# WhatsApp API without Meta verification: what works

URL: https://wa.genuka.com/en/docs/guides/without-meta-verification
Language: English

> WhatsApp API without Meta verification: what an unverified business can send, what verification unlocks, and the real risk of unofficial APIs.

Yes, you can send messages through the official WhatsApp API without getting your business
verified by Meta. Through a Tech Provider like Genuka, you connect your number in minutes and send
marketing and utility templates, up to 250 unique recipients per 24 hours to start with.
One-time passcodes and higher limits come, in practice, through verification.

*Last updated October 8, 2026*

## Which "Meta verification" are we talking about?

The phrase covers two different processes, and only one of them concerns you.

| Process                                                                                       | Who does it                                                                                 | Needed to get started?                                                                                                                                                                                                                                  |
| --------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Becoming a provider** on the WhatsApp Business Platform (Tech Provider or Solution Partner) | The provider. Genuka is a Meta Tech Provider: the Meta app and its permissions are Genuka's | No. You connect your number through Meta's Embedded Signup, with no provider application to file                                                                                                                                                        |
| **Verifying your business** (Business Verification)                                           | You, on your Meta business portfolio                                                        | No. Meta made it optional at the start in 2022: you message customers right after signup and verify when you are ready to scale ([Meta changelog, April 14, 2022](https://developers.facebook.com/documentation/business-messaging/whatsapp/changelog)) |

With Embedded Signup, your business owns all of its WhatsApp assets — account, number, templates
([Meta, Embedded Signup](https://developers.facebook.com/documentation/business-messaging/whatsapp/embedded-signup/overview/)).
Genuka does not rent you access: it gives you an API on top of your own account.

## What can an unverified business do?

| Capability                                                | Unverified business                                                                                                                 | Verified business                                                                                                                               |
| --------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------- |
| Reply inside the 24-hour customer service window          | Yes, outside the messaging limit                                                                                                    | Yes                                                                                                                                             |
| `MARKETING` and `UTILITY` templates                       | Yes                                                                                                                                 | Yes                                                                                                                                             |
| `AUTHENTICATION` templates (OTP codes)                    | Refused at creation (Genuka observation, detailed below)                                                                            | Yes                                                                                                                                             |
| Unique recipients outside the window, per moving 24 hours | 250 to start ([Meta](https://developers.facebook.com/documentation/business-messaging/whatsapp/messaging-limits))                   | 2,000, then raised automatically up to unlimited (same page)                                                                                    |
| Registered numbers per business portfolio                 | 2 to start ([Meta](https://developers.facebook.com/documentation/business-messaging/whatsapp/business-phone-numbers/phone-numbers)) | Up to 20 (same page)                                                                                                                            |
| Templates per WhatsApp account                            | 250 ([Meta](https://developers.facebook.com/documentation/business-messaging/whatsapp/templates/overview))                          | Up to 6,000, with an approved display name (same page)                                                                                          |
| Official Business Account badge                           | No                                                                                                                                  | Possible, with other conditions ([Meta](https://developers.facebook.com/documentation/business-messaging/whatsapp/official-business-accounts/)) |

The 250 limit counts **unique** recipients reached **outside** a customer service window, and it
applies to the whole business portfolio, not to one number. Replying to a customer who just wrote
to you does not eat into it.

## How do I send a first message without verification?

1. ### Create a Genuka WA account

   Seven-day free trial, no card required. Your workspace opens straight away.

2. ### Connect your number

   From the **Numbers** page of your dashboard (or **Connect link** if you manage clients), start the
   connection and follow Meta's Embedded Signup — see
   [Connecting a number](https://wa.genuka.com/en/docs/onboarding). If the number already runs on the WhatsApp Business
   app, keep it: that is [coexistence](https://wa.genuka.com/en/docs/guides/coexistence).

