Before you start
Three things decide how long this takes. Two of them you can start today.
Start business verification first
Meta reviews your business documents before it will let you message the public, and that review takes one to three days. It is the only step with a queue. Begin it now and do everything else while you wait.What to have ready
- A Meta Business account — free
- Your GST certificate or incorporation papers, for verification
- A phone number not already on WhatsApp — not on regular WhatsApp, not on WhatsApp Business. A fresh SIM, or a landline that can take one call
- A card, for Meta's message charges
- A web address this console can be reached at — see step 5. This is the one most people don't expect
Until WhatsApp is connected, nothing is real
The console works fully in practice mode. Messages are simulated, clearly badged, and never leave your computer — so you can learn every screen before a single customer sees anything.Connecting WhatsApp
Ten steps, in order — each depends on the one before it. Steps 1 to 4 happen in Meta, 5 is yours, 6 to 10 move between the two.
- 01
Start business verification1–3 days
In Meta Business Suite, go to Settings → Security Centre and begin verification. Upload your GST certificate or incorporation documents.
Until this clears, Meta only lets you message a small number of test recipients you add by hand. Everything below can be done while it's pending.
- 02
Get a phone number that isn't on WhatsApp
This is where most first attempts stall. The number cannot already be in use on regular WhatsApp or the WhatsApp Business app. If it is, you must delete that account first — and that erases its chat history.
Safest choice: a new SIM bought for this, or an office landline that can take one verification call.
- 03
Create the Meta app
At developers.facebook.com/apps, create an app and add the WhatsApp product to it. Then add and verify your phone number — Meta sends a code to it.
- 04
Create a permanent access token
The most common way this breaks
The token Meta shows you on the API Setup screen expires after 24 hours. Nothing on that page says so. Everything works today, and tomorrow every message fails.Go to Business settings → System users, create a system user, give it access to your WhatsApp account, and generate a token there. That one is permanent. Use it.
- 05
Give this console a public web address
Meta has to reach this app over the internet — that's how customer replies and delivery receipts arrive, and how WhatsApp fetches images and PDFs attached to your templates.
A
localhostaddress works perfectly on your own screen and is invisible to Meta. Skip this and you will be able to send, and will never receive a reply.Option Cost Best for Cloudflare Tunnel — a subdomain of a domain you own Free Anyone who already has a domain. Permanent, professional address. Quick tunnel — a temporary random address Free Trying it out. The address changes each restart. A small server ₹400–800/month Real use, where the console must never be off. Whatever you choose, something has to stay switched on. WhatsApp does not hold messages for you — if nothing answers when a customer writes, Meta retries for a while and then gives up. - 06
Copy five values into the console
Open Settings → WhatsApp Connection. Each field has a link that jumps straight to the Meta screen it comes from.
- Access tokenWhatsApp → API Setup — the permanent one from step 4
- Phone number IDSame screen. A long number, not your phone number
- Business account IDSame screen. Needed to submit templates
- App IDApp Settings → Basic. Needed for image, video and PDF headers
- App secretApp Settings → Basic. Proves messages really came from Meta
Also fill in Public address of this app — the address from step 5.
- 07
Set the webhook — and press Subscribe
In Meta, go to WhatsApp → Configuration → Webhooks and paste the two values the console shows on the same Settings screen: the callback URL and the verify token.
Then press Manage and tick “messages”
Saving the URL is not enough. If nobody ticksmessages, sending works perfectly and no customer reply ever arrives — with no error anywhere to tell you. - 08
Add a payment method
In Meta, go to Billing → Payment settings and add a card. Without one, sending stops once the free allowance is used.
- 09
Press “Run check”
On the same Settings screen. It tests six things separately — your details, your token, your number, your templates, your webhook subscription, and whether Meta can actually reach you — and names whichever one is wrong, with what to do about it.
- 10
Send yourself a real message
Type your own number and press Send test. If it arrives on your phone, sending works. Reply to it and watch the message appear in your inbox — that proves receiving works too.
This is the only step that proves the whole chain. Everything before it is an educated guess.
The Meta screens you'll need
- Business settings → Security CentreStart business verification. This is the step with a multi-day queue — begin it first.
- Your Meta appsCreate the app, or open the one you already made.
- WhatsApp → API SetupAccess token, Phone number ID and Business account ID are all on this page.
- App Settings → BasicYour App ID and App secret.
- Business settings → System usersCreate a permanent access token here. The one on API Setup expires in 24 hours.
- WhatsApp → ConfigurationSet the callback URL and verify token, then press Manage and tick "messages".
- Billing → Payment settingsAdd a card. Without one, sending stops once the free allowance is used.
Creating accounts
There are three ways an account comes into existence, and they suit different situations.
The very first account — the Owner
On a brand-new install, the first person to open the console sees a setup page instead of a login. They enter the business name, their name, their email and a password of at least ten characters.
That creates the first Owner and then permanently closes the setup page, so nobody can later create themselves an Owner account.
Create a second Owner the same day
There is no “forgot password” email in this console, and one Owner cannot reset another Owner's password. With only one Owner, a forgotten password locks you out of your own customer records. The console warns you while this is true.Adding someone yourself
Settings → Team Members → Add team member. Only an Owner can do this. You enter their name, email, a starting role and a password — the console suggests a good one.
