Meta App Review & Integration
WhatsApp Business Integration & Permissions Guide
Effective ·Meta Tech Provider Architecture
1. Application Purpose
Our platform enables businesses to connect their official WhatsApp Business Account (WABA) with our customer support inbox (Chatwoot Core). This allows customer support teams to manage customer inquiries collaboratively, assign incoming conversations to agents, and maintain conversation continuity.
2. Meta Permissions Requested & Justification
whatsapp_business_management
Why it is needed: During Embedded Signup, our platform uses this permission to:
- Enumerate the customer's WhatsApp Business Accounts (WABAs) and associated phone numbers.
- Subscribe our webhook endpoint to the customer's WABA (
POST /{waba_id}/subscribed_apps) to receive incoming customer messages. - Fetch WhatsApp business profile metadata (verified name, business hours, profile picture) to populate the Chatwoot inbox settings.
whatsapp_business_messaging
Why it is needed: This core messaging permission is essential to:
- Receive real-time incoming messages and media sent by consumers to the business's WhatsApp number.
- Send outbound customer support agent replies through the WhatsApp Cloud API (
POST /{phone_number_id}/messages). - Receive delivery receipts (delivered, read, failed) to update message delivery statuses in real-time.
3. Onboarding Workflow
- Business Registration: The business admin visits our Onboarding Portal and enters their organization name and admin email.
- Meta Embedded Signup Dialog: The user clicks "Connect WhatsApp with Meta", launching the official Meta Facebook Login modal configured with WhatsApp Embedded Signup (
config_id). - Business Portfolio & Number Selection: Within Meta's dialog, the user selects their Meta Business Portfolio, creates or selects their WABA, and verifies their phone number via SMS/voice OTP.
- Token Exchange: The client-side Facebook SDK passes the authorization
codeto our serverless endpoint (/api/onboard) to securely exchange it for a system user token. - Webhook Registration: Our backend subscribes to the customer's WABA via Meta Graph API.
- Chatwoot Workspace Provisioning: Our backend calls Chatwoot Platform API to provision a dedicated account and configured WhatsApp inbox.
4. Data Protection & Security Architecture
- Isolated Tenancy: Message content is strictly segregated by Chatwoot account ID and accessible only to authorized agents.
- Encrypted Transport: Webhook payloads from Meta Cloud API are transmitted over HTTPS with TLS 1.3 and validated using Meta's
X-Hub-Signature-256HMAC signature. - Self-Service Erasure: Clients can disconnect the app at any time via Facebook Business Integrations or submit an erasure ticket via our Data Deletion Portal.
