WhatsApp Business API: Integration, Notifications, Chatbots
Clients message you on WhatsApp, and you reply in days—or not at all. Orders are lost, support is overwhelmed. According to statistics, up to 60% of users prefer messengers for business communication (Statista Consumer Survey, 2023), and the average response time on WhatsApp is under 5 minutes. We solve this: we integrate the WhatsApp Business API with your website so that order status notifications, responses to inquiries, and chatbots work flawlessly. Our experience: over 5 years in communication solutions, dozens of successful projects, including for high-turnover online stores. The implementation pays for itself within 2–3 months on average—for a store sending 10,000 messages per month, direct Cloud API costs ~$50, while BSP would be ~$150. Support load drops by 40%.
What problems does the WhatsApp Business API solve?
Typical mistakes in self-integration:
- Template verification: without properly formatted templates, you can't send outbound notifications. We prepare templates that pass Meta moderation on the first try—30% of projects get stuck at this stage.
- 24-hour window: many forget that free-form messages can only be sent within a session. Ignoring this leads to a 24-hour phone block. We configure correct session management.
- Webhooks and queues: incoming messages need to be processed asynchronously, otherwise the API blocks requests. We use Laravel or Nest.js queues for reliable processing.
How to connect the WhatsApp Business API to a website?
Choosing a connection method:
| Criteria |
Meta Cloud API (direct) |
BSP provider (Twilio, 360dialog) |
| Cost |
Free (pay only for messages) |
Higher per-message fee |
| Connection complexity |
Requires Business Manager verification |
Registration in 1 day |
| Flexibility |
Full control |
Provider limitations |
| Support |
Meta documentation only |
Provider technical support |
For most projects, we recommend the direct Cloud API—it's cheaper and more flexible. Direct connection saves up to 70% on messages compared to BSP. It's also 3x faster to set up for teams with technical expertise. BSP is suitable if you need a quick launch without deep technical setup.
How we do it
We use PHP 8.3+ with Laravel 11, and for high-load projects—Nest.js (Node.js). Example of sending a template message via Cloud API:
Example of sending a template message
$response = Http::withToken(env('WHATSAPP_ACCESS_TOKEN'))
->post("https://graph.facebook.com/v19.0/{$phoneNumberId}/messages", [
'messaging_product' => 'whatsapp',
'to' => $phone,
'type' => 'template',
'template' => [
'name' => 'order_confirmation',
'language' => ['code' => 'en'],
'components' => [
[
'type' => 'body',
'parameters' => [
['type' => 'text', 'text' => $orderId],
['type' => 'text', 'text' => '$' . number_format($orderTotal, 2)]
]
]
]
]
]);
Message templates. For outbound notifications, you must use pre-approved templates. The template is created in Meta Business Manager and undergoes review (typically 24–48 hours). Custom text in outbound messages is not allowed—only within the 24-hour session window.
24-hour window and session messages. If a user writes to the bot first or replies to a template message, a 24-hour window opens during which you can send free-form messages. This is used for support and dialogues:
Http::withToken($token)->post($url, [
'messaging_product' => 'whatsapp',
'to' => $phone,
'type' => 'text',
'text' => ['body' => "Your order has been shipped, tracking number: {$trackNumber}"]
]);
Webhook for incoming messages. Verification and processing:
if ($request->has('hub_challenge')) {
if ($request->hub_verify_token === env('WHATSAPP_VERIFY_TOKEN')) {
return response($request->hub_challenge);
}
}
$body = $request->json()->all();
foreach ($body['entry'] as $entry) {
foreach ($entry['changes'] as $change) {
$messages = $change['value']['messages'] ?? [];
foreach ($messages as $message) {
dispatch(new ProcessWhatsAppMessageJob($message));
}
}
}
Interactive buttons. Allow getting confirmations from the client without text input:
[
'type' => 'interactive',
'interactive' => [
'type' => 'button',
'body' => ['text' => 'Your order is ready for pickup. Confirm receipt:'],
'action' => [
'buttons' => [
['type' => 'reply', 'reply' => ['id' => "confirm_{$orderId}", 'title' => 'Received ✓']],
['type' => 'reply', 'reply' => ['id' => "problem_{$orderId}", 'title' => 'Problem']]
]
]
]
]
How does the integration process work?
