# WhatsApp error 200: access denied (200-299) — fix

URL: https://wa.genuka.com/en/docs/errors/200
Language: English

> WhatsApp Cloud API error 200: missing token, revoked permission or a system user with no access to the account. How to diagnose and fix it.

WhatsApp error 200, like the whole 200 to 299 range, means the call lacks the rights it needs: no
token, a permission never granted or since removed, or a system user with no access to the target
WhatsApp account. It has nothing to do with HTTP status 200. You fix it by restoring access, not by
retrying.

## What does error 200 mean?

Meta lists two entries among its authorization errors
([Meta, Cloud API error codes](https://developers.facebook.com/documentation/business-messaging/whatsapp/support/error-codes#authorization-errors)):

| Code           | `details` according to Meta                                                                                                                                                         | What Meta recommends                                                                      |
| -------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- |
| `200`          | "No access token was provided." The API then answers "Provide valid app ID", on some `GET` endpoints such as `whatsapp_business_profile`; other endpoints return 190 or 104 instead | "Ensure your request includes a valid access token." Meta notes this is distinct from 190 |
| `200` to `299` | "Permission is either not granted or has been removed."                                                                                                                             | Check in the access token debugger that the app has the permissions the endpoint requires |

Meta's token guide adds the most common production case: most endpoints check that the user behind
the token has access to the requested resource, and otherwise refuse with error code 200, "not to
be confused with HTTP status code 200"
([Meta, Access tokens](https://developers.facebook.com/documentation/business-messaging/whatsapp/access-tokens#business-asset-access)).
Graph calls this range "API Permission"
([Meta, Graph API error handling](https://developers.facebook.com/docs/graph-api/guides/error-handling)).

## When does error 200 happen?

* **The system user is not assigned to the account.** An "employee" system user needs partial or
  full access to the WhatsApp account **and** the Messaging account: access to the latter alone is
  not enough (same page).
* **The token lacks a permission.** Deregistering a number without `whatsapp_business_management`
  returns 200, for example
  ([Meta, Registration](https://developers.facebook.com/documentation/business-messaging/whatsapp/business-phone-numbers/registration)).
* **The request has no token at all**, typically a `GET` on the business profile.
* **The business stopped sharing its account with the partner.** Meta then emits a
  `PARTNER_REMOVED` event ([Meta, account\_update webhook](https://developers.facebook.com/documentation/business-messaging/whatsapp/webhooks/reference/account_update)),
  and the partner's system user loses access to the account.

### Where do you see it in Genuka WA?

With Genuka WA, the last case is a common one: your customer removed Genuka's access to their
WhatsApp account, in their Business Manager or, for a coexistence number, from the WhatsApp
Business app ([Meta, coexistence](https://developers.facebook.com/documentation/business-messaging/whatsapp/embedded-signup/onboarding-business-app-users/)). Genuka receives the
`PARTNER_REMOVED`, marks the connection `disconnected` and forwards the `account_update` event to
your [webhooks](https://wa.genuka.com/en/docs/webhooks). The same situation can also come back as code 100 with
subcode 33, "… cannot be loaded due to missing permissions", see [error 100](https://wa.genuka.com/en/docs/errors/100).

Genuka does not put codes 200 to 299 in a dedicated class: the class follows the HTTP status Meta
returned, `config` on a 401 or 403, `unknown` otherwise. Either way, the refusal is not retryable.

| Channel                   | What you get                                                   |
| ------------------------- | -------------------------------------------------------------- |
| `POST /api/v1/messages`   | `409 send_config` or `400 send_unknown`, with `meta.code: 200` |
| `POST /api/v1/templates`  | `403` or `422`, `"error": "meta_rejected"`                     |
| `GET /api/v1/connections` | `"status": "disconnected"` on the number concerned             |

A coexistence number can also turn `offboarded`: Meta reported that it is no longer linked to the
API, for instance after a device change followed by a re-registration
([Meta, coexistence](https://developers.facebook.com/documentation/business-messaging/whatsapp/embedded-signup/onboarding-business-app-users/)). Genuka then refuses sends itself, before calling
Meta: `409 send_config`, with a message naming the offboarding ("was offboarded by the
merchant…") and no `meta.code`. A number you released from your plan is refused the same way, as
`409 number_released`.

