Setting up the WhatsApp Cloud API with Meta's MCP and an AI agent

Meta's WhatsApp Business Tools MCP lets Claude, Codex or Cursor create the account, register the number and build templates. What that changes for a Shopify store, and the parts it doesn't.

On September 15, 2026 Meta released the WhatsApp Business Tools MCP, a server that lets an AI coding agent such as Claude, Codex, Cursor or ChatGPT act on the WhatsApp Business Platform for you: create the business account, add and verify a phone number, register it for the Cloud API, write and submit message templates, configure webhooks, send a test message. TechCrunch's headline called it the boring parts of WhatsApp Business setup, which is fair. It is also the part that, in our experience, makes half of the Shopify merchants who try the official API give up and go back to a linked-device app.

This article is for a store owner or the developer helping them who wants to know what the MCP actually changes about connecting a Shopify store to the Cloud API, what it leaves exactly as it was, and how the pieces map onto Beacon Messenger's setup screen. It is not a review of the MCP; we have used it for a few days, and it works about as well as the tooling it drives.

What the MCP does

The MCP is a remote server you add to your AI client. You sign in with Facebook Login for Business, pick which of your businesses the agent may see, and grant Read or Manage scope per app. From then on the agent has tools for the WhatsApp Business Platform, and you talk to it in sentences. Meta's documentation groups the tools roughly as:

  • Discovery and prerequisites: list the businesses and WhatsApp Business Accounts you administer, and check whether Terms of Service are accepted, Business Verification is done and a payment method is on file. If something is missing it tells you which screen to go to.
  • Onboarding: create a WhatsApp Business Account, add a phone number with a display name, trigger the SMS or voice one-time code, and register the number for the Cloud API. You still type the code; the agent cannot receive it.
  • Templates: create or edit a message template from a description, and report its category and approval status.
  • Webhooks: set the callback URL and verify token on the app and subscribe to fields such as messages.
  • Testing: send a message from the registered number to a number you control.

Two design choices are worth noticing. Access is scoped to the businesses you select, not to everything your Meta account can touch. And the flow is built so that access tokens do not end up in the prompt history; the agent calls Meta with the session you authorised, rather than with a token you pasted into a chat. That second point matters more than it sounds, and we come back to it below.

Meta keeps this server separate from the Meta Social Technologies MCP, which is about the developer platform in general: Graph API endpoints, error lookup, app status, documentation search. If your agent has that one connected instead, it can explain the WhatsApp API to you but not operate it.

Which setup steps it takes over, and which it does not

Our Cloud API notifications guide walks through the manual setup. Here is the same list with a column for the MCP and a column for what Beacon Messenger ultimately needs from each step.

Cloud API setup steps for a Shopify store, before and after the MCP
StepManual (Business Manager / Developer Console)With the MCPWhat Beacon Messenger needs
Meta developer app with the WhatsApp productCreate in the Developer ConsoleStill manual; the MCP works with apps you already haveThe app secret
WhatsApp Business AccountCreate in Business settingsAgent creates itThe WABA ID
Phone number added, verified, registeredSeveral screens plus an SMS codeAgent adds and registers; you type the codeThe phone number ID
Business Verification, Terms, payment methodHunt through Business settings and BillingAgent checks and points at the missing oneNothing directly, but sends fail without them
Message templatesTemplate editor, one at a timeAgent drafts and submits from a descriptionApproved templates to map to each automation
Webhook callback and verify tokenPaste into the app's WhatsApp configurationAgent sets them if you give it the valuesThe values come from Beacon Messenger's WhatsApp page
Permanent System User tokenBusiness settings, System users, Generate tokenNot part of the MCP flowThe token, entered once and stored encrypted

Read down the last column and a pattern shows: the MCP removes the clicking, not the outputs. At the end you still have four identifiers to copy into Beacon Messenger (WABA ID, phone number ID, permanent token, app secret), and one pair to copy the other way (callback URL and verify token). The agent can read the first three IDs back to you; the permanent token you still create yourself, on purpose.

Templates are where the time actually goes

Ask any merchant who has run Cloud API notifications for a year what took the longest and it will not be the phone number. It will be templates: getting the wording past Meta's review, keeping the category as utility rather than marketing, and rewriting when a template gets paused for quality. The MCP helps with the first draft and with the round trips. Describe the message (order confirmation, one variable for the order number, one for the total, a button that opens the order status page) and the agent produces a compliant template body and submits it.

