WhatsApp

Live

BEARER TOKEN

BUSINESS MESSAGING

Communication

WhatsApp gives your agent business messaging through the WhatsApp Business Cloud API: send text, media, and template messages, manage message templates, and configure business phone numbers and profiles.

  • Per-user credentials: each call uses the actual user's access token, never a shared bot.
  • Encrypted per-tenant vault: AES-256, resolved at request time, never in LLM context.
  • Scoped before every call: pre-call scope check, 90-day SIEM-exportable audit chain.
WhatsApp
agent · Acme Q3
Run
Send the order_shipped template to +1 415 555 0134 for order 8812.
S
whatsapp_send_template_message
118ms
Messaging agent
Sent the order_shipped template to +1 415 555 0134 with order 8812 filled in. WhatsApp accepted it and returned a message ID.
Sources: 1 template message, en_US
whatsapp
1 message
18:29
Message Claude...

Tools your messaging agent reaches for on WhatsApp, scoped per user.

CALL ANY TOOL
36 tools for WhatsApp business messaging: send text, media, location, contact, interactive, and template messages, manage templates, QR codes, phone numbers, and business profiles.
whatsapp_business_account_get
Get business account
Get details for a WhatsApp Business Account, such as its name, currency, timezone, and message template namespace. Returns the requested fields as a JSON object. Use whatsapp_phone_numbers_list to see the phone numbers under this account.
Parameters
Name
Type
Required
Description
waba_id
string
Required
The WhatsApp Business Account ID.
fields
string
Optional
Comma-separated list of fields to return.
whatsapp_business_profile_get
Get business profile
whatsapp_business_profile_update
Update business profile
whatsapp_businesses_list
List businesses
whatsapp_client_wabas_list
List client wabas
whatsapp_mark_message_read
Read mark message
whatsapp_media_delete
Delete media
whatsapp_media_get_url
Media get url
whatsapp_message_template_create
Create message template
whatsapp_message_template_delete
Delete message template
whatsapp_message_template_get
Get message template
whatsapp_message_template_update
Update message template
whatsapp_message_templates_list
List message templates
whatsapp_owned_wabas_list
List owned wabas
whatsapp_phone_number_deregister
Phone number deregister
whatsapp_phone_number_get
Get phone number
whatsapp_phone_number_register
Phone number register
whatsapp_phone_number_request_code
Phone number request code
whatsapp_phone_number_set_pin
Phone number set pin
whatsapp_phone_number_verify_code
Phone number verify code
whatsapp_phone_numbers_list
List phone numbers
whatsapp_qr_code_create
Create qr code
whatsapp_qr_codes_list
List qr codes
whatsapp_send_contacts_message
Send contacts message
whatsapp_send_interactive_message
Send interactive message
whatsapp_send_location_message
Send location message
whatsapp_send_media_message
Send media message
whatsapp_send_reaction_message
Send reaction message
whatsapp_send_template_message
Send template message
whatsapp_subscribed_apps_subscribe
Subscribed apps subscribe

For more tools, view docs.

Build your Agent
Same auth pattern across LangChain, OpenAI, Anthropic, and Google ADK.
Python · LlamaIndex
import { ScalekitClient } from "@scalekit-sdk/node";
import { createReactAgent } from "@langchain/langgraph/prebuilt";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);

// WhatsApp tools scoped to this user
const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["whatsapp"], toolNames: [
    "whatsapp_message_templates_list",
    "whatsapp_send_template_message",
    "whatsapp_send_text_message"] },
  pageSize: 100,
});

const agent = createReactAgent({ llm, tools });
await agent.invoke({ messages: [{ role: "user", content: "Send the order_shipped template to +1 415 555 0134 for order 8812" }] });
import OpenAI from "openai";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
const openai = new OpenAI();

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["whatsapp"] }, pageSize: 100,
});

const res = await openai.chat.completions.create({
  model: "gpt-5",
  messages: [{ role: "user", content: "Send the order_shipped template to +1 415 555 0134 for order 8812" }],
  tools,
});

