Product
WhatsApp MCP: how AI agents connect to WhatsApp Business, safely
The Model Context Protocol lets assistants like Claude and ChatGPT use real tools. Meta now has an MCP for setting up WhatsApp Business, and Buddy is planning one for the day-to-day work of running a channel. Here is what each does, what's live and what's still a plan.
The Buddy Team · · 13 min read
Product
WhatsApp MCP
A WhatsApp MCP is a server that lets an AI assistant, such as Claude or ChatGPT, work with WhatsApp Business tools through the Model Context Protocol, an open standard for connecting AI applications to external systems. Meta launched its own WhatsApp Business Tools MCP on 15 September 2026 for setup and testing. Buddy MCP, for running campaigns and audiences, is planned.
That one paragraph hides a lot of detail that matters if you're deciding whether to let an agent near your WhatsApp number. This guide explains what MCP actually is, exactly what Meta's server can and can't do, where WhatsApp's AI rules draw the line, and how we're designing Buddy MCP so that an assistant can do useful work without ever sending a message you didn't approve.
What is the Model Context Protocol (MCP)?
MCP is an open-source standard that gives AI applications one consistent way to reach data, tools and workflows outside the model. The project's own analogy is a USB-C port: instead of every assistant building a custom connector for every service, a service publishes one MCP server and any compatible assistant can use it. The MCP site lists Claude, ChatGPT, Visual Studio Code and Cursor among the clients that support it.
The architecture overview describes three participants. The host is the AI application you talk to. It creates one client for each server it connects to, and each server is a program that provides context and actions. Servers can run locally on your machine or remotely on a company's infrastructure, which is how most business tools will offer them.
| MCP primitive | What it is | WhatsApp example |
|---|---|---|
| Tools | Functions the assistant can call to take an action | Create a message template, list phone numbers, send a test message |
| Resources | Data the assistant can read for context | A template's approval status, a campaign's delivery numbers |
| Prompts | Reusable templates that structure a task | "Draft a re-engagement message for people who haven't clicked in 60 days" |
One more piece matters for anything touching customers: MCP lets a server ask the user for input mid-task, a feature the protocol calls elicitation. The specification explicitly mentions using it to ask for confirmation of an action. That is the natural place for a "yes, send this to 4,200 people" step, and it's a big part of how we intend Buddy MCP to work.
What is Meta's WhatsApp Business Tools MCP?
On 15 September 2026 Meta announced the WhatsApp Business Tools MCP, a server that connects a developer's AI coding agent directly to the WhatsApp Business Platform. Meta's pitch is that getting an integration running normally means hopping between the Developer Console, Business Manager, the API reference and your editor, and pasting access tokens where they shouldn't live. The MCP lets you ask your agent to do that setup instead.
According to Meta's tool reference, the tools cover six areas:
| Area | What the tools do |
|---|---|
| Discovery | List the businesses, WhatsApp Business Accounts and phone numbers you can access, with their status |
| Phone number onboarding | Add a number, send and check the verification code, register it for messaging |
| Message templates | List, inspect, create, update and delete templates, and track approval |
| Messaging | Send free-form text or template messages from a registered number |
| Webhooks | Configure callback URLs and subscribe accounts to webhook events |
| Account setup | Configure payments, check business verification and obtain system user access tokens |
On security, Meta says you sign in with Facebook Login for Business and grant a specific set of scopes, so tokens don't end up in your prompt history. Before any tool runs, the server checks that you're an admin of the app, resolves the attached business and confirms the WhatsApp Business Cloud API Terms of Service are accepted. Requests are rate limited per user per tool. Meta says the server is discoverable in Claude, Codex and ChatGPT, is rolling out gradually, and that the interface and tool set are in beta and may change.
This release is built for development and testing workflows, not production sending at scale.
That sentence is the key to understanding where Meta's MCP fits. It's a developer tool for standing up an integration: getting a number registered, a template approved and a webhook pointed at your server. It is not a marketing platform. It doesn't hold your subscriber list, record consent, sort replies or tell you whether last Tuesday's campaign worked. Those jobs still need a system built for them.
What do WhatsApp's rules say about AI agents?
Two rules shape what any AI connected to WhatsApp can do. The first is about who you message. Meta's opt-in guidance requires that people agree to receive messages from your business on WhatsApp before you contact them. An agent doesn't change that. If anything, it raises the stakes, because an agent can build and send to a list far faster than a person can check it.
The second is about what the AI is. From 15 January 2026, WhatsApp's business terms bar general-purpose AI chatbots, where the assistant itself is the main thing being offered, from the WhatsApp Business Solution, as TechCrunch reported. Bots that serve a specific business purpose, like answering order questions or booking appointments, are still allowed. The Business Messaging Policy also expects a clear path to a human when you automate conversations.
