ChatBridge24

SETUP, END TO END

Documentation

Everything between creating an account and sending your first approved template, in the order it actually happens — including the three steps that are decided by Meta rather than by us, and how long each of those usually takes.

Read this once before you start. Three of the steps below are Meta’s decisions rather than ours — verifying a number, approving a display name and approving a template — and knowing which three stops a wait looking like a fault.

1 · Create a workspace

An account on our own portal. No CRM required to get this far.

Sign up with an email address and a password. A workspace holds your connected numbers, your colleagues and your subscription; a colleague is invited with a role rather than a number of their own, because the subscription is per connected number and there is no seat charge to ration.

If you work inside a supported CRM you can install the app there instead, and the workspace is created for you as part of the install.

2 · Connect a WhatsApp Business number

Through Meta’s own flow, on your own business portfolio.

01

Have the number ready

It must be a number you control that can receive an SMS or a voice call, and it must not be active in the WhatsApp or WhatsApp Business app. A number already live with another provider is a migration rather than a new connection — see step 3.

02

Run the embedded flow

A window of Meta’s opens, you sign in with the Facebook account that owns (or will own) the business portfolio, and you pick or create the WhatsApp Business Account the number will live on. The account and the number stay yours throughout.

03

Finish it in the app

If the number still needs registering we ask for the six-digit two-step PIN. If the number has never been verified, we ask Meta to text or call it and you type the code. Both steps are shown as what they are rather than as a generic error.

3 · If the number is already with another provider

It is a migration, and two things must be true first.

Turn off two-step verification at the current provider, then run the same connect flow choosing the destination account. The display name, the quality rating, the messaging limits and the approved templates travel with the number.

One precondition is easy to miss: if the current provider stores your messages in a particular region, that setting travels too and has to be set on the destination before the number can be registered. We read Meta’s own refusal, set the region it names and try once more — so the usual symptom is a short delay rather than a dead end.

4 · Get the display name approved

Meta reviews the name your customers will see. We do not.

The display name is reviewed against Meta’s own policy and the result is a state on the number: approved, under review, or rejected with a reason. A number can send while the name is still under review.

Two states are routinely misread. A code verification that reads as expired is normal on a number that was verified a while ago — it describes the one-time code, not the number. And business verification is not the blue tick: the tick is a separate, rarer grant, and this product only ever shows one where Meta itself shows one.

5 · Get a template approved

Required for anything outside the free-text window.

Build the template in the app, submit it, and watch the review. Approval is Meta’s and usually arrives in minutes, though it can take longer. A rejected template comes back with Meta’s own reason attached.

One mechanism is worth understanding before you build a template with a picture in its header: the file you upload at build time and the file identifier used at send time are two different objects at Meta, and the second cannot be derived from the first. That is why we keep the bytes you uploaded — and why a template built outside this app can still be sent, because we adopt the sample Meta itself approved.

6 · Wire it to where your team works

Our inbox, your CRM, your own software — or more than one.

  • Our workspace needs no wiring: invite the people who answer the number. What that includes.
  • A supported CRM is installed from its own marketplace and then binds the number to a channel. Registrations re-assert themselves, because a CRM can delete a registered step on an app update. How the Bitrix24 connector works.
  • Your own software uses a scoped API key and a webhook endpoint. The API and webhooks.

7 · Call the API

One key, one endpoint of yours, one required header.

Create a key in the app, give it only the scopes it needs, and store it as a secret — it is shown once and kept as a hash, so it cannot be read back out of our database by anybody.

Every send requires an idempotency key. That is not a convention here, it is enforced: a send without one is refused, because a retried send is a real message to a real person and a real charge. Register a webhook endpoint for inbound messages and delivery state, and verify the signature over the raw body before you parse it.

Questions that come up during setup

How long does the whole thing take?
The parts we control are minutes. The parts Meta controls — verifying the number, approving the display name, approving the first template — are the ones that set the pace, and each is shown as a state on the number rather than as a spinner.
Can I use a number that is in the WhatsApp app on somebody’s phone?
Not while it is. A number on the official transport cannot also be a personal WhatsApp account; it has to be deleted from the app first, or you connect a different number.
Do I need a Facebook Page?
You need a Meta business portfolio, which the embedded flow will create if you do not have one. The portfolio and the WhatsApp Business Account stay yours.
What happens to my messages if we stop paying?
The number stops sending and the data is deleted thirty days after the account is closed or the app is uninstalled, automatically. How deletion works.

Reference

The REST API and webhooks

Keys, scopes, the required idempotency key and the webhook queue.

WhatsApp Business API, explained

What the official transport is and what it is not.

How we protect your data

Where everything is stored, who can reach it, and for how long.