3. ### Add a payment method on Meta's side

   A client onboarded by a Tech Provider adds its own payment method to its WhatsApp Business
   account, and Meta bills it directly
   ([Meta, Partners](https://developers.facebook.com/documentation/business-messaging/whatsapp/solution-providers/overview)).
   Without one, your templates get approved but every send fails with `131042` ("there was an error
   related to your payment method", [Meta error codes](https://developers.facebook.com/documentation/business-messaging/whatsapp/support/error-codes)).

4. ### Get a utility or marketing template approved

   Create it with `POST /api/v1/templates` — see the [API reference](https://wa.genuka.com/en/docs/api#templates). Meta's
   review can take up to 24 hours
   ([Meta](https://developers.facebook.com/documentation/business-messaging/whatsapp/templates/overview)).

5. ### Send it

   One call, whatever the language:

**curl**

```bash
curl -X POST https://wa.genuka.com/api/v1/messages \
  -H "Authorization: Bearer $GENUKA_WA_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "connectionId": "con_1",
    "to": "+237690000001",
    "template": { "name": "order_confirmation", "language": "en_US", "variables": ["Awa", "ORD-1042"] }
  }'
# { "data": { "messageId": "wamid.HBg…" } }
```

**Node.js**

```ts
const response = await fetch("https://wa.genuka.com/api/v1/messages", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${process.env.GENUKA_WA_API_KEY}`,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({
    connectionId: "con_1",
    to: "+237690000001",
    template: { name: "order_confirmation", language: "en_US", variables: ["Awa", "ORD-1042"] },
  }),
});
const json = await response.json();
if (!response.ok) throw new Error(`${response.status} ${json.error}: ${json.message ?? ""}`);
console.log(json.data.messageId); // wamid.HBg…
```

**Python**

```python
import os
import requests

response = requests.post(
    "https://wa.genuka.com/api/v1/messages",
    headers={
        "Authorization": f"Bearer {os.environ['GENUKA_WA_API_KEY']}",
        "User-Agent": "acme-crm/1.0 (+https://example.com)",
    },
    json={
        "connectionId": "con_1",
        "to": "+237690000001",
        "template": {"name": "order_confirmation", "language": "en_US", "variables": ["Awa", "ORD-1042"]},
    },
    timeout=30,
)
response.raise_for_status()
print(response.json()["data"]["messageId"])  # wamid.HBg…
```

**PHP**

```php
<?php
$ch = curl_init("https://wa.genuka.com/api/v1/messages");
curl_setopt_array($ch, [
    CURLOPT_POST => true,
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_USERAGENT => "acme-crm/1.0 (+https://example.com)",
    CURLOPT_HTTPHEADER => [
        "Authorization: Bearer " . getenv("GENUKA_WA_API_KEY"),
        "Content-Type: application/json",
    ],
    CURLOPT_POSTFIELDS => json_encode([
        "connectionId" => "con_1",
        "to" => "+237690000001",
        "template" => ["name" => "order_confirmation", "language" => "en_US", "variables" => ["Awa", "ORD-1042"]],
    ]),
]);
$json = json_decode(curl_exec($ch), true);
curl_close($ch);
echo $json["data"]["messageId"] ?? $json["error"];
```

A `200` means Meta accepted the message; delivery follows on your [webhooks](https://wa.genuka.com/en/docs/webhooks).
Your messaging limit shows in WhatsApp Manager, under **Account tools > Messaging limits**
([Meta](https://developers.facebook.com/documentation/business-messaging/whatsapp/messaging-limits)).
`GET /api/v1/numbers?refresh=true` also returns a `messagingLimitTier` per number, as an indication
only: it comes from a field Meta has deprecated and can be empty.

