AllyOneCRM / Connect WhatsApp
Connect WhatsApp
AllyOneCRM connects numbers via Embedded Signup — Meta's official flow. You never paste an access token manually.
1. Fetch the widget configuration
GET/v1/waba-accounts/embedded-signup/config
Requires authentication (user session or API key) — your backend passes appId and configId to the frontend, which initializes Meta's JavaScript SDK.
{ "enabled": true, "appId": "...", "configId": "..." }
2. Run the Embedded Signup
The end user logs in through Meta's official widget (FB.login) directly on your screen — AllyOne never sees their Meta account password. At the end, the widget returns an authorization code.
3. Exchange the code for the connection
POST/v1/waba-accounts/embedded-signup/exchange
{
"code": "AQC8k2...",
"wabaId": "1058...",
"phoneNumberId": "1049..."
}
What happens in this call, on the server side:
- The
codeis exchanged for a long-lived access token directly on Meta's Graph API. - The number's verified metadata (display name, quality, messaging limit) is fetched and saved.
- The app is automatically subscribed to that number's webhooks — no manual step to configure a webhook in the Meta App.
- The token is encrypted before being persisted.
One number, one tenant
Each waba_id/phone_number_id can only be connected to one tenant at a time — the API rejects an attempt to connect a number already linked to another account.
24-hour window
This behavior comes straight from Meta's Cloud API; it is not an AllyOne rule:
| Situation | What can be sent |
|---|---|
| Contact replied in the last 24h | Free text, media, buttons — any content |
| Outside the 24h window | Only Meta pre-approved Templates |
