aws-social-messaging
aws/agent-toolkit-for-aws
Manage WhatsApp messaging, templates, media, and delivery tracking via AWS End User Messaging Social.
What is aws-social-messaging?
This skill enables agents to send WhatsApp messages through AWS End User Messaging Social, including template management (create, update, delete), sending utility/marketing/authentication messages, uploading and managing media, configuring delivery event tracking, and diagnosing messaging failures. Use it when you need to integrate WhatsApp messaging into workflows or manage WhatsApp business accounts.
- Create, update, delete, and retrieve WhatsApp message templates with category selection (UTILITY, MARKETING, AUTHENTICATION)
- Send template-based messages (no 24h restriction) and freeform messages (within 24h customer response window)
- Upload, retrieve, and delete media for messages and template headers with reusable media IDs
- Configure event destinations for delivery tracking, template status notifications, and reclassification alerts
- Troubleshoot delivery issues by verifying WABA status, phone number health, template state, and quotas
- Support parameter validation for phone numbers, template names, language codes, and API versions
How to install aws-social-messaging
npx skills add https://github.com/aws/agent-toolkit-for-aws --skill aws-social-messaging- AWS CLI installed and configured with appropriate credentials
- IAM role with scoped permissions for social-messaging actions (templates, sending, media, events, diagnostics)
- AWS MCP server recommended for sandboxed execution and audit logging (optional but recommended)
- WhatsApp Business Account (WABA) linked to AWS account with COMPLETE registration status
- Phone number ID and WABA ID for sending messages
How to use aws-social-messaging
- 1.Verify AWS CLI is installed and configured with credentials; confirm IAