Build a WhatsApp bot with the WhatsApp Cloud API

Build a WhatsApp bot on Meta's official Cloud API and keep it online 24/7. Paste one paragraph; your AI agent writes, deploys and checks the bot.

You can have a WhatsApp bot that answers day and night, using Meta’s official WhatsApp Cloud API. You set up a free Meta developer app with a test number, save a few keys in your aidrop.it project, and paste one paragraph into Claude Code, Codex or Cursor. Your agent writes the bot and puts it online; you paste its address into Meta’s dashboard. Plan on about 30 minutes.

The bot lives on aidrop.it, not on your phone or laptop. Meta passes each message to the bot’s web address; the bot answers through Meta.

What you will have at the end

  • A WhatsApp number that replies to any message you send it, within seconds.
  • A bot that answers with your laptop closed and after every update.
  • The bot’s code saved in a repository, so your agent can change it later.

Words you will meet

  • WhatsApp Cloud API — Meta’s official way for a program to send and receive WhatsApp messages.
  • Access token — the key your bot sends messages with. Meta’s first one expires within a day.
  • Webhook — the web address Meta calls each time someone writes to your number.
  • Verify token — a password you make up and give to both Meta and your bot.
  • App secret — a key Meta uses to sign each message, so your bot can ignore fakes.
  • Secret — a private value kept in your aidrop.it project, never in the code.

What you need

  • A Facebook account to sign in to Meta for Developers.
  • A Meta app, which holds your WhatsApp keys. Create it with the use case Connect with customers through WhatsApp and follow Meta’s Get Started guide. You get a free test number, its phone number ID and a temporary access token.
  • Your own WhatsApp number on the test number’s short list of allowed recipients.
  • An aidrop.it account with your agent connected, as in the Quickstart. The smallest plan is enough; this bot needs no database.

You will save four secrets: the access token, the phone number ID, the app secret (Meta’s app dashboard, Settings, Basic) and a verify token you make up. Your agent names them for the Project Secrets page. Never paste them into the chat.

Say this to your agent

Say this to your agent
Build me a WhatsApp bot on the official WhatsApp Cloud API
and run it on aidrop.it, 24/7. Use my
existing aidrop.it Project, or create one called "WhatsApp
bot" if I have none.
What it does: it replies "You said: " plus the text to every
incoming text message. It ignores delivery statuses and other
message types.
How it works:
- Answer Meta's webhook check (hub.mode, hub.verify_token,
hub.challenge) using my verify token.
- Check the X-Hub-Signature-256 header on every incoming
message against my app secret, over the raw body, and reject
anything that does not match.
- Answer Meta right away; it retries unanswered messages.
- Do not use whatsapp-web.js, Baileys or any unofficial client.
- Read aidrop.it's runtime rules before writing code and follow
them, including the outbound proxy.
Secrets: tell me the exact names to add on the Project Secrets
page for the access token, phone number ID, app secret and
verify token, and wait until I confirm. Never ask me to paste
values here, and never log them or message text.
Build it, check it runs, fix what fails. Then give me the
webhook address to paste into Meta and say what you checked.

What your agent does

  1. Picks your aidrop.it project, or creates one.
  2. Tells you which secrets to save, and waits while you save them.
  3. Writes the bot, plus a small “I’m alive” page aidrop.it checks to see it is running.
  4. Saves the code to a repository on aidrop.it and builds it there.
  5. Watches the build. If it fails, it reads the error, fixes the code and builds again.
  6. Gives you the webhook address for Meta.

Then you finish in Meta’s app dashboard. Open the WhatsApp Configuration panel (under Use cases, Customize, for apps made with the WhatsApp use case). Paste the address into Callback URL and your made-up password into Verify token, then save. Meta checks the address with your bot on the spot (how). Last, subscribe to the messages field in the list that appears.

Check that it works

  • Send “hi” from your phone to the test number. The bot answers “You said: hi”.
  • Close your laptop and send another message. It still answers.
  • Try again the next day. If it went quiet, the temporary token expired: see the FAQ.

When something goes wrong

What you see What to tell your agent
Meta says the callback URL could not be verified “Meta’s webhook check fails. Check the bot is running and answers the check with my verify token.”
Your message arrives but no answer comes back “The bot receives messages but cannot send. Read the logs and check outgoing requests use the proxy.”
The bot stops answering after about a day Make a permanent token (see FAQ), save it in place of the old one, then say “build again”.
The same answer arrives twice “Meta re-sent a message. Answer Meta at once and skip messages you already handled.”

FAQ

How do I get a permanent WhatsApp Cloud API access token?

Meta’s first token expires within a day. For one that lasts, create a system user in Meta’s Business settings, give it your app and WhatsApp account, and generate a token with the business_management, whatsapp_business_management and whatsapp_business_messaging permissions. Meta’s access token guide shows each step.

How much does the WhatsApp Business API cost?

As of September 2026, Meta charges per message, a model in place since July 1, 2025. Ordinary replies inside the 24 hours after a customer’s last message are free, and so are utility templates sent then. Marketing and authentication templates are always charged, as are utility templates outside that window. Rates vary by country: see Meta’s pricing page.

Can I run a WhatsApp bot for free?

The messages can be free: a bot that only answers people who wrote first stays inside the free window. The server that keeps the bot online is what costs money. On aidrop.it the free plan runs nothing; the smallest plan, Starter, runs a bot like this one. See aidrop.it for current prices.

Search the docs