## How do I fix error 200?

### If you go through Genuka WA

1. **Check the number's state.**

   ```bash title="GET /api/v1/connections"
   curl "https://wa.genuka.com/api/v1/connections?companyId=cmp_123" \
     -H "Authorization: Bearer $GENUKA_WA_API_KEY"
   ```

   ```json title="Response (excerpt)"
   { "data": [ { "id": "con_1", "companyId": "cmp_123", "displayPhoneNumber": "+237 6 90 …",
                 "qualityRating": "GREEN", "status": "disconnected" } ] }
   ```

2. **If it is `disconnected`, find out why before asking for a reconnection.** The status means Meta
   reported the account as no longer shared with Genuka, or deleted, or that you released the number
   yourself. A customer who removed access goes through the same `/connect/{your-slug}` link again:
   access comes back on the same record, with messages, templates and statistics kept and no new slot
   used in your plan ([Connect a number](https://wa.genuka.com/en/docs/onboarding)). A released number needs a free slot
   again. A deleted account, or one disabled by Meta ([error 368](https://wa.genuka.com/en/docs/errors/368)), is not
   restored by reconnecting: the `account_update` event forwarded to your webhooks tells you which
   case applies. If it is `offboarded`, follow the [coexistence guide](https://wa.genuka.com/en/docs/guides/coexistence).

3. **If it still reads `connected`, contact Genuka support** with the response's `x-request-id`
   header and `meta.traceId`. The status reflects the latest events received from Meta: it does not
   prove that access is intact.

### If you call the Cloud API with your own token

1. **Assign the system user to both accounts.** In Meta Business Suite: portfolio settings,
   **Accounts > WhatsApp accounts**, pick the account, **People** tab, **+Add people**, then the system
   user and its access level. Repeat under **Accounts > Messaging accounts**
   ([Meta, Access tokens](https://developers.facebook.com/documentation/business-messaging/whatsapp/access-tokens#business-asset-access)).
2. **Check the token's permissions** in the
   [access token debugger](https://developers.facebook.com/tools/debug/accesstoken/):
   `whatsapp_business_management` and `whatsapp_business_messaging`, plus `business_management` if
   you manage portfolio assets.
3. **Do not rely on the API cascade.** Access granted through the API on the Messaging account also
   applies to the linked WhatsApp account, but Meta calls this behaviour interim, and Meta Business
   Suite does not do it. Assign both accounts explicitly (same page).

## How do I prevent error 200?

* **Subscribe an endpoint to `account_update`.** A `PARTNER_REMOVED` warns you the moment a
  customer removes access, before your sends start failing.
* **Tell your customers what removal means.** Removing Genuka from their Business Manager cuts the
  API on every number of that WhatsApp account.
* **If you manage your own tokens**, Meta says an admin system user has access by default to every
  WhatsApp account owned by or shared with your portfolio; an employee system user has to be
  assigned account by account.

## Related error codes

* [190](https://wa.genuka.com/en/docs/errors/190): the token has expired or was invalidated.
* [10](https://wa.genuka.com/en/docs/errors/10): permission not granted or removed, including OTP templates for an
  unverified business.
* [3](https://wa.genuka.com/en/docs/errors/3): capability or permission missing for this endpoint.
* [0](https://wa.genuka.com/en/docs/errors/0): Meta could not authenticate the app user.

## FAQ

### Is error 200 related to HTTP status 200?

Not at all. It is a Meta error code, returned in the `code` field of a failed response. Meta points
this out in its own documentation.

### My customer removed Genuka by mistake: what should they do?

Go through your connect link again. The number comes back on the same record, with its history,
and without using an extra slot.

### Why does the error only hit some of my numbers?

Because access is granted per WhatsApp account. The numbers of a customer who removed access fail;
those of your other customers keep working.

### Should I retry?

No. Until access is restored, every new call will produce the same error.

## Sources

* [Meta — Error codes](https://developers.facebook.com/documentation/business-messaging/whatsapp/support/error-codes)
* [Meta — Access tokens, business asset access](https://developers.facebook.com/documentation/business-messaging/whatsapp/access-tokens#business-asset-access)
* [Meta — Register a business phone number](https://developers.facebook.com/documentation/business-messaging/whatsapp/business-phone-numbers/registration)
* [Meta — account\_update webhook](https://developers.facebook.com/documentation/business-messaging/whatsapp/webhooks/reference/account_update)
* [Meta — Onboarding WhatsApp Business app users (coexistence)](https://developers.facebook.com/documentation/business-messaging/whatsapp/embedded-signup/onboarding-business-app-users/)
* [Meta — Graph API, Handling errors](https://developers.facebook.com/docs/graph-api/guides/error-handling)