// Execute the tool call with the user's vaulted WhatsApp access token
await sk.tools.executeTool(res.choices[0].message.tool_calls[0], "user_123");
import Anthropic from "@anthropic-ai/sdk";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);
const anthropic = new Anthropic();

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["whatsapp"] }, pageSize: 100,
});

const msg = await anthropic.messages.create({
  model: "claude-sonnet-5",
  max_tokens: 1024,
  messages: [{ role: "user", content: "Send the order_shipped template to +1 415 555 0134 for order 8812" }],
  tools,
});

// Tool call runs with the user's vaulted WhatsApp access token
await sk.tools.executeTool(msg.content, "user_123");
import { Agent } from "@google/adk/agents";
import { ScalekitClient } from "@scalekit-sdk/node";

const sk = new ScalekitClient(env.SCALEKIT_ENV_URL, env.SCALEKIT_CLIENT_ID, env.SCALEKIT_CLIENT_SECRET);

const { tools } = await sk.tools.listScopedTools("user_123", {
  filter: { connectionNames: ["whatsapp"] }, pageSize: 100,
});

const agent = new Agent({
  name: "messaging_agent",
  model: "gemini-2.5-pro",
  instruction: "WhatsApp tools scoped to this user",
  tools,
});

await agent.run("Send the order_shipped template to +1 415 555 0134 for order 8812");
Try these prompts
Copy any prompt into your agent. Each maps directly to a WhatsApp tool. Click to copy, paste into your agent, done.
Messages
Copy the prompt
Copied
Send a text message to +1 415 555 0134 confirming tomorrow's delivery window.
Copy the prompt
Copied
Send our store location to this customer.
Copy the prompt
Copied
Send an interactive message with Reschedule and Cancel buttons.
Templates
Copy the prompt
Copied
List approved message templates for this WhatsApp Business Account.
Copy the prompt
Copied
Create a payment_reminder template in English.
Copy the prompt
Copied
Send the order_shipped template for order 8812.
Numbers and profile
Copy the prompt
Copied
List the phone numbers on this WhatsApp Business Account.
Copy the prompt
Copied
Update the business profile description and website.
Copy the prompt
Copied
Create a QR code that opens a chat with a prefilled message.
SEE HOW AUTH WORKS
Each user connects their own WhatsApp access token once; Scalekit sends it with every call. Access tokens stay vaulted, every call is scope checked, and every action is logged.
1
Authorize
Your user connects
WhatsApp
once. We tie it to their identity and the meetings they approved — no shared bot account, no org-wide access
Who:
user ‘A’
when:
Once per user
access:
Limited to user
2
Store
Their
WhatsApp
token lives in a vault scoped to them. User A's meetings are never reachable by an agent acting for user B, even on the same connection
vault:
encrypted
scope:
per-user
tokens:
auto-refreshed
3
Resolve
When your agent calls a
WhatsApp
tool, we fetch the right token server-side. It never touches your agent, never appears in the LLM context, never shows up in your logs
speed:
~40ms
check:
before every call
seen by:
nobody
4
Audit
Every
WhatsApp
tool call is logged — who triggered it, which meeting was fetched, what came back. 90 days of history, tied to the user who authorized it
history:
90 days
export:
SIEM-ready
logged:
every call
Test other agents
See the same per-user auth pattern across other communication connectors.
Support and Ops Teams
Support ticket automation agent
Fetches new Zendesk tickets, drafts a reply from Notion knowledge base articles, digests what it cannot answer to Slack, and archives the rest, acting as the support agent rather than a shared API key.
Support and Ops Teams
Support triage agent
Fetches new Zendesk tickets, classifies them by type and urgency, searches the Notion knowledge base for an answer, and routes what it cannot resolve to Slack. Every call runs on the support agent's own delegated OAuth.
GTM and RevOps Teams
Outbound prospecting agent
Searches Apollo for prospects matching your ICP, scores and ranks them, drafts personalized outreach in Gmail, and logs every send to Google Sheets. Mail goes out as the rep, not from a shared inbox.
GTM and RevOps Teams
CRM AI agent
Reads the Granola transcript after every call, extracts next steps and updates the HubSpot record, drafts the follow-up in Gmail, and confirms in Slack, all on the rep's own delegated OAuth.
Test other agents
See the same per-user auth pattern across other communication connectors.
SUPPORT
Support ticket automation (Google ADK)
Fetch, annotate, and archive Zendesk tickets with Notion context, digesting anything it cannot answer to Slack.
SUPPORT
Support triage agent
Classify new Zendesk tickets, search the Notion knowledge base for an answer, and route what it cannot resolve to Slack.
SALES
Outbound prospecting agent
Search Apollo for ICP matches, rank them, draft personalised Gmail outreach, and log every send to Google Sheets.
GTM
CRM AI agent
Turn each Granola call transcript into a HubSpot record update, a drafted Gmail follow-up, and a Slack recap.
Why Scalekit
Secure your agent's access. Connectors ship in minutes
01.
Shared tokens break per-user analytics
A shared WhatsApp access token looks fine in a demo. In production every outbound message looks like one service account, and you cannot tell which user triggered it. Scalekit resolves the credential of the actual user who triggered the agent, never a shared bot.
// shared key
audit → bot_service_account

