Unofficial WhatsApp APIs over QR code: the real risks
What an unofficial WhatsApp API is, why it breaks Meta terms, what happens when the number is disabled, and how it compares to the official Cloud API.
Updated September 2, 2026
An unofficial API is any solution that automates ordinary WhatsApp by pretending to be a linked device: you scan a QR code, a server keeps the session open and sends messages on your behalf. There is no agreement with Meta, no registered account and no published rules — and that is exactly where the risk sits.
Why it breaks the terms
WhatsApp's terms allow automation only through the official interfaces. Keeping a device session open on a server to send messages at scale is unauthorised use, and Meta treats it as such: when the pattern is detected, the number is disabled.
This is not a theoretical threat. Detection looks at behaviour — volume, cadence, block rate, known library fingerprints — and does not need anyone to report you.
What you lose when the number goes down
A ban gives nothing back. Gone with it:
- the number, usually printed on cards, the website, ads and the storefront;
- the history of the conversations, if it only ever lived inside that tool;
- the trust of everyone who had the contact saved;
- the time it takes to rebuild all of it on a new number, from scratch.
And there is no appeal: with no registered account, there is no support channel to reverse it.
What the unofficial route does not deliver
| Unofficial API (QR) | Official Cloud API | |
|---|---|---|
| Agreement with Meta | none | yes, registered account |
| Risk of being disabled | high, without warning | tied to message quality |
| Meta support | none | yes |
| Business verification | no | yes |
| Business account badge | no | yes, after verification |
| Approved templates | no | yes |
| Quality metrics | no | yes, per number and per template |
| Continuity when changing vendor | none | the WABA and the number are yours |
"But it is cheaper"
The honest comparison is not between a tool's monthly fee and Meta's per-message price. It is between a predictable cost and losing the channel.
It also helps to remember that on the official API, support inside the 24-hour window is not charged by Meta. Operations that answer fast and use templates only when there is a fact to communicate spend far less than the back-of-napkin estimate suggests.
How to migrate without losing the number
The path is the same as day one on the official API: disconnect the unofficial sessions, free the number and connect it through Meta's embedded signup. If the number lives in the WhatsApp Business app today, coexistence lets the app keep working while the operation migrates.
Migrating before a problem is always cheaper than migrating after — after, it is usually with a different number.
Still have a question?
The FAQ covers pricing, Meta rules, team roles and agent access. The technical documentation is public and any AI agent can read it.