WhatsApp Embedded Signup in 2026: History Import, Health Check, and Error 2018278
I connected my own WhatsApp number through Embedded Signup in one sitting, without opening Meta's developer dashboard once. No app creation, no token juggling, no webhook URL to paste. I clicked connect inside OT1-Pro, logged into Facebook, picked my Business Portfolio, verified my number with an OTP code, and the official Cloud API number was live. Then the part I did not expect kicked in: every Messenger and Instagram chat I had ever had started importing, so the AI had context on day one.
I built OT1-Pro as a single inbox for WhatsApp, Messenger, Instagram, Telegram and email, because I was tired of telling founders to hire a developer just to receive a WhatsApp message. This post is the exact record of what I shipped: how Embedded Signup really works, what Meta rejects, how the health check keeps the subscription alive, why I import full chat history on connect, and why error 2018278 will ruin your first bulk send if nobody warns you.
If you have not yet fought Meta's two-milestone verification chain, start with Meta App Verification 2026: A Founder's Guide. That guide covers Business Portfolio verification plus App Review with Advanced Access. Everything below assumes OT1-Pro's app already cleared those two milestones, which is why you get to skip them.
Why I killed the old token-paste setup
The old way to connect WhatsApp Cloud API looked like this: create a Meta app, add the WhatsApp product, create a WhatsApp Business Account, add a phone number, generate a permanent system-user token, copy the phone-number ID and WABA ID into our settings form, then manually subscribe the app to webhooks. I watched three separate founders paste the wrong phone-number ID into the WABA ID field. One pasted a test number and spent two days debugging inbound messages that were never going to arrive.
Embedded Signup removes all of that. Meta hosts the whole flow inside a popup. You log in with Facebook, you pick the Business Portfolio, you pick or create the WhatsApp Business Account, you pick the phone number, you approve the permissions. Meta hands OT1-Pro back an authorization code, and our backend exchanges it for the WABA ID, phone-number ID and a long-lived system-user token without you touching any of it. There is no developer step left for you.
I kept the old manual fields in the database for migration, but no new customer should ever see them. If you can log into Facebook and receive an SMS, you can connect.
What Embedded Signup actually asks you for
Here is the numbered flow I shipped, exactly as you will see it inside OT1-Pro:
- Click Connect WhatsApp. We open Meta's Embedded Signup dialog with the exact scopes the Cloud API needs: business_management, whatsapp_business_messaging and whatsapp_business_management.
- Log into Facebook and pick your Business Portfolio. Use the Portfolio that owns your company domain. If you pick a personal or empty Portfolio, your display name will fail later.
- Pick or create the WhatsApp Business Account. Most founders pick the existing WABA. If you have none, Meta creates one under that Portfolio inside the popup.
- Claim the phone number. Enter the number you want customers to message. It must be able to receive an OTP voice call or SMS during the popup. It cannot already be on the WhatsApp consumer app or on another WABA.
- Submit the display name. This is what customers see instead of your number. Type your exact business name.
- Approve and return. Meta redirects back to OT1-Pro with an authorization code. Our backend exchanges it, stores the token server-side, subscribes webhooks, runs the health check, and starts the history import.
- Send a test message. Message your new number from your personal phone, watch it land in the OT1-Pro inbox, and reply from the inbox. You are live on the official Cloud API.
Total time for my own number: eleven minutes, including waiting for the OTP call. Total developer dashboard pages opened: zero.
Display-name rules that reject real businesses
Display-name review is where Embedded Signup founders get their first rejection email, usually two to six hours after they thought they were done. I have now seen every variant. Meta's reviewer checks three things, and all three are literal:
First, no generic names. "Customer Support", "Sales Team", "Store", "Service Center" are all rejected on sight. The name must identify a business or product. "Nile Dental Clinic" passes. "Dental Support" does not. I tried submitting "Customer Support" on a test WABA just to confirm, and the rejection arrived in 41 minutes.
Second, no emojis, trademark symbols, or leading punctuation. No "Nile Dental 🦷", no "Nile™ Dental", no "-Nile Dental-". One founder lost three days because his brand stylizes as "BRAND™" on his website and he copied it character for character.
Third, the name must visibly match your domain. If your website is niledental.com, submit "Nile Dental Clinic". Do not submit "NDC Smiles" even if that is your Instagram handle. The reviewer opens your domain and compares. Fix it by renaming to the exact title tag of your homepage and resubmitting.
Your number must receive OTP, and it must be clean
Two number problems block Embedded Signup before display-name review even starts. I hit both during testing.
The number must be OTP-capable. Meta calls or texts a six-digit code during the popup to prove you control it. I burned a virtual test range that never received the call, then switched to a normal Egyptian mobile and the code arrived in nine seconds. If the code never arrives, wait five minutes, check the number can receive international calls, then retry once.
The number must be clean. If it is currently registered in the WhatsApp consumer app or Business app, Embedded Signup refuses it with "number already in use". Delete the account from the app first, or pick a different number. Same if it is attached to another WABA. Remove it, wait ten minutes, then claim it.
Subscription health check: the silent killer I automated
Getting connected is half the job. Staying connected is the other half, and this is where I lost messages for a customer for six hours before I understood what had happened.
Meta delivers inbound WhatsApp messages through a webhook subscription with two layers: the app-level subscription on our Meta app, and the WABA-level subscription on your business account. Either layer can silently drop after a password change or an admin removing the app. Inbound stops while sending still works, so it looks like customers went quiet.
So I shipped a subscription health check that runs after every connect and on a schedule. It queries the Graph API for the subscribed fields on both layers and resubscribes anything missing. You see a green "Healthy" badge or a red "Reconnect needed" badge naming the exact missing field.
| Step | What happens | What breaks | Fix |
|---|---|---|---|
| 1. Embedded Signup popup | Meta returns an auth code for your WABA and number | Wrong Portfolio picked, popup closed early, scopes declined | Reconnect, pick the Portfolio that owns your domain, accept all scopes |
| 2. Code exchange | Backend swaps the code for WABA ID, phone-number ID and system-user token | Expired code after long idle in popup | Run the popup again from the start, codes expire in minutes |
| 3. Number + display name | OTP verification and display-name review submitted | Generic name like Customer Support, emoji or ™, number already in app | Exact business name matching domain, clean OTP-capable number |
| 4. Webhook subscribe | App-layer and WABA-layer fields subscribed | Admin removed app, password reset dropped subscription | Health check resubscribes, or click Reconnect |
| 5. Health check | Required fields verified on both layers | Red badge naming a missing field | One-click resubscribe from connections screen |
| 6. History import | Messenger and IG chats imported with context | Thousands of chats slow first sync, sticker rows look odd | Let the queue finish, stickers render as images, check sync diagnostics |
| 7. First bulk send | Template broadcast with reachable-now count | Error 2018278 on stale contacts outside 24h window | Stale contacts auto-skipped, send template to reopen window |
I check that health badge the way I check server uptime. If it is red, nothing else you do in the inbox matters until it is green again.
The Instagram Direct path most guides skip
WhatsApp gets the headlines, but half my customers connect Instagram in the same session. I shipped the Instagram Direct path alongside Embedded Signup because the failure mode is identical: founder connects, expects history, sees an empty inbox, assumes the connection failed.
Instagram Business Login connects your IG professional account through Facebook Login and subscribes the same webhook stack. The permission that matters is instagram_manage_messages plus pages_messaging for the linked Page. If you connect a personal IG account not linked to a Facebook Page, events never arrive. Convert to a business account, link the Page, then reconnect.
If your Facebook Page itself does not appear during connect, that is almost never a scope problem. It is the Business Portfolio trap: Meta's /me/accounts endpoint only returns Pages where you hold a direct Page role, not Pages assigned through a Portfolio. I wrote the full fix at Facebook Page Not Showing? Business Portfolio Fix. Read that before you blame the popup.
Full chat-history import: AI with context on day one
This is the feature I am proudest of in this release. The moment you connect Messenger or Instagram, OT1-Pro imports the full chat history for every conversation on that Page, not just new messages going forward.
Why I built it this way: an AI sales agent with no history is useless for the first month. It does not know Ahmed asked about installments three weeks ago. With the import, the AI reads the prior thread before its first reply. On my test Page with 400 Messenger threads, the first AI reply referenced a two-month-old delivery complaint, and the customer replied "finally someone remembers".
On connect we page through the Page's conversations endpoint, pull each thread newest-first, and mark sync state per thread. The connections screen shows sync diagnostics: threads found, imported, failed, and last-sync time. If you connect a Page with 5,000 threads, let the queue finish. The AI gets sharper as the backfill completes.
