of a customer who removed access fail; those of your other customers keep working.
Should I retry?
No. Until access is restored, every new call will produce the same error.
Sources
WhatsApp error 190: access token expired — cause and fix
WhatsApp Cloud API error 190 (access token expired): which token expired, how to replace it for good, and why Genuka WA users never handle Meta tokens.
WhatsApp error 4: app rate limit reached — fix
WhatsApp error 4 (API Too Many Calls): the app hit its Meta API call rate limit. How it differs from 80007 and 130429, and how to retry safely.