# WhatsApp error 368: account restricted — cause and fix

URL: https://wa.genuka.com/en/docs/errors/368
Language: English

> WhatsApp error 368: the WhatsApp Business Account is restricted or disabled for a Meta policy violation. Durations, requesting a review, prevention.

WhatsApp error 368 means the WhatsApp Business account linked to the app has been restricted or
disabled for violating a platform policy. It is neither a bug nor a rate limit: retrying will not
help. The way out goes through Business Support Home, where the business sees the violation, how
long it lasts, and can request a review.

## What does error 368 mean?

Meta lists it among the Cloud API's integrity errors:

> "The WhatsApp Business Account associated with the app has been restricted or disabled for
> violating a platform policy."
> — [Meta, Cloud API error codes](https://developers.facebook.com/documentation/business-messaging/whatsapp/support/error-codes#integrity-errors)

The suggested fix points to Meta's policy enforcement document. In the general Graph
documentation, code 368 is called "Temporarily blocked for policies violations"
([Meta, Graph API error handling](https://developers.facebook.com/docs/graph-api/guides/error-handling)).

### What restrictions does Meta apply?

Meta starts with a warning. If the account keeps violating the rules, restrictions grow longer
step by step
([Meta, Policy enforcement](https://developers.facebook.com/documentation/business-messaging/whatsapp/policy-enforcement)):

| Restriction     | Effect                                                                  |
| --------------- | ----------------------------------------------------------------------- |
| 1 or 3 days     | No marketing, utility or authentication templates; no new phone numbers |
| 5, 7 or 30 days | No messages at all; no new phone numbers                                |
| Account lock    | Indefinite block on all sends, lifted only through an appeal            |
| Disabled        | Permanently removed from the platform, after several unheeded warnings  |

For severe harm, Meta names child exploitation, scams, terrorism and the sale of illegal drugs, the
account can be offboarded immediately (same page).

## When does error 368 happen?

Meta names spam, template misclassification, high-risk categories (adult content, alcohol and
tobacco, drugs, gambling, unsafe supplements) and excessive negative user feedback as reasons for
restrictions (same page). In practice:

* **Messages to people who never asked for them**, who then block or report the number.
* **A template classified `UTILITY` whose content is promotional.** Meta counts misclassification
  as a violation.
* **An activity WhatsApp's commerce rules forbid or tightly restrict.**

### Where do you see it in Genuka WA?

Genuka WA puts code 368 in the `config` class: the account can no longer do what is asked, and no
retry will change that.

| Channel                  | What you get                                                                                                                                                                              |
| ------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `POST /api/v1/messages`  | `409`, `"error": "send_config"`, `meta.code: 368`                                                                                                                                         |
| Campaign                 | Each refused recipient turns `failed` with no retry; for a `MARKETING` campaign, Genuka first tries the Marketing Messages API, then the `/messages` endpoint, which refuses the same way |
| `account_update` webhook | Meta's event, forwarded as is in `data`                                                                                                                                                   |

Meta documents the `account_update` events to watch
([account\_update webhook](https://developers.facebook.com/documentation/business-messaging/whatsapp/webhooks/reference/account_update)):

| `event`               | What it announces                                                                                |
| --------------------- | ------------------------------------------------------------------------------------------------ |
| `ACCOUNT_VIOLATION`   | A violation, with its type in `violation_info`                                                   |
| `ACCOUNT_RESTRICTION` | A restriction, with its type (for example `RESTRICTED_BIZ_INITIATED_MESSAGING`) and its end date |
| `DISABLED_UPDATE`     | The account's ban state: `SCHEDULE_FOR_DISABLE`, `DISABLE` or `REINSTATE`                        |

Genuka forwards each event type only once per WhatsApp account until its event log purges it,
according to your plan's retention period: a second `ACCOUNT_RESTRICTION` on the same account
within that window may never reach you. To know the current restriction, rely on Business Support
Home rather than on the webhook alone.

## How do I fix error 368?

Neither Genuka nor your code can lift a restriction: the decision is Meta's, and only the business
that owns the account can contest it.

1. **Pause sends on that account.** Suspend the campaigns and automations that target its numbers:
   while the restriction lasts, every refused send only adds to the list of failures to replay.
2. **Open Business Support Home.** In Meta Business Suite: **All tools**, then **Business Support
   Home**, then **Account Overview**. The violation is described there: the policy violated, examples
   of allowed and disallowed content, active restrictions, what happens on a repeat, and how to appeal
   (same Meta page).
3. **Request a review if you are compliant.** Select the account, pick the violation, **Request
   Review**, add your supporting details and submit. Meta says the decision typically takes 24 to 48
   hours, either "Unchanged" or "Reversed". Not every spam violation can be appealed: sometimes you
   have to wait for the restriction to end.
4. **Fix the cause before resuming.** Contact list, template classification, send frequency: resume
   with small volumes to contacts who have opted in.

## How do I prevent error 368?

* **Only message people who agreed to it**, and give them a simple way to stop receiving your
  marketing messages.
* **Classify your templates honestly.** A promotion is not a utility message.
* **Watch quality before the penalty.** Subscribe an endpoint to `account_update` and
  `phone_number_quality_update` ([Webhooks](https://wa.genuka.com/en/docs/webhooks)): falling quality shows up before a
  restriction does.
* **Keep an eye on [131048](https://wa.genuka.com/en/docs/errors/131048)**: sends limited after blocks or reports are
  often the early warning.

## Related error codes

* `131031`: account restricted or disabled, or request data that does not match the account (a
  wrong two-step verification PIN, for instance).
* [131048](https://wa.genuka.com/en/docs/errors/131048): sends limited after too many blocked or reported messages.
* `130497`: account barred from messaging users in certain countries.
* `131064`: messaging limit imposed after template classification violations.

## FAQ

### How long does a restriction last?

It depends on severity and repetition: 1 or 3 days for templates, 5, 7 or 30 days for all sends,
and an open-ended lock until an appeal succeeds. The `ACCOUNT_RESTRICTION` event carries the end
date when there is one; if it was not forwarded to you, Business Support Home lists the active
restrictions.

### Can Genuka lift the restriction?

No. The decision and the review belong to Meta. Genuka relays the error and the account events;
the appeal is made from the business's Business Support Home.

### Are my other customers affected?

No. The restriction applies to one WhatsApp Business account. Your other customers' accounts are
not concerned.

### Should I retry the refused sends?

Not during the restriction. Resume after its end date, or after a "Reversed" decision.

## Sources

* [Meta — Error codes](https://developers.facebook.com/documentation/business-messaging/whatsapp/support/error-codes)
* [Meta — Policy enforcement](https://developers.facebook.com/documentation/business-messaging/whatsapp/policy-enforcement)
* [Meta — account\_update webhook](https://developers.facebook.com/documentation/business-messaging/whatsapp/webhooks/reference/account_update)
* [Meta — Graph API, Handling errors](https://developers.facebook.com/docs/graph-api/guides/error-handling)
