Genuka WA docs

WhatsApp API without Meta verification: what works

WhatsApp API without Meta verification: what an unverified business can send, what verification unlocks, and the real risk of unofficial APIs.

Yes, you can send messages through the official WhatsApp API without getting your business verified by Meta. Through a Tech Provider like Genuka, you connect your number in minutes and send marketing and utility templates, up to 250 unique recipients per 24 hours to start with. One-time passcodes and higher limits come, in practice, through verification.

Last updated October 8, 2026

Which "Meta verification" are we talking about?

The phrase covers two different processes, and only one of them concerns you.

ProcessWho does itNeeded to get started?
Becoming a provider on the WhatsApp Business Platform (Tech Provider or Solution Partner)The provider. Genuka is a Meta Tech Provider: the Meta app and its permissions are Genuka'sNo. You connect your number through Meta's Embedded Signup, with no provider application to file
Verifying your business (Business Verification)You, on your Meta business portfolioNo. Meta made it optional at the start in 2022: you message customers right after signup and verify when you are ready to scale (Meta changelog, April 14, 2022)

With Embedded Signup, your business owns all of its WhatsApp assets — account, number, templates (Meta, Embedded Signup). Genuka does not rent you access: it gives you an API on top of your own account.

What can an unverified business do?

CapabilityUnverified businessVerified business
Reply inside the 24-hour customer service windowYes, outside the messaging limitYes
MARKETING and UTILITY templatesYesYes
AUTHENTICATION templates (OTP codes)Refused at creation (Genuka observation, detailed below)Yes
Unique recipients outside the window, per moving 24 hours250 to start (Meta)2,000, then raised automatically up to unlimited (same page)
Registered numbers per business portfolio2 to start (Meta)Up to 20 (same page)
Templates per WhatsApp account250 (Meta)Up to 6,000, with an approved display name (same page)
Official Business Account badgeNoPossible, with other conditions (Meta)

The 250 limit counts unique recipients reached outside a customer service window, and it applies to the whole business portfolio, not to one number. Replying to a customer who just wrote to you does not eat into it.

How do I send a first message without verification?

Create a Genuka WA account

Seven-day free trial, no card required. Your workspace opens straight away.

Connect your number

From the Numbers page of your dashboard (or Connect link if you manage clients), start the connection and follow Meta's Embedded Signup — see Connecting a number. If the number already runs on the WhatsApp Business app, keep it: that is coexistence.

Add a payment method on Meta's side

A client onboarded by a Tech Provider adds its own payment method to its WhatsApp Business account, and Meta bills it directly (Meta, Partners). Without one, your templates get approved but every send fails with 131042 ("there was an error related to your payment method", Meta error codes).

Get a utility or marketing template approved

Create it with POST /api/v1/templates — see the API reference. Meta's review can take up to 24 hours (Meta).

Send it

One call, whatever the language:

curl -X POST https://wa.genuka.com/api/v1/messages \
  -H "Authorization: Bearer $GENUKA_WA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "connectionId": "con_1",
    "to": "+237690000001",
    "template": { "name": "order_confirmation", "language": "en_US", "variables": ["Awa", "ORD-1042"] }
  }'
# { "data": { "messageId": "wamid.HBg…" } }

A 200 means Meta accepted the message; delivery follows on your webhooks. Your messaging limit shows in WhatsApp Manager, under Account tools > Messaging limits (Meta). GET /api/v1/numbers?refresh=true also returns a messagingLimitTier per number, as an indication only: it comes from a field Meta has deprecated and can be empty.

What does business verification unlock?

One-time passcodes (authentication templates)

This is the limit people find out about last. On the WhatsApp accounts connected to Genuka WA, we observe that:

  • creating an AUTHENTICATION template for an unverified business fails with the Graph message "Application does not have permission for this action". The message blames the app; the cause is the client's business;
  • the account's health status then carries error 141010, "The Business has not passed business verification" (health_status field, Meta docs);
  • MARKETING and UTILITY templates on the same account go through normally.

That observation covers unverified businesses still at the 250 limit. The rule as 360dialog, another Meta partner, documents it is broader: complete one of Meta's scaling paths (verification by Meta or by the partner, for example) and have a messaging limit of at least 2,000 (360dialog, Authentication messages). Business verification is the most direct path, not the only one.

