AllyOneCRM / Connect WhatsApp

Connect WhatsApp

AllyOneCRM connects numbers via Embedded Signup — Meta's official flow. You never paste an access token manually.

1. Fetch the widget configuration

GET/v1/waba-accounts/embedded-signup/config

Requires authentication (user session or API key) — your backend passes appId and configId to the frontend, which initializes Meta's JavaScript SDK.

{ "enabled": true, "appId": "...", "configId": "..." }

2. Run the Embedded Signup

The end user logs in through Meta's official widget (FB.login) directly on your screen — AllyOne never sees their Meta account password. At the end, the widget returns an authorization code.

3. Exchange the code for the connection

POST/v1/waba-accounts/embedded-signup/exchange
{
  "code": "AQC8k2...",
  "wabaId": "1058...",
  "phoneNumberId": "1049..."
}

What happens in this call, on the server side:

  • The code is exchanged for a long-lived access token directly on Meta's Graph API.
  • The number's verified metadata (display name, quality, messaging limit) is fetched and saved.
  • The app is automatically subscribed to that number's webhooks — no manual step to configure a webhook in the Meta App.
  • The token is encrypted before being persisted.
One number, one tenant

Each waba_id/phone_number_id can only be connected to one tenant at a time — the API rejects an attempt to connect a number already linked to another account.

24-hour window

This behavior comes straight from Meta's Cloud API; it is not an AllyOne rule:

SituationWhat can be sent
Contact replied in the last 24hFree text, media, buttons — any content
Outside the 24h windowOnly Meta pre-approved Templates
Connect WhatsApp — AllyOneCRM