Communication
WhatsApp Business Webhooks
Meta WhatsApp Business API. Receive events for messages, message status updates, and template updates.
Connecting WhatsApp Business to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into WhatsApp Business. Then:
- 1Go to Meta Developer Portal → Your App → WhatsApp → Configuration
- 2Under Webhooks, paste your Hookbase ingest URL as the Callback URL
- 3Enter a Verify Token (used for initial handshake)
- 4Subscribe to the message fields you need
- 5Use the App Secret from Basic Settings as your Hookbase signing secret
Signature verification
WhatsApp Business signs its webhooks with HMAC-SHA256 in X-Hub-Signature-256, and Hookbase has no verifier for that combination today. We would rather say so here than let a source report every event as verified while nothing was checked.
What you can do:
- Receive them on a
customsource with no signing secret. Hookbase still dedupes, retries, transforms, routes and replays them; it just does not vouch for the sender. - Set a signing secret anyway if WhatsApp Business can be configured to send a hex HMAC-SHA256 of the raw body in
X-Signature,X-Webhook-SignatureorX-Hub-Signature-256— that is the one scheme the custom verifier implements. - Verify downstream: the original headers travel with the event, so your own service or a transform can check the signature itself. The key is at Meta Developer Portal → Your App → Configuration → App Secret.
- Narrow the blast radius with an IP allowlist and a hard-to-guess source slug.
WhatsApp Business event types
6 of the events people route most often. Hookbase accepts every event WhatsApp Business sends, whether or not it is listed here.
messages
A new message was received
message_status.delivered
A message was delivered
message_status.read
A message was read
message_status.failed
A message delivery failed
message_template_status_update
A message template status changed
account_update
Account status changed (e.g., phone number quality)
What a WhatsApp Business webhook looks like
A messages payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"object": "whatsapp_business_account",
"entry": [
{
"id": "WHATSAPP_BUSINESS_ACCOUNT_ID",
"changes": [
{
"value": {
"messaging_product": "whatsapp",
"metadata": {
"display_phone_number": "15551234567",
"phone_number_id": "PHONE_ID"
},
"messages": [
{
"from": "15559876543",
"id": "wamid.abc123",
"timestamp": "1678901234",
"text": {
"body": "Hello!"
},
"type": "text"
}
]
},
"field": "messages"
}
]
}
]
}Start receiving WhatsApp Business webhooks
Create a source, paste the URL into WhatsApp Business, and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free