The email and password are shown to you once. There is no invitation email; you pass the details on however you normally would.
When someone asks to join
Anyone can open the sign-in page and press “Need an account?”. They enter their name, email and an optional note.
Nothing is created at that moment. The request appears in Settings → Requests, where an Owner approves or declines it. Approving is what creates the account, and the console then shows a password to pass on — once.
Seats
Every workspace has a limit on how many people can sign in — Owners, Managers and Agents counted together. Deactivated people don't count, so you can keep a former employee's records without paying for the seat.
Only Sigma Tech India can change that limit. If you need more seats, ask.
The three roles
The role sets a sensible starting point. After that an Owner adjusts what each person can do, individually — because “Manager” means very different things at different businesses.
| Role | What they start with | Typically |
|---|---|---|
| Owner | Everything, always. Cannot be restricted. | You, and one other person you trust completely. |
| Manager | Build and send campaigns, approve others' campaigns, write and submit templates, manage groups, export contacts, change the bot and rules. Not WhatsApp credentials, and not roles. | Whoever runs the day-to-day and is accountable for spend. |
| Agent | Nothing beyond the inbox — replying, updating leads, leaving notes. Everything else must be granted deliberately. | Your sales desk. |
Adjusting an individual
On the Team screen, open “What [name] is allowed to do” under anyone. Each permission is a tick-box with a plain-English explanation, and the ones that spend money or delete things are marked.
The three campaign powers
Two tick-boxes produce exactly three outcomes, and the screen tells you which is in force:
| Ticked | What happens when they press send |
|---|---|
| Neither | Refused. They cannot build a campaign at all. |
| Build campaigns | It goes into the approval queue. Nothing is sent. |
| + Send without approval | It goes out immediately, and spends real money. |
Who approves what
The complete list. Anything not here needs no approval.
| Action | Who can do it | Notes |
|---|---|---|
| Create the very first Owner | Nobody — it's automatic | Only on a fresh install. The page closes for good afterwards. |
| Add a team member | Owner | Subject to the seat limit. |
| Approve someone who asked to join | Owner | No account exists until this happens. |
| Change someone's role | Owner | Resets their permissions to the new role's defaults. |
| Change what someone can do | Owner | Can be delegated, but nobody can grant a power they lack. |
| Reset a colleague's password | Owner | An Owner cannot reset another Owner's. |
| Approve a password-reset request | Owner | The new password is shown once, for you to pass on. |
| Send a campaign immediately | Anyone with “send without approval” | Managers have this by default; Agents do not. |
| Release a campaign that's waiting | Anyone with “approve campaigns” | A refusal must carry a reason, which the sender sees. |
| Submit a template to Meta | Anyone with “submit templates” | Meta then approves or rejects it, usually within the hour. |
| Enter or change WhatsApp credentials | Owner | These spend money, so they stay with the account holder. |
| Change sending speed and hours | Owner | Managers can see the settings but not change them. |
| Delete contacts | Anyone with “delete contacts” | Permanent, and takes the conversation history with it. |
| Download the contact list | Anyone with “download contact lists” | That file leaves the app. Grant it deliberately. |
| Change the seat limit | Sigma Tech India only | An Owner who could raise their own ceiling has no ceiling. |
Two things nobody can do
- Remove the last Owner. Demoting or deactivating the only remaining Owner is refused — it would lock the business out of its own records.
- Remove Sigma Tech India's access. A provider account can't be demoted, deactivated or reset by a business Owner. Otherwise the first move in any disagreement would be removing the only people who can raise a seat limit or help recover a locked account.
If you get locked out
Three routes back in, from easiest to last resort.
Another Owner is available
Ask them to reset it: Settings → Team Members. This is why a second Owner matters.
Nobody is signed in
On the sign-in page, press “Forgotten your password?” and enter your email. An Owner sees the request and resets it for you.
You are the only Owner
Whoever has access to the computer running the console can open the app folder and run:
npm run recover
It lists the Owner accounts, you pick one, and set a new password — nothing is shown as you type. It also signs out anyone currently using that account.
When something's wrong
| What you see | Almost always |
|---|---|
| Everything worked yesterday, nothing works today | The 24-hour access token expired. Create a permanent one from System users. |
| Messages send, but no reply ever arrives | Nobody ticked “messages” in Meta → WhatsApp → Configuration → Webhooks → Manage. |
| The connection check says Meta can't reach you | The public address is missing, is a localhost address, or the tunnel has stopped. |
| A template has said “pending” for hours | Press Check with Meta on the Templates screen. Rejections show Meta's reason. |
| “Add team member” is refused | The workspace is at its seat limit. Deactivate someone who has left, or ask for more seats. |
| A campaign won't send | Either the quality rating is red — sending is blocked until it recovers — or the person needs “send without approval”. |
| Nothing is really being sent | WhatsApp isn't connected yet. A “Demo” badge sits next to the logo whenever that's true. |
Keeping your data safe
Everything — every contact, message and setting — lives in a single file: prisma/app.db. Copy it somewhere safe on a schedule. Settings → Data Export also gives you your contacts and full message history as spreadsheets whenever you want them.