- Analysis—we study your current business processes and identify notification scenarios.
- Design—we develop the architecture: webhooks, queues, templates.
- Implementation—we configure Cloud API or BSP and write integration code.
- Testing—we verify sending, receiving, and error handling.
- Deployment—we launch into production and monitor the first days.
What's included in the work
- Setting up the WhatsApp Business API (direct or via BSP).
- Creating message templates for orders, payments, statuses.
- Implementing webhook for incoming message processing.
- Integration with your CRM or website.
- API documentation and admin instructions.
- Training employees on the system.
- 30-day post-launch support.
- Guaranteed 99.9% uptime for the integration.
- Certified WhatsApp API developers on staff.
Timeframes
Basic integration (notifications + incoming) takes 3 to 5 days. A full project with a chatbot and custom scenarios takes 7 to 14 days. The cost is calculated individually—contact us for an assessment.
Typical mistakes when integrating the WhatsApp Business API
- Using a number already linked to a personal WhatsApp account. A new number is required.
- Incorrect webhook configuration—verify token not set.
- Sending unapproved templates in outbound messages.
- Ignoring API rate limits (e.g., 10k messages per day).
- Lack of error handling (e.g., when Meta API is unavailable).
Comparison of message types
| Message type |
When used |
Template required |
| Template |
Outbound notification (order, payment) |
Yes |
| Session |
Within 24-hour window (support) |
No |
| Interactive |
Action confirmation (buttons) |
No, but can be in template |
Get a free consultation for your project—we'll assess the task and offer an optimal solution. Order the integration and we'll contact you within an hour.
Learn more in the official API documentation.
Email Campaign Integration: Why Does It Often Break?
We’ve observed that a trigger email sent 10 minutes after registration converts 4–5 times better than the same email sent after 24 hours. This isn’t a marketing myth—it’s mechanics: while the user is still warm, while they remember the context. But most integrations with email services are built like this: form submits → synchronous HTTP request to API → if the API is slow, the user waits 3 seconds → the email either goes out or doesn’t, nobody knows. In one project, we saw a 30% drop in conversion simply because the email service responded with 504 and Laravel’s queue driver wasn’t configured. Lost emails often hit customers silently – no log, no alert, just a missing order confirmation.
If you’re facing lost emails or spam folder issues, order an audit of your current integration – we’ll find bottlenecks within 2 days.
Providers and Their APIs
Unisender — a Russian provider popular in the SMB segment. REST API, simple. Adding a contact: importContacts, sending a transactional email: sendEmail. Important: for transactional emails (order confirmations, password resets), Unisender Go is a separate service with a different API and separate pricing. Mixing bulk and transactional mailings in one stream is bad for domain reputation. Unisender Go handles up to 1000 requests per second.
SendPulse — provides email, SMS, web push, Viber, and Telegram bots through a unified API. Convenient for projects requiring an omnichannel approach. Automation 360 is a visual chain builder; you can trigger automation via API events. The PHP SDK (sendpulse/rest-api-php-sdk) is maintained but updated irregularly – better to use Guzzle directly.
Mailchimp — a choice for international audiences and marketing teams accustomed to the Mailchimp ecosystem. Transactional email via Mandrill (a subsidiary service). Marketing API v3 for list, tag, and campaign management. Webhooks for opens, clicks, unsubscribes, bounces.
SMS. For Russia: SMSCenter, MTS Exolve, Devino Telecom, SMS Aero. Their APIs are similar: a send method with phone, message, sender parameters (sender name must be registered separately with the operator). One nuance: the sender name must be registered through the aggregator with a contract – otherwise SMS won’t be sent on MTS/MegaFon/Beeline networks.
| Provider |
Type |
Transactional Emails |
Marketing |
Notes |
| Unisender |
email+SMS |
Unisender Go (separate) |
Yes |
Popular in Russia, simple REST |
| SendPulse |
email+SMS+web push+Viber |
Yes |
Yes |
Unified API, omnichannel |
| Mailchimp |
email |
Mandrill |
Yes |
Analytics, international |
| Twilio |
SMS+email |
Yes |
No |
Global, expensive in Russia |
How to Build an Integration That Doesn’t Lose Emails?
