The official API vs. unofficial tools, and why this is the decision that matters most
There are two kinds of connection between WhatsApp and a CRM. The first is Meta's official WhatsApp Business Platform, which requires a business verification process but is the sanctioned route. The second is unofficial tools that emulate the WhatsApp protocol without going through the official API, usually cheaper and faster to get running.
Meta's policy explicitly states that unauthorized access at scale, meaning messaging people through a service that doesn't operate under their terms or policies, entitles Meta to limit or remove access to WhatsApp Business Services. This isn't a footnote; it's the foundation the rest of the policy rests on.
The real risk: account lockout, not just a warning
Meta operates a graduated enforcement model. A first violation typically brings a warning or a temporary block of up to 30 days that prevents sending marketing or utility messages. Repeated violations lead to an 'account lock,' an indefinite block on sending any message that can only be lifted through a formal appeal, and if the business keeps ignoring the warnings, the account can be permanently disabled.
Unofficial tools expose you to exactly this risk precisely because they don't pass through the official API's verification mechanisms. If a WhatsApp Business account also serves as a real customer-service channel, locking it doesn't just hurt a marketing campaign, it stops all customer communication through that channel until the appeal is resolved.
Pricing: a model that already changed once, and keeps changing
Until July 2025, Meta billed by 'conversation,' a 24-hour window in which any number of messages could be sent for one flat fee. Starting July 1, 2025, the model shifted to per-message billing: every template message sent is billed individually, based on the recipient's country and the message category.
| Category | When it's billed (as of now) |
|---|---|
| Marketing | Always billed when sent outside an open service window |
| Utility | Billed outside the service window; free inside an open service window |
| Authentication | Billed outside the service window; free inside an open service window |
| Service (regular replies) | Free for all businesses, as of now |
When an automated message is right, and when it's spam
Before any message, Meta requires explicit opt-in from the recipient, which identifies the business by name and clearly states that the person agrees to receive messages from it. A general consent isn't enough to cover every message category; the official recommendation is to get separate consent per category, for example order updates versus marketing messages, or at minimum to offer a clear way to opt out of a specific category without leaving the whole channel.
Meta also tracks quality metrics and rate-limits businesses whose quality stays low over time, and users can block or report a business that floods them. In practice, this means a correct automated message is one the recipient expected and consented to in advance, not every message that's technically possible to send.
Privacy: what it actually means that the channel belongs to Meta
The WhatsApp Business API isn't a fully private channel from a business standpoint. Messages sent through the API pass through Meta's infrastructure and often also through an approved Business Solution Provider (BSP) that connects the business to the API, rather than staying strictly between the business and the customer the way a regular in-app chat does. Any data collected through the channel, including phone numbers and message content, is subject to the business's privacy policy and to applicable law, exactly like any other data-collection channel.
How I approach this
In every WhatsApp integration I build, the starting point is the official API only, even if that means a slower business-verification process up front. After that, we look together at which messages are actually worth automating, like status updates or reminders the customer expects, versus what should stay a human conversation so the channel's quality and the customer's trust don't erode.