## What does business verification unlock?

### One-time passcodes (authentication templates)

This is the limit people find out about last. On the WhatsApp accounts connected to Genuka WA, we
observe that:

* creating an `AUTHENTICATION` template for an unverified business fails with the Graph message
  "Application does not have permission for this action". The message blames the app; the cause
  is the client's business;
* the account's health status then carries error `141010`, "The Business has not passed business
  verification" (`health_status` field, [Meta docs](https://developers.facebook.com/documentation/business-messaging/whatsapp/support/health-status));
* `MARKETING` and `UTILITY` templates on the same account go through normally.

That observation covers unverified businesses still at the 250 limit. The rule as 360dialog,
another Meta partner, documents it is broader: complete one of Meta's scaling paths (verification
by Meta or by the partner, for example) and have a messaging limit of at least 2,000
([360dialog, Authentication messages](https://docs.360dialog.com/docs/resources/authentication-messages)).
Business verification is the most direct path, not the only one.

The WhatsApp account's `business_verification_status` field says so too
([Meta reference](https://developers.facebook.com/documentation/business-messaging/whatsapp/reference/whatsapp-business-account/whatsapp-business-account-api)).
With Genuka you never handle a Meta token: check the verification state in Meta Business Suite, on
the portfolio that owns your WhatsApp account. Once the business is verified, the
[OTP from Node.js guide](https://wa.genuka.com/en/docs/guides/whatsapp-otp-nodejs) takes over.

### Higher limits

Verifying the business is one of the three paths Meta offers to go from 250 to 2,000 unique
recipients per 24 hours. Beyond that, the limit rises on its own (10,000, 100,000, then unlimited)
as long as your messages stay high quality and you use at least half of your limit over 7 days
([Meta, Messaging limits](https://developers.facebook.com/documentation/business-messaging/whatsapp/messaging-limits)).
Verification also takes you from 2 to 20 registered numbers on the portfolio; Meta raises that cap
the same way once your portfolio reaches the 2,000 messaging limit
([Meta, Business phone numbers](https://developers.facebook.com/documentation/business-messaging/whatsapp/business-phone-numbers/phone-numbers)).

### Can I go past 250 without verification?

Yes. Meta accepts another path: deliver 2,000 messages outside the customer service window to
unique recipients over a moving 30 days, using templates with a high quality rating (same page).
With a limit of 250 per 24 hours, that takes at least 8 days of near-maximum sending. Meta also
lists a third path: having the partner who onboarded you verify your business.

Verification itself starts in Meta Business Suite, on the portfolio that owns your WhatsApp
account: follow [Meta's official procedure](https://www.facebook.com/business/help/2058515294227817).

## What about unofficial WhatsApp APIs (QR code, WhatsApp Web)?

Some services promise a "WhatsApp API without Meta": you scan a QR code as you would for WhatsApp
Web, and their server drives your ordinary WhatsApp account. There is indeed no Meta onboarding,
no verification and no template. But:

* **It breaks WhatsApp's terms.** They forbid bulk messaging and auto-messaging, unauthorized
  access to the services, including through automated means, and building software or APIs that
  work substantially like WhatsApp's services for third parties
  ([WhatsApp Terms of Service](https://www.whatsapp.com/legal/terms-of-service)).
* **The number can be suspended at any time.** WhatsApp may suspend or terminate access that
  violates its terms (same page), and the WhatsApp Business policy explicitly targets messaging
  people at scale in an unauthorized manner
  ([WhatsApp Business Messaging Policy](https://whatsappbusiness.com/policy/)). The number at stake
  is often the one your customers know.
* **The official platform's tools are missing.** No approved templates to re-engage a customer
  outside the 24-hour window, no marketing opt-out signal forwarded by Meta.

The detailed comparison lives at [Unofficial WhatsApp APIs](https://wa.genuka.com/en/docs/compare/unofficial-whatsapp-apis).