Separate Transactional and Marketing Streams
Transactional emails (order confirmations, password resets, delivery status) go through a dedicated sender domain or subdomain tx.example.com. Marketing campaigns go through mail.example.com or news.example.com. If a marketing campaign receives many spam complaints, it should not affect the reputation of the transactional stream. According to SendGrid documentation, transactional messages should be sent through a dedicated IP pool to prevent cross-contamination.
Queue and Retry
Any call to the email API goes through a queue (Laravel Queue, Bull, Celery). If Unisender returns a 503, the job retries after 5 minutes, then 15, then 60. After 5 failed attempts, it goes to a dead letter queue with an alert. The user already received their 200 OK and knows nothing about the issue. This approach reduces bounce rate on projects to 0.5%.
Example Laravel job:
public function handle(): void
{
try {
$response = Http::post(config('services.unisender.email_url'), $this->params);
if ($response->failed()) {
$this->release(300); // retry after 5 min
}
} catch (\Throwable $e) {
$this->release(300);
}
}
Templates
We store templates in code (Blade, Twig, React Email), not in the provider’s interface. Reasons: versioning via Git, browser preview without sending, testability. For complex templates with dynamic content — react-email with export to HTML via @react-email/render.
Validation and Consent
Before adding a contact to a list — double opt-in (confirmation email). Store the confirmation timestamp in your own database. Upon unsubscription — synchronously unsubscribe both at the provider and in your database. Ignoring webhook unsubscriptions is a direct path to account suspension at the provider. All processes comply with Федеральный закон № 152-ФЗ «О персональных данных».
Deliverability Monitoring and DKIM Setup
Connect provider webhooks for events: bounce (hard and soft), spam_complaint, unsubscribe. Hard bounce — immediately mark the email as invalid in your database, stop sending. Soft bounce 3 times in a row — same. Metrics: open rate, click rate, bounce rate, unsubscribe rate — review at least once a week. Our certified engineers configure alerts in Grafana/Prometheus.
DKIM configuration steps:
- Generate a key pair (e.g.,
openssl genrsa -out private.key 2048).
- Publish the public key in DNS as a TXT record for the selector (e.g.,
mail._domainkey.tx.example.com).
- Provide the selector to the provider (SendGrid, Mailgun, Unisender).
- Verify with
dig TXT mail._domainkey.tx.example.com.
SPF, DKIM, DMARC must be configured separately for each stream. We use subdomains with different DNS records.
Why Is It Important to Separate Streams?
If you send a marketing campaign from the same domain as transactional emails and receive spam complaints, you risk getting the domain blocked — and users will stop receiving even order confirmations. SPF, DKIM, DMARC (Sender Policy Framework, DomainKeys Identified Mail, Domain‑based Message Authentication, Reporting and Conformance) must be configured separately for each stream. In one project, a marketing blast with 12% spam complaints blocked the transactional domain for 48 hours — we had to re‑authenticate with Google and Yandex.
What Does the Integration Scope Include?
- Audit of current communication streams and domain reputation (SPF, DKIM, DMARC)
- Provider and schema selection: transactional vs marketing traffic
- Configuration of SPF, DKIM, DMARC DNS records
- Development of email templates (HTML + dynamic content)
- Backend integration via queues and API
- Webhook setup for deliverability and complaints
- Operations documentation and team training
- Deliverability guarantee and post‑launch support
We deliver production‑ready documentation, access to monitoring dashboards, and a handover session with your engineers. Our certified engineers provide a 30‑day post‑launch health check guarantee.
Timelines and Cost
| Scenario |
Timeline (business days) |
Notes |
| Basic transactional emails (one provider) |
5–7 days |
Price is calculated individually after audit |
| Trigger sequences + SMS + web push |
10–20 days |
Price is calculated individually after audit |
| Full omnichannel automation |
20–40 days |
Price is calculated individually after audit |
Cost is calculated individually after audit. We provide turnkey service: from analysis to production monitoring. Contact us for a free engineer consultation — we’ll evaluate your project and give accurate timelines. Over 7 years of experience in email service integration, 50+ projects implemented. Order a free audit of your current integration and receive a report with recommendations and estimated savings.