This account was set up with a temporary password. Choose your own before continuing — whoever created the account knows the current one.
Two-step verification is required. Scan this with Google Authenticator, Microsoft Authenticator or any similar app, then enter the code it shows.
Can't scan? Type this key in by hand:
Country code first. Spaces, dashes and + are fine — they're stripped.
If this number hasn't replied to you in the last 24 hours, WhatsApp will reject plain text. You'll be told if that happens and can switch to a template.
Templates are the only thing WhatsApp accepts outside the 24-hour window.
Set up under Auto-replies and sent exactly as configured. To reach a number that hasn't messaged you in the last 24 hours, pick one marked Template — WhatsApp rejects the other kinds there, and you'll be told if that happens.
Agents work the inbox. Admins do that too, and manage these accounts. Disabling keeps someone's history but blocks sign-in.
Share this with them over a private channel — they can't change it themselves yet.
Sign-ins, account changes and messages sent or deleted. Message text is never recorded here — only that a message was sent, and to whom.
Answers sent without an agent. Rules are tried in order — a tapped button first, then a typed word, then the catch-all. Replies go out as plain text, which is all that's needed: a guest who just messaged has an open 24-hour window.
Always allowed here — the rule is answering a message the guest just sent, so their 24-hour window is open. The payload is what a tap sends back, so it's what another button rule would match on.
Up to ten. A tap comes back the same as a button tap, so another button rule matching the payload is what answers it.
A template isn't needed to reach the guest — they just messaged, so the window is open. It's how you send buttons, which is what turns a reply into a menu.
0 sends every time. Worth setting for the catch-all, so someone typing three lines doesn't get three identical replies.
Rules as a JSON file, so a whole menu can be written up elsewhere and loaded in one go. Checking a file changes nothing — it reports what would happen, including any button pointing at a payload no rule answers.
Shows which rule would answer, without sending anything.
The WhatsApp number this inbox sends and receives on. Most of the time there's nothing to do here — it matters when setting the number up, moving it to a new deployment, or after Meta asks you to verify it again.
Meta sends a 6-digit code to the number itself. Only needed when it isn't verified yet.
Binds the number to this app. Needs the number's two-step PIN — if it has never had one, pick six digits and keep them somewhere safe. The PIN is sent to Meta and is not stored here.
Releases the number from the Cloud API. Nothing sends or arrives until it is registered again. You'll be asked to confirm.
The messages set up under Auto-replies, sent exactly as configured — wording, buttons and menus already in place. Anything with buttons or a menu only works inside the guest's 24-hour window.
An authenticator app on your phone generates a 6-digit code that changes every 30 seconds. It needs no signal and no email — the app and this server just agree on the time.
Scan this with Google Authenticator, Microsoft Authenticator, or any similar app.
Can't scan? Type this key in by hand:
On. You'll be asked for a code from your authenticator app each time you sign in. Turning it off needs your password.