Build and operate
Testing your integration
Test safely before you go live.
In a nutshell
Use a test key (sk_test_). It works on sandbox businesses, whose WhatsApp is simulated end to end - connect, send, receive, statuses, callbacks - without Meta. Then test the failure paths on purpose.
The sandbox
A test key (sk_test_...) works on sandbox businesses only - a separate set from
your live ones, created the usual way with POST /businesses.
Their WhatsApp is simulated: nothing reaches Meta or anyone's phone.
- Connect. Create a connect link and open it: the page connects a simulated account in one click, with a number and approved templates (
fee_reminder,welcome), and sendswhatsapp.connection. - Receive. Simulate an incoming message - it creates the contact and conversation and sends
message.received, as live. - Send. Send text (inside the window) or templates as usual. Messages are
sentat once; to a number ending in0001they fail with131026, like a number not on WhatsApp. - Deliver. Simulate a delivery status -
delivered,readorfailed- and getmessage.status.
Callbacks from sandbox businesses carry "sandbox": true. Templates you create in the
sandbox are approved at once.
Staging with a real number
- Ask for a staging product. A PaalChat operator creates it and gives you a token with the abilities you need.
- Connect a test number. Meta gives every app a test WhatsApp number that can message up to five verified recipients. Connect it through the normal connect link.
- Expose your callback endpoint. Run your app locally behind an HTTPS tunnel and ask the operator to set that URL as the staging callback URL.
- Import the Postman collection. Download it, set
tokenandexternal_id, and callGet product.
Note
With a live key and Meta's test number, messages are real WhatsApp messages, so only use numbers you control.
Test these paths on purpose
-
GET /meshows every ability your code uses. - Creating the same business twice returns
201then200. - Free-form text to a number that has not messaged you returns
422 outside_service_window, and your app offers a template. - A send to a number that is not on WhatsApp ends as
message.statusfailedwith code131026. - Sending the same
referencetwice returns202then200, and only one message arrives. - Your callback endpoint answers
401to a bad signature and to a signature older than 5 minutes. - Delivering the same callback twice changes nothing the second time.
- A
whatsapp.connectiondisconnectedcallback disables WhatsApp features in your app.