## Which path should I choose?

| What you need                                                                                            | The path                                                                                                  |
| -------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------- |
| Notifications, confirmations, reminders, campaigns: up to 250 unique recipients a day outside the window | Cloud API through Genuka, no verification                                                                 |
| Sending OTP codes                                                                                        | Cloud API through Genuka, once you clear one of Meta's scaling paths (business verification, in practice) |
| Reaching more than 250 people a day outside the window from day one                                      | Business verification                                                                                     |
| Keeping your WhatsApp Business app on the same number                                                    | [Coexistence](https://wa.genuka.com/en/docs/guides/coexistence)                                                                |
| Automating a personal WhatsApp account                                                                   | No path that complies with WhatsApp's terms                                                               |

## FAQ

### Can I send OTP codes without business verification?

Not until your portfolio has cleared one of Meta's scaling paths. An unverified business at the
250 limit is refused the authentication template that carries the code, with error `141010` in the
account's health status. Business verification is the most direct path, not the only one.
Marketing and utility templates stay available in the meantime.

### Why does Meta answer "Application does not have permission for this action"?

On an `AUTHENTICATION` template, it is the symptom of an unverified business, not of a token or
app problem. Genuka then returns `403 meta_rejected`, with Meta's message and its identifiers
(`meta.code`, `meta.traceId`). Check the verification status in Meta Business Suite, on the
portfolio that owns your WhatsApp account. If you have your own Graph API access, the WhatsApp
account's `business_verification_status` and `health_status` fields say so too.

### Do I need to become a Tech Provider myself to use the API?

No. Genuka is a Tech Provider: you connect your number through Meta's Embedded Signup and call
Genuka's REST API with an API key, with no Meta token to manage.

### How long does it take to go from 250 to 2,000 recipients without verification?

At least 8 days: you need 2,000 messages delivered outside the window to unique recipients over
30 days, with high-quality templates, and the starting limit is 250 per 24 hours.

### Can my number get banned on the official API?

Not for using the API as such. Meta does rate-limit a number whose quality stays low
([Meta, Get opt-in](https://developers.facebook.com/documentation/business-messaging/whatsapp/getting-opt-in))
and restricts an account that violates its policies (errors `368` / `131031`). Message people who
agreed to hear from you.

## Sources

* Meta — [WhatsApp Business Platform changelog](https://developers.facebook.com/documentation/business-messaging/whatsapp/changelog)
* Meta — [Messaging limits](https://developers.facebook.com/documentation/business-messaging/whatsapp/messaging-limits)
* Meta — [Business phone numbers](https://developers.facebook.com/documentation/business-messaging/whatsapp/business-phone-numbers/phone-numbers)
* Meta — [Template fundamentals](https://developers.facebook.com/documentation/business-messaging/whatsapp/templates/overview)
* Meta — [Official Business Accounts](https://developers.facebook.com/documentation/business-messaging/whatsapp/official-business-accounts/)
* Meta — [Embedded Signup](https://developers.facebook.com/documentation/business-messaging/whatsapp/embedded-signup/overview/)
* Meta — [Partners (Tech Providers and Solution Partners)](https://developers.facebook.com/documentation/business-messaging/whatsapp/solution-providers/overview)
* Meta — [Health status](https://developers.facebook.com/documentation/business-messaging/whatsapp/support/health-status)
* Meta — [WhatsApp Business Account API](https://developers.facebook.com/documentation/business-messaging/whatsapp/reference/whatsapp-business-account/whatsapp-business-account-api)
* Meta — [Error codes](https://developers.facebook.com/documentation/business-messaging/whatsapp/support/error-codes)
* Meta — [Get opt-in for WhatsApp](https://developers.facebook.com/documentation/business-messaging/whatsapp/getting-opt-in)
* Meta — [Verify your business in Meta Business Suite](https://www.facebook.com/business/help/2058515294227817)
* 360dialog — [Authentication messages](https://docs.360dialog.com/docs/resources/authentication-messages)
* WhatsApp — [Terms of Service](https://www.whatsapp.com/legal/terms-of-service)
* WhatsApp — [Business Messaging Policy](https://whatsappbusiness.com/policy/)