It's worth being precise here. The chatbot rule is about an AI talking to your customers inside WhatsApp. An MCP is usually about an AI helping you, the business, operate your tools from your own assistant. Those are different situations. But the spirit carries over: automation should serve a clear business purpose, people should be able to reach a human, and nobody should receive messages they didn't agree to.
There's also a practical limit an agent can't argue with. WhatsApp caps how many marketing templates each person receives from all businesses, based on their engagement, and a message that falls outside that cap fails with error 131049. Meta's per-user limits page also notes that WhatsApp doesn't currently deliver marketing templates to people with US phone numbers. An agent that fires off a campaign without knowing this will simply produce a lot of failures.
WhatsApp MCP vs the Cloud API vs a platform MCP
People use "WhatsApp MCP" to mean several different things. It helps to separate them, because each has a different job and a different risk profile.
| WhatsApp Cloud API | Meta's WhatsApp Business Tools MCP | A platform MCP (such as planned Buddy MCP) | |
|---|---|---|---|
| Who uses it | Your code | A developer's AI coding agent | A marketer's or operator's AI assistant |
| Main job | Send and receive messages at scale | Set up and test an integration | Run the channel: audiences, drafts, results |
| Knows about consent and opt-outs | No, you build it | No | Yes, it inherits the platform's consent records |
| Knows campaign results | Only raw webhooks | No | Yes, the platform's analytics |
| Production sending | Yes | No, Meta says dev and test only | Only with explicit human confirmation |
| Status | Live | Live, beta, rolling out | Buddy MCP: planned, not built |
The Cloud API is the foundation under all of this. Meta's MCP makes the setup side of it easier to reach from an agent. A platform MCP sits one level up: it exposes the things a business actually manages day to day, and it can refuse actions the platform itself would refuse, like messaging someone who replied STOP.
How Buddy MCP is designed (planned)
Buddy MCP is on our roadmap for after the first 30 days following launch on 12 October 2026. We're publishing the intended design now because the design is the point: an assistant should be able to do the analysis and drafting that eats your afternoon, while the decisions that affect customers stay with you. Here is what we plan.
1. Scoped connections to one workspace
You'll connect an AI client to a single Buddy workspace and choose what it can reach, for example read-only analytics, or reading plus drafting. The plan is for the assistant never to see more than the person who connected it could see in Buddy, so the existing roles (Owner, Admin, Member) and per-number access still apply.
2. Read tools for context
Read tools would let an assistant look at what Buddy already knows: audience size and tags, consent status, campaign results (sent, delivered, read, clicked, replied, failed and why), reply categories, template approval and quality, and your number's health and messaging limit. This is where most of the value is, because it turns questions like "which WhatsNews got replies last month?" into a sentence instead of an export.
3. Write tools that prepare, not publish
Write tools would create things in a draft state: a WhatsNew draft built on an approved template, a suggested tag-based audience, an automation outline, or a new template ready for you to submit to Meta. You'd review them in Buddy just as if a colleague had prepared them.
4. Explicit confirmation for anything high-impact
Sending or scheduling a WhatsNew, changing a live automation, exporting contacts and removing data are the actions we plan to gate behind explicit human confirmation. The confirmation should show what will happen in plain numbers: which template, which audience, how many subscribed recipients, and which number it sends from. The assistant can ask; a person decides.
5. Audit logs
Every call would be logged: which client, which person connected it, what was read, what was drafted, what was requested and what was confirmed or declined. If something goes wrong, you should be able to see exactly how it happened.
6. The platform's rules still apply
An MCP is another door into Buddy, not a way round it. Today Buddy only sends campaigns to subscribed contacts, suppresses anyone who replied STOP or turned off marketing messages, and uses Meta-approved templates outside the 24-hour window. The plan is for MCP actions to go through the same checks, so an assistant can't do anything the app itself wouldn't let you do.
Read (planned)
Audiences, tags, consent, campaign results, reply categories, template status, number health.
Draft (planned)
WhatsNews drafts, suggested audiences, automation outlines, template drafts. Nothing leaves Buddy.
Confirm (planned)
Sends, schedules, live automation changes, exports and deletions need a person to say yes.
Audit (planned)
A log of what each client read, drafted, requested and what was approved.
What could you ask an assistant to do with Buddy MCP?
These are illustrative workflows for the planned server, written as you might type them. None of them works today.
- 1Weekly review. "Summarise last week's WhatsNews: delivery, read and reply rates, the top failure reason, and how many people opted out." The assistant uses read tools and gives you a short report.
