Sigma Tech Back to sign in

Sigma WhatsApp Manager · Setup guide

Connecting WhatsApp, and setting up your team

Everything needed to take this console from a fresh install to sending and receiving real WhatsApp messages — and who has to approve what along the way. Written to be followed in order, with the slow step first.

Before you start

Three things decide how long this takes. Two of them you can start today.

Start business verification first

Meta reviews your business documents before it will let you message the public, and that review takes one to three days. It is the only step with a queue. Begin it now and do everything else while you wait.

What to have ready

  • A Meta Business account — free
  • Your GST certificate or incorporation papers, for verification
  • A phone number not already on WhatsApp — not on regular WhatsApp, not on WhatsApp Business. A fresh SIM, or a landline that can take one call
  • A card, for Meta's message charges
  • A web address this console can be reached at — see step 5. This is the one most people don't expect

Until WhatsApp is connected, nothing is real

The console works fully in practice mode. Messages are simulated, clearly badged, and never leave your computer — so you can learn every screen before a single customer sees anything.

Connecting WhatsApp

Ten steps, in order — each depends on the one before it. Steps 1 to 4 happen in Meta, 5 is yours, 6 to 10 move between the two.

  1. 01

    Start business verification1–3 days

    In Meta Business Suite, go to Settings → Security Centre and begin verification. Upload your GST certificate or incorporation documents.

    Until this clears, Meta only lets you message a small number of test recipients you add by hand. Everything below can be done while it's pending.

  2. 02

    Get a phone number that isn't on WhatsApp

    This is where most first attempts stall. The number cannot already be in use on regular WhatsApp or the WhatsApp Business app. If it is, you must delete that account first — and that erases its chat history.

    Safest choice: a new SIM bought for this, or an office landline that can take one verification call.

  3. 03

    Create the Meta app

    At developers.facebook.com/apps, create an app and add the WhatsApp product to it. Then add and verify your phone number — Meta sends a code to it.

  4. 04

    Create a permanent access token

    The most common way this breaks

    The token Meta shows you on the API Setup screen expires after 24 hours. Nothing on that page says so. Everything works today, and tomorrow every message fails.

    Go to Business settings → System users, create a system user, give it access to your WhatsApp account, and generate a token there. That one is permanent. Use it.

  5. 05

    Give this console a public web address

    Meta has to reach this app over the internet — that's how customer replies and delivery receipts arrive, and how WhatsApp fetches images and PDFs attached to your templates.

    A localhost address works perfectly on your own screen and is invisible to Meta. Skip this and you will be able to send, and will never receive a reply.

    OptionCostBest for
    Cloudflare Tunnel — a subdomain of a domain you ownFreeAnyone who already has a domain. Permanent, professional address.
    Quick tunnel — a temporary random addressFreeTrying it out. The address changes each restart.
    A small server₹400–800/monthReal use, where the console must never be off.
    Whatever you choose, something has to stay switched on. WhatsApp does not hold messages for you — if nothing answers when a customer writes, Meta retries for a while and then gives up.
  6. 06

    Copy five values into the console

    Open Settings → WhatsApp Connection. Each field has a link that jumps straight to the Meta screen it comes from.

    • Access tokenWhatsApp → API Setup — the permanent one from step 4
    • Phone number IDSame screen. A long number, not your phone number
    • Business account IDSame screen. Needed to submit templates
    • App IDApp Settings → Basic. Needed for image, video and PDF headers
    • App secretApp Settings → Basic. Proves messages really came from Meta

    Also fill in Public address of this app — the address from step 5.

  7. 07

    Set the webhook — and press Subscribe

    In Meta, go to WhatsApp → Configuration → Webhooks and paste the two values the console shows on the same Settings screen: the callback URL and the verify token.

    Then press Manage and tick “messages”

    Saving the URL is not enough. If nobody ticks messages, sending works perfectly and no customer reply ever arrives — with no error anywhere to tell you.
  8. 08

    Add a payment method

    In Meta, go to Billing → Payment settings and add a card. Without one, sending stops once the free allowance is used.

  9. 09

    Press “Run check”

    On the same Settings screen. It tests six things separately — your details, your token, your number, your templates, your webhook subscription, and whether Meta can actually reach you — and names whichever one is wrong, with what to do about it.

  10. 10

    Send yourself a real message

    Type your own number and press Send test. If it arrives on your phone, sending works. Reply to it and watch the message appear in your inbox — that proves receiving works too.

    This is the only step that proves the whole chain. Everything before it is an educated guess.

The Meta screens you'll need

Creating accounts

There are three ways an account comes into existence, and they suit different situations.

The very first account — the Owner

On a brand-new install, the first person to open the console sees a setup page instead of a login. They enter the business name, their name, their email and a password of at least ten characters.

That creates the first Owner and then permanently closes the setup page, so nobody can later create themselves an Owner account.

Create a second Owner the same day

There is no “forgot password” email in this console, and one Owner cannot reset another Owner's password. With only one Owner, a forgotten password locks you out of your own customer records. The console warns you while this is true.

Adding someone yourself

Settings → Team Members → Add team member. Only an Owner can do this. You enter their name, email, a starting role and a password — the console suggests a good one.

