Embed Signup
Let clients connect their own WhatsApp Business accounts via Facebook's embedded signup flow
Embed signup lets you onboard clients without needing their WABA credentials directly. Instead, you share a link that opens a Facebook-hosted flow where they authorize the connection.
Flow
- Create a pending client (no WABA fields)
- Generate a signed signup link
- Share the link with your client
- Client completes the Facebook embedded signup
- The platform exchanges the FB code for an access token and registers the webhook automatically
1. Create a Pending Client
const res = await fetch('https://wapi.lintech.live/api/clients/', {
method: 'POST',
headers: { 'Authorization': 'Bearer wamcp_your_key', 'Content-Type': 'application/json' },
body: JSON.stringify({ display_name: 'My Client Store', external_id: 'your-internal-id' }),
});
const client = await res.json(); // client.id used in next stepResponse includes the client id with signup_status: "pending".
2. Get the Signup Link
// Standard
const res = await fetch(`https://wapi.lintech.live/api/clients/${clientId}/signup-link`, {
headers: { 'Authorization': 'Bearer wamcp_your_key' },
});
const { url, sig } = await res.json();
// With catalog permissions
const resCatalog = await fetch(`https://wapi.lintech.live/api/clients/${clientId}/signup-link?catalog=true`, {
headers: { 'Authorization': 'Bearer wamcp_your_key' },
});{
"url": "https://wapi.lintech.live/embed/signup/{id}?sig=hmac...",
"sig": "hmac_signature"
}The link is HMAC-signed — only requests with a valid signature can complete the signup.
The catalog=true variant appends &catalog=true to the URL and uses a separate Meta app configuration that requests catalog access permissions during the OAuth flow.
3. Client Completes Signup
When the client opens the link, they see a "Connect with WhatsApp" button that launches the Meta embedded signup flow. After completing it, the platform:
- Exchanges the Facebook auth code for an access token via the System User Access Token flow
- Registers the phone number with WhatsApp using the Phone Numbers API
- Updates the client with WABA ID, phone number ID, catalog ID, and Meta business ID
- Registers the webhook listener
The client's signup_status changes from pending to completed.
4. Copy Link from Dashboard
In the Clients table, every row has a link icon button with two options:
- Copy Signup Link — standard flow, WhatsApp Business setup only
- Signup Link (catalog) — includes catalog management permissions
What the Flow Returns
The embedded signup WA_EMBEDDED_SIGNUP postMessage delivers:
{
"type": "WA_EMBEDDED_SIGNUP",
"event": "FINISH",
"data": {
"phone_number_id": "1234567890",
"waba_id": "0987654321",
"catalog_ids": ["111222333"],
"business_id": "444555666"
}
}The Facebook login callback provides a short-lived code which is exchanged for a token via the OAuth Access Token endpoint.
Reference
Redirect URLs
Set success_redirect_url and failure_redirect_url on a client (at registration, via PATCH /api/clients/{id}, or in the dashboard's Edit Client sheet) to send the customer back to your app after the hosted signup page finishes.
On success, the customer lands on success_redirect_url with these query parameters:
| Parameter | Description |
|---|---|
client_id | The client UUID |
waba_id | WhatsApp Business Account ID |
phone_number_id | Meta phone number ID |
catalog_id | Catalog ID (catalog flow only) |
meta_business_id | Meta Business ID |
signup_status | Always completed |
On failure or cancellation, the customer lands on failure_redirect_url with client_id, status=failed, and an error parameter.
The signup_completed webhook fires regardless of redirects — treat the webhook as the source of truth and the redirect as UX.
Link Expiry
Signup links expire after 30 days by default. Pass expires_in_days (1–365) to GET /api/clients/{id}/signup-link to change this; the response includes expires_at (unix timestamp). The expiry is covered by the HMAC signature, so it cannot be tampered with. Links generated before expiry support remain valid.