The WhatsApp account's business_verification_status field says so too (Meta reference). With Genuka you never handle a Meta token: check the verification state in Meta Business Suite, on the portfolio that owns your WhatsApp account. Once the business is verified, the OTP from Node.js guide takes over.

Higher limits

Verifying the business is one of the three paths Meta offers to go from 250 to 2,000 unique recipients per 24 hours. Beyond that, the limit rises on its own (10,000, 100,000, then unlimited) as long as your messages stay high quality and you use at least half of your limit over 7 days (Meta, Messaging limits). Verification also takes you from 2 to 20 registered numbers on the portfolio; Meta raises that cap the same way once your portfolio reaches the 2,000 messaging limit (Meta, Business phone numbers).

Can I go past 250 without verification?

Yes. Meta accepts another path: deliver 2,000 messages outside the customer service window to unique recipients over a moving 30 days, using templates with a high quality rating (same page). With a limit of 250 per 24 hours, that takes at least 8 days of near-maximum sending. Meta also lists a third path: having the partner who onboarded you verify your business.

Verification itself starts in Meta Business Suite, on the portfolio that owns your WhatsApp account: follow Meta's official procedure.

What about unofficial WhatsApp APIs (QR code, WhatsApp Web)?

Some services promise a "WhatsApp API without Meta": you scan a QR code as you would for WhatsApp Web, and their server drives your ordinary WhatsApp account. There is indeed no Meta onboarding, no verification and no template. But:

  • It breaks WhatsApp's terms. They forbid bulk messaging and auto-messaging, unauthorized access to the services, including through automated means, and building software or APIs that work substantially like WhatsApp's services for third parties (WhatsApp Terms of Service).
  • The number can be suspended at any time. WhatsApp may suspend or terminate access that violates its terms (same page), and the WhatsApp Business policy explicitly targets messaging people at scale in an unauthorized manner (WhatsApp Business Messaging Policy). The number at stake is often the one your customers know.
  • The official platform's tools are missing. No approved templates to re-engage a customer outside the 24-hour window, no marketing opt-out signal forwarded by Meta.

The detailed comparison lives at Unofficial WhatsApp APIs.

Which path should I choose?

What you needThe path
Notifications, confirmations, reminders, campaigns: up to 250 unique recipients a day outside the windowCloud API through Genuka, no verification
Sending OTP codesCloud API through Genuka, once you clear one of Meta's scaling paths (business verification, in practice)
Reaching more than 250 people a day outside the window from day oneBusiness verification
Keeping your WhatsApp Business app on the same numberCoexistence
Automating a personal WhatsApp accountNo path that complies with WhatsApp's terms

FAQ

Can I send OTP codes without business verification?

Not until your portfolio has cleared one of Meta's scaling paths. An unverified business at the 250 limit is refused the authentication template that carries the code, with error 141010 in the account's health status. Business verification is the most direct path, not the only one. Marketing and utility templates stay available in the meantime.

Why does Meta answer "Application does not have permission for this action"?

On an AUTHENTICATION template, it is the symptom of an unverified business, not of a token or app problem. Genuka then returns 403 meta_rejected, with Meta's message and its identifiers (meta.code, meta.traceId). Check the verification status in Meta Business Suite, on the portfolio that owns your WhatsApp account. If you have your own Graph API access, the WhatsApp account's business_verification_status and health_status fields say so too.

Do I need to become a Tech Provider myself to use the API?

No. Genuka is a Tech Provider: you connect your number through Meta's Embedded Signup and call Genuka's REST API with an API key, with no Meta token to manage.

How long does it take to go from 250 to 2,000 recipients without verification?

At least 8 days: you need 2,000 messages delivered outside the window to unique recipients over 30 days, with high-quality templates, and the starting limit is 250 per 24 hours.

Can my number get banned on the official API?

Not for using the API as such. Meta does rate-limit a number whose quality stays low (Meta, Get opt-in) and restricts an account that violates its policies (errors 368 / 131031). Message people who agreed to hear from you.

Sources

On this page