Guides

Unofficial WhatsApp APIs over QR code: the real risks

What an unofficial WhatsApp API is, why it breaks Meta terms, what happens when the number is disabled, and how it compares to the official Cloud API.

Updated September 2, 2026

An unofficial API is any solution that automates ordinary WhatsApp by pretending to be a linked device: you scan a QR code, a server keeps the session open and sends messages on your behalf. There is no agreement with Meta, no registered account and no published rules — and that is exactly where the risk sits.

Why it breaks the terms

WhatsApp's terms allow automation only through the official interfaces. Keeping a device session open on a server to send messages at scale is unauthorised use, and Meta treats it as such: when the pattern is detected, the number is disabled.

This is not a theoretical threat. Detection looks at behaviour — volume, cadence, block rate, known library fingerprints — and does not need anyone to report you.

What you lose when the number goes down

A ban gives nothing back. Gone with it:

  • the number, usually printed on cards, the website, ads and the storefront;
  • the history of the conversations, if it only ever lived inside that tool;
  • the trust of everyone who had the contact saved;
  • the time it takes to rebuild all of it on a new number, from scratch.

And there is no appeal: with no registered account, there is no support channel to reverse it.

What the unofficial route does not deliver

Unofficial API (QR) Official Cloud API
Agreement with Meta none yes, registered account
Risk of being disabled high, without warning tied to message quality
Meta support none yes
Business verification no yes
Business account badge no yes, after verification
Approved templates no yes
Quality metrics no yes, per number and per template
Continuity when changing vendor none the WABA and the number are yours

"But it is cheaper"

The honest comparison is not between a tool's monthly fee and Meta's per-message price. It is between a predictable cost and losing the channel.

It also helps to remember that on the official API, support inside the 24-hour window is not charged by Meta. Operations that answer fast and use templates only when there is a fact to communicate spend far less than the back-of-napkin estimate suggests.

How to migrate without losing the number

The path is the same as day one on the official API: disconnect the unofficial sessions, free the number and connect it through Meta's embedded signup. If the number lives in the WhatsApp Business app today, coexistence lets the app keep working while the operation migrates.

Migrating before a problem is always cheaper than migrating after — after, it is usually with a different number.

Still have a question?

The FAQ covers pricing, Meta rules, team roles and agent access. The technical documentation is public and any AI agent can read it.