One detail that took a full afternoon: stickers. The old importer stored them as the text "[Sticker]", so the AI replied like a confused robot and the inbox showed a gray bubble. I changed it to keep the sticker image URL and render it as an image bubble, with a text label only as fallback for the AI reader.
The 24-hour window and Meta error 2018278
Here is the rule that ruins every founder's first WhatsApp broadcast: outside a 24-hour customer-service window, you cannot send free-form text. If the customer messaged you within the last 24 hours, you can reply normally. If not, the Graph API returns error 2018278 with the message "The message was not sent because it was sent outside the allowed time frame" and drops the send.
I quote that error code exactly because you will see it. Search your logs for 2018278 and you will find the contacts whose window expired. No retry fixes it. The only way to reopen the window is a pre-approved template message, which the customer can reply to, reopening 24 hours of normal chat.
I built bulk sends around this honestly. When you select 800 contacts, OT1-Pro checks last-inbound time per contact first. Stale contacts are auto-skipped, counted as "skipped: window expired", and shown with a reachable-now count before anything sends. One click then sends the approved template to the skipped group to reopen them.
Tier ladder: 1,000 to unlimited, and how one broadcast resets you
Every new WhatsApp number starts at Tier 1: 1,000 business-initiated conversations per 24 hours. Business-initiated means you messaged first with a template. Customer replies inside the window do not count against the cap. The ladder from there is fixed: Tier 1 at 1,000 per 24h, Tier 2 at 10,000, Tier 3 at 100,000, Tier 4 unlimited. Meta moves you up automatically when your quality rating stays high and your volume justifies it, roughly over a rolling seven-day window. There is no application form for the next tier.
Quality rating is the gate. Green means healthy, yellow warning, red restricted. Drop to red and Meta pushes you back down within a day. I watched a founder on Tier 2 fire one purchased list of 6,000 cold contacts, collect blocks, and wake up back on Tier 1 with the rest hard-capped. The cap is per number, so a second number on the same WABA keeps its tier.
My rules: never start a new number with a cold blast, warm it with opted-in utility traffic first, and pause any template whose block rate spikes.
Dollar math: BSP markup versus $79 flat
Most BSPs charge per conversation on top of Meta's fees: Meta's fee plus $0.02 to $0.05 per marketing conversation as margin, plus a $49 to $149 monthly platform fee. At 20,000 marketing conversations a month, a $0.03 markup alone is $600 in margin before the subscription. At 50,000 it is $1,500.
OT1-Pro pricing is flat: $79 per month with Meta's fees passed through at cost. At 20,000 conversations you pay $79 plus Meta's bill instead of $600 in markup plus a platform fee. Breakeven against a $0.03-markup BSP lands around 2,500 conversations a month.
Now the Tier-1 cost of one bad broadcast. Suppose average order value is $25 and the list converts at 3%. A clean send to 1,000 opted-in contacts is 30 orders, $750 in revenue. Fire that Tier-1 budget at a stale purchased list, eat blocks, and the next days convert near zero while Meta holds you at Tier 1 for another week: roughly $5,000 in forgone revenue plus re-approval delay. I would rather auto-skip 400 stale contacts than burn the number for a vanity sent count.
Compare the full picture at OT1-Pro vs WATI. Per-message markups look small until you multiply them by real broadcast volume.
What I would do in your first hour
If I were connecting today: Embedded Signup with an OTP-capable number, exact business name as display name with homepage title matching, green health badge before inviting the team, Instagram Direct in the same session, let history import finish, then first broadcast to opted-in contacts with the reachable-now count read out loud.
That hour buys you an official Cloud API number with no developer step, an AI that remembers customers from day one, and counts you can trust. Start free here, no credit card.
Stop losing the leads you already earned
OT1-Pro runs your follow-up, analysis, and AI replies in one inbox — WhatsApp, Instagram, Messenger, Telegram, and email, in Arabic or English, scored by lead quality, with every AI credit receipted in a transparent ledger. Free plan, no credit card.
Start free → · Sales follow-up automation · Lead follow-up software · Pricing · vs WATI · Talk to the founder on WhatsApp
Ready to try OT1-Pro?
Connect WhatsApp, Instagram, Facebook & Telegram with AI that sells for you.
Get started free