WaMCP

Embed Signup

Let clients connect their own WhatsApp Business accounts via Facebook's embedded signup flow

Embed signup lets you onboard clients without needing their WABA credentials directly. Instead, you share a link that opens a Facebook-hosted flow where they authorize the connection.

Flow

  1. Create a pending client (no WABA fields)
  2. Generate a signed signup link
  3. Share the link with your client
  4. Client completes the Facebook embedded signup
  5. The platform exchanges the FB code for an access token and registers the webhook automatically

1. Create a Pending Client

const res = await fetch('https://wapi.lintech.live/api/clients/', {
  method: 'POST',
  headers: { 'Authorization': 'Bearer wamcp_your_key', 'Content-Type': 'application/json' },
  body: JSON.stringify({ display_name: 'My Client Store', external_id: 'your-internal-id' }),
});
const client = await res.json(); // client.id used in next step

Response includes the client id with signup_status: "pending".

// Standard
const res = await fetch(`https://wapi.lintech.live/api/clients/${clientId}/signup-link`, {
  headers: { 'Authorization': 'Bearer wamcp_your_key' },
});
const { url, sig } = await res.json();

// With catalog permissions
const resCatalog = await fetch(`https://wapi.lintech.live/api/clients/${clientId}/signup-link?catalog=true`, {
  headers: { 'Authorization': 'Bearer wamcp_your_key' },
});
Response
{
  "url": "https://wapi.lintech.live/embed/signup/{id}?sig=hmac...",
  "sig": "hmac_signature"
}

The link is HMAC-signed — only requests with a valid signature can complete the signup.

The catalog=true variant appends &catalog=true to the URL and uses a separate Meta app configuration that requests catalog access permissions during the OAuth flow.

3. Client Completes Signup

When the client opens the link, they see a "Connect with WhatsApp" button that launches the Meta embedded signup flow. After completing it, the platform:

  • Exchanges the Facebook auth code for an access token via the System User Access Token flow
  • Registers the phone number with WhatsApp using the Phone Numbers API
  • Updates the client with WABA ID, phone number ID, catalog ID, and Meta business ID
  • Registers the webhook listener

The client's signup_status changes from pending to completed.

In the Clients table, every row has a link icon button with two options:

  • Copy Signup Link — standard flow, WhatsApp Business setup only
  • Signup Link (catalog) — includes catalog management permissions

What the Flow Returns

The embedded signup WA_EMBEDDED_SIGNUP postMessage delivers:

{
  "type": "WA_EMBEDDED_SIGNUP",
  "event": "FINISH",
  "data": {
    "phone_number_id": "1234567890",
    "waba_id": "0987654321",
    "catalog_ids": ["111222333"],
    "business_id": "444555666"
  }
}

The Facebook login callback provides a short-lived code which is exchanged for a token via the OAuth Access Token endpoint.

Reference

Meta — Embedded Signup

Redirect URLs

Set success_redirect_url and failure_redirect_url on a client (at registration, via PATCH /api/clients/{id}, or in the dashboard's Edit Client sheet) to send the customer back to your app after the hosted signup page finishes.

On success, the customer lands on success_redirect_url with these query parameters:

ParameterDescription
client_idThe client UUID
waba_idWhatsApp Business Account ID
phone_number_idMeta phone number ID
catalog_idCatalog ID (catalog flow only)
meta_business_idMeta Business ID
signup_statusAlways completed

On failure or cancellation, the customer lands on failure_redirect_url with client_id, status=failed, and an error parameter.

The signup_completed webhook fires regardless of redirects — treat the webhook as the source of truth and the redirect as UX.

Signup links expire after 30 days by default. Pass expires_in_days (1–365) to GET /api/clients/{id}/signup-link to change this; the response includes expires_at (unix timestamp). The expiry is covered by the HMAC signature, so it cannot be tampered with. Links generated before expiry support remain valid.

On this page