Get API key
Updated: Sep 18, 2026
Copy for LLM
Meta Business Agent Platform API requests are authenticated as a system user, so every call needs a system user access token. This page covers generating that token.
Prerequisites
- A Meta app granted both the
whatsapp_business_messagingandwhatsapp_business_managementpermissions. Thewhatsapp_business_messagingpermission authenticates your requests. Thewhatsapp_business_managementpermission is required to read agent data — without it, read calls return an empty result. - A system user with your app and WhatsApp Business account (WABA) assigned to it. If you don’t have one yet, create it and assign the assets first — see Create a system user and Assign the app and WABA.
Generate the token
- Go to Meta Business Suite. In the left navigation select Settings, then under Users select System users, and click your system user.
- In the upper right, click Generate new token. A dialog opens.
- In the dialog, select your app from the dropdown, then click Next.
- Select the token expiration setting, then click Next.
- Select the checkboxes next to the whatsapp_business_messaging and whatsapp_business_management permissions. A token without whatsapp_business_messaging returns
401. A token that has messaging but not whatsapp_business_management authenticates, but read calls return no data. - Click Generate token and save it somewhere secure. It is shown only once.
The
whatsapp_business_messaging permission authenticates your calls, but reading agent data — for example evaluation cases and results — also requires the whatsapp_business_management permission. If a read call succeeds but returns no data, the most common cause is a token that has messaging but not management: add whatsapp_business_management and generate a new token. Receiving data also requires that the Meta Business Agent Terms of Service are accepted for the WABA (see End-to-end setup); if the WABA hasn’t accepted them, calls return 403 rather than empty data. A few endpoints require additional Meta-granted access beyond both permissions — if data is still empty after adding management, contact your Meta representative to confirm your app’s access.Solution Partners and Tech Providers
If you are calling on behalf of a client’s WhatsApp Business account, use a Business Integration System User (BISU) token instead. A BISU token lets your platform act on behalf of multiple client WABAs under a single credential. See Generate an access token for both options side by side, and the BISU documentation for generating and managing these tokens.
Set the API version header
Note: Use theX-API-Versionshown on each endpoint’s reference page. Meta Business Agent Platform endpoints take2.0.0. Without the header, a request resolves to the oldest version that endpoint supports —1.0.0for endpoints that predate these field names — so set2.0.0explicitly. Cloud API endpoints differ — Thread Control, for example, takes1.0.0.
Next steps
- Quickstart — onboard an agent and send it your first message in three API calls.
- End-to-end setup — the full path to running an agent in front of WhatsApp users, including billing, app subscription, and webhook fields.