The email and password are shown to you once. There is no invitation email; you pass the details on however you normally would.

When someone asks to join

Anyone can open the sign-in page and press “Need an account?”. They enter their name, email and an optional note.

Nothing is created at that moment. The request appears in Settings → Requests, where an Owner approves or declines it. Approving is what creates the account, and the console then shows a password to pass on — once.

Because nothing exists until approval, an unapproved stranger never occupies one of your seats and never appears in your team list.

Seats

Every workspace has a limit on how many people can sign in — Owners, Managers and Agents counted together. Deactivated people don't count, so you can keep a former employee's records without paying for the seat.

Only Sigma Tech India can change that limit. If you need more seats, ask.

The three roles

The role sets a sensible starting point. After that an Owner adjusts what each person can do, individually — because “Manager” means very different things at different businesses.

RoleWhat they start withTypically
OwnerEverything, always. Cannot be restricted.You, and one other person you trust completely.
ManagerBuild and send campaigns, approve others' campaigns, write and submit templates, manage groups, export contacts, change the bot and rules. Not WhatsApp credentials, and not roles.Whoever runs the day-to-day and is accountable for spend.
AgentNothing beyond the inbox — replying, updating leads, leaving notes. Everything else must be granted deliberately.Your sales desk.

Adjusting an individual

On the Team screen, open “What [name] is allowed to do” under anyone. Each permission is a tick-box with a plain-English explanation, and the ones that spend money or delete things are marked.

The three campaign powers

Two tick-boxes produce exactly three outcomes, and the screen tells you which is in force:

TickedWhat happens when they press send
NeitherRefused. They cannot build a campaign at all.
Build campaignsIt goes into the approval queue. Nothing is sent.
+ Send without approvalIt goes out immediately, and spends real money.
Nobody can hand out a permission they don't hold themselves — so a Manager can never grant an Agent the power to approve campaigns and then have that Agent approve their own.

Who approves what

The complete list. Anything not here needs no approval.

ActionWho can do itNotes
Create the very first OwnerNobody — it's automaticOnly on a fresh install. The page closes for good afterwards.
Add a team memberOwnerSubject to the seat limit.
Approve someone who asked to joinOwnerNo account exists until this happens.
Change someone's roleOwnerResets their permissions to the new role's defaults.
Change what someone can doOwnerCan be delegated, but nobody can grant a power they lack.
Reset a colleague's passwordOwnerAn Owner cannot reset another Owner's.
Approve a password-reset requestOwnerThe new password is shown once, for you to pass on.
Send a campaign immediatelyAnyone with “send without approval”Managers have this by default; Agents do not.
Release a campaign that's waitingAnyone with “approve campaigns”A refusal must carry a reason, which the sender sees.
Submit a template to MetaAnyone with “submit templates”Meta then approves or rejects it, usually within the hour.
Enter or change WhatsApp credentialsOwnerThese spend money, so they stay with the account holder.
Change sending speed and hoursOwnerManagers can see the settings but not change them.
Delete contactsAnyone with “delete contacts”Permanent, and takes the conversation history with it.
Download the contact listAnyone with “download contact lists”That file leaves the app. Grant it deliberately.
Change the seat limitSigma Tech India onlyAn Owner who could raise their own ceiling has no ceiling.

Two things nobody can do

  • Remove the last Owner. Demoting or deactivating the only remaining Owner is refused — it would lock the business out of its own records.
  • Remove Sigma Tech India's access. A provider account can't be demoted, deactivated or reset by a business Owner. Otherwise the first move in any disagreement would be removing the only people who can raise a seat limit or help recover a locked account.

If you get locked out

Three routes back in, from easiest to last resort.

Another Owner is available

Ask them to reset it: Settings → Team Members. This is why a second Owner matters.

Nobody is signed in

On the sign-in page, press “Forgotten your password?” and enter your email. An Owner sees the request and resets it for you.

You are the only Owner

Whoever has access to the computer running the console can open the app folder and run:

npm run recover

It lists the Owner accounts, you pick one, and set a new password — nothing is shown as you type. It also signs out anyone currently using that account.

This is not a back door. It needs access to the computer holding your database — and anyone with that already has the file itself. It exists so the correct fix is one command rather than editing the database by hand.

When something's wrong

What you seeAlmost always
Everything worked yesterday, nothing works todayThe 24-hour access token expired. Create a permanent one from System users.
Messages send, but no reply ever arrivesNobody ticked “messages” in Meta → WhatsApp → Configuration → Webhooks → Manage.
The connection check says Meta can't reach youThe public address is missing, is a localhost address, or the tunnel has stopped.
A template has said “pending” for hoursPress Check with Meta on the Templates screen. Rejections show Meta's reason.
“Add team member” is refusedThe workspace is at its seat limit. Deactivate someone who has left, or ask for more seats.
A campaign won't sendEither the quality rating is red — sending is blocked until it recovers — or the person needs “send without approval”.
Nothing is really being sentWhatsApp isn't connected yet. A “Demo” badge sits next to the logo whenever that's true.

Keeping your data safe

Everything — every contact, message and setting — lives in a single file: prisma/app.db. Copy it somewhere safe on a schedule. Settings → Data Export also gives you your contacts and full message history as spreadsheets whenever you want them.