What it cannot do is change the rules the template is judged against:

  • Utility templates must be about a transaction the customer already has with you. The moment a shipping update includes a discount code for the next order, reviewers can reclassify it as marketing, at a marketing rate and subject to marketing opt-in.
  • Approval is still a review, still takes from minutes to a day or more, and still rejects for things like placeholders at the very start or end of the message. The agent reports the status; it does not speed the queue.
  • A template's quality rating still comes from how recipients react to it. Blocks and reports pause it regardless of who wrote it.
  • Beacon Messenger loads the approved templates from your WhatsApp Business Account when you save the connection, and lets you map them to the order confirmation, shipping, cash-on-delivery and abandoned-checkout automations. A template that is pending or rejected is not offered, so drafting it well the first time still saves the most time.

Consent, the 24-hour window and billing are untouched

The MCP is a setup tool. Nothing about the messaging policy moves. You still need a documented opt-in before you send a customer a template they did not ask for; for a Shopify store that is a checkbox at checkout or a stored marketing consent, not the fact that they gave you a phone number for delivery. Free-form replies are still only possible inside the 24-hour customer service window a customer opens by writing to you. And the pricing change on October 1, 2026, which we covered in detail last week, arrives on schedule: service messages become billable beyond a monthly allowance, and utility templates inside the window are charged.

One item from that change has a deadline of tomorrow. Meta's notice says that a business without a payment method on file by September 30, 2026 will stop having service messages delivered once they become chargeable. The MCP's prerequisite check will tell you whether a payment method is attached. If you do nothing else with it this week, ask it that one question.

Security: what to hand the agent and what to keep

An agent that can register phone numbers and edit templates is operating with real authority over a channel your customers trust. A few habits keep that safe.

  • Grant the MCP access to the one business it needs, at the scope it needs. Meta lets you adjust each app's Read or Manage scope afterwards from Business Integrations settings; revoke Manage when setup is done.
  • Do not paste a permanent System User token into a chat, ever, even if the agent asks for it to "finish the job". The MCP is designed so it does not need one. The token belongs in exactly one place: the WhatsApp page of the app that sends your messages, where Beacon Messenger encrypts it at rest and only uses it to call graph.facebook.com.
  • Treat the verify token the same way. It is a shared secret between Meta and Beacon Messenger's webhook endpoint. Giving it to the agent to configure the webhook is fine; leaving it in a shared conversation log afterwards is not.
  • Read back what the agent did. After a session, open Business settings and confirm the number, the templates and the webhook subscription look like what you asked for. Agents are confident and occasionally wrong, and Meta will not undo a template submission because a model misread you.

After setup: the part no MCP covers

Once the connection is saved, the interesting work is operational. Did the shipping update for order #4821 deliver? Was it read? Did the customer reply Cancel to the cash-on-delivery confirmation, and did the order get tagged? Those answers come from the webhook events Meta sends to the callback URL, and from the app that receives them. Beacon Messenger keeps a per-message log with sent, delivered, read and failed states, retries transient failures, and enforces a hard monthly message cap so a runaway automation cannot turn into a surprise invoice. Our delivery verification post explains how to read that log.

The MCP makes the first afternoon shorter. The following twelve months are the same as they were, and that is where choosing the official API over a linked phone pays off: a channel Meta can see, with receipts you can audit, at a price you can predict.

If you are starting from zero, Beacon Messenger walks you through the same fields the table above lists, with links to the exact Meta screens, and shows the number's verified name and quality rating as soon as the connection is saved so you know the credentials are right before the first order comes in.

Frequently asked questions

Can an AI agent set up the WhatsApp Cloud API for my Shopify store?

Most of it. With Meta's WhatsApp Business Tools MCP an agent can create the WhatsApp Business Account, add and register the phone number, draft and submit templates and configure the webhook. You still type the verification code, create the permanent System User token and enter the resulting IDs and token into the app that sends your notifications.

Does the Meta MCP replace a Shopify WhatsApp app?

No. The MCP configures the Meta side once. It does not watch your Shopify orders, send templates when an order ships, receive delivery receipts or let customers confirm a cash-on-delivery order. That is what an app like Beacon Messenger does, using the WABA ID, phone number ID, token and app secret the setup produces.

Is it safe to give an AI agent access to my WhatsApp Business Account?

Meta scopes access to the businesses you choose and to Read or Manage per app, and the flow avoids putting access tokens in the chat. Keep the permanent token out of the conversation, lower the scope to Read once setup is done, and check Business settings afterwards to confirm what the agent changed.

Will templates created by an AI agent be approved faster?

No. Review and approval are the same process regardless of who submits the template. The agent helps by producing a compliant first draft and by reporting status without you opening the template editor, which saves round trips rather than queue time.

More guides