// scalekit
audit → user_abc ✓
02.
Authentication is not authorization
03.
Multi-tenancy is architectural
04.
WhatsApp today. Ten connectors tomorrow.
“Our agents act across Salesforce, Gong, Google Drive, and more, on behalf of every customer. Scalekit behind the scenes meant we can keep adding tools without ever rebuilding how credentials or tool calling work.”
Venu Madhav Kattagoni
Head of Engineering / Von
FAQs
Frequently Asked Questions
Does the agent access WhatsApp as the user or as a shared key?
As the user. Each user connects their own WhatsApp access token once, and Scalekit sends it with every call. Audit logs attribute every action to that user, not a shared service account.
Where is the WhatsApp access token stored?
In Scalekit's managed AES-256 token vault, namespaced per tenant. To rotate it, the user reconnects with a new access token. Revocation is a single dashboard action. Credentials never appear in prompts, logs, or LLM context.
Can I limit what the agent does in WhatsApp?
Yes. Filter by tool name in listScopedTools to expose only what you want, for example template sends without template deletion or phone number deregistration. Scalekit also enforces scope checks before every API call.
What happens when a user revokes WhatsApp access?
The connection is invalidated on the next tool call. Subsequent requests for that user fail closed with a clear error. Other users in the tenant remain unaffected. The event is logged for audit.
What can the agent do in WhatsApp?
36 tools for the WhatsApp Business Cloud API: send text, media, location, contact, reaction, interactive, and template messages, mark messages read, manage message templates and QR codes, register and verify phone numbers, update business profiles, and manage webhook subscriptions. Start with whatsapp_businesses_list to find a business_id.
Start in your coding agent
Up and running in one command
Install the Scalekit skill in your editor of choice. Connector, auth, tools, prompt, all wired up
Claude Code REPL
/plugin marketplace add scalekit-inc/claude-code-authstack
/plugin install agentkit@scalekit-auth-stack
Cursor Code REPL
# ~/.cursor/mcp.json
{
""mcpServers"": {
""whatsapp"": {
""url"": ""https://mcp.scalekit.com/whatsapp"",
""headers"": { ""Authorization"": ""Bearer $SCALEKIT_TOKEN"" }
}
}
}
Codex Code REPL
# ~/.codex/config.toml
[mcp_servers.whatsapp]
url = ""https://mcp.scalekit.com/whatsapp""
auth_env = ""SCALEKIT_TOKEN""
Copilot Code REPL
# .vscode/mcp.json
{
""servers"": {
""whatsapp"": {
""url"": ""https://mcp.scalekit.com/whatsapp"",
""type"": ""http""
}
}
}