- 2Re-engagement draft. "Find subscribers tagged course-waitlist who haven't replied to anything in 60 days and draft a friendly check-in using our approved re-engagement template." The assistant creates a draft and a suggested audience. You review, adjust and confirm the send in Buddy.
- 3Template housekeeping. "Which templates are paused or have low quality, and why?" Then: "Draft a clearer version of the paused one." You submit the new template to Meta yourself.
- 4Pre-send check. "Before I send tomorrow's launch, tell me how many recipients have US numbers and whether the send fits within our messaging limit." The assistant flags that US numbers won't receive marketing templates and suggests splitting the send.
- 5Reply triage. "List everyone in the Question category from yesterday's campaign with their message, grouped by topic." You answer them from the Inbox.
Notice what's missing: "send it" is never the assistant's final step. It's the step where a person looks at a confirmation and decides.
What Buddy's AI does today
Buddy MCP is planned, but some of Buddy's AI is already in the product, and it follows the same principle of a co-pilot, not an autopilot. In the Inbox, Suggest a reply with AI drafts a short reply from the recent conversation, which you edit and send yourself. In Automations, the When a reply is categorised trigger can use AI to sort replies into Interested, Question, Purchased, Follow up or Not now, falling back to keyword rules. In both cases a person or a rule you wrote decides what happens next.
We cover these features, the January 2026 chatbot rule and our human-approval principle in detail in our guide to WhatsApp AI agents, and you can see the Buddy AI roadmap on the Buddy AI page.
How to evaluate any WhatsApp MCP server
Whether it's Meta's, ours or a community project on GitHub, ask these questions before you connect an assistant to a number your customers rely on.
- How does it authenticate? Look for a proper sign-in with scopes (as Meta's uses) rather than pasting a long-lived access token into a config file.
- Can you limit it to read-only? Least privilege should be possible, not just full access or nothing.
- Which actions need confirmation? Sends, exports and deletions should never happen on the model's say-so alone.
- Does it respect consent? A server that can message any number in an uploaded list is a policy risk. It should only reach people who opted in, and honour opt-outs.
- Is there an audit log? You should be able to see what the assistant did, and who connected it.
- What about untrusted text? Customer messages are input written by strangers. A server that feeds replies to a model which can also send messages needs guardrails against instructions hidden in that text.
- Is it the official platform? Unofficial servers that automate the consumer WhatsApp app can put your number at risk. Stick to servers built on Meta's official WhatsApp Business Platform.
What you can do today
If you're a developer standing up a WhatsApp integration, Meta's MCP is worth trying in a test app, keeping in mind Meta's own dev-and-test label. If you want to run a WhatsApp channel, Buddy's app does that now: connect your own number through Embedded Signup, grow a consented list with your opt-in page, send WhatsNews on approved templates, reply from one inbox and automate follow-ups. Our WhatsApp marketing platform guide walks through the full loop.
If you're building your own automation, the Buddy API is in early access today for managing subscribers, with a public beta from 12 October 2026 that adds template sends, campaigns and signed webhooks. Our WhatsApp Business API integration guide covers what's live. And if Buddy MCP is something you'd use, tell us what you'd want it to do on the Buddy MCP page.
WhatsApp MCP: frequently asked questions
Is there an official WhatsApp MCP server?
Yes. Meta announced the WhatsApp Business Tools MCP on 15 September 2026. It helps developers set up WhatsApp Business accounts, numbers, templates and webhooks from an AI agent. Meta says it's in beta, rolling out gradually, and meant for development and testing rather than production sending at scale. Details are in Meta's tool reference.
Can an AI agent send WhatsApp marketing messages for me?
Technically, an agent with the right tools can call the API. Whether it should is another matter. Recipients must have opted in, marketing outside the 24-hour window needs an approved template, and per-user limits apply. We think bulk sends should always need a person's explicit confirmation, which is how Buddy MCP is planned.
Does WhatsApp's 2026 chatbot ban stop me using AI?
No. From 15 January 2026 the rule bars general-purpose AI chatbots, where the assistant is the product, from the WhatsApp Business Solution. AI that supports a specific business purpose, such as suggesting replies or sorting messages, is still allowed, and Meta's policy expects a clear route to a human.
When will Buddy MCP be available?
Buddy MCP is planned for after the first 30 days following our 12 October 2026 launch. Nothing is built yet, so we don't give a date. You can register interest on the Buddy MCP page.
What's the difference between MCP and the WhatsApp API?
The WhatsApp Cloud API is how software sends and receives messages. MCP is a standard way for an AI assistant to discover and call tools. An MCP server for WhatsApp usually wraps the API (or a platform built on it) so an assistant can use it safely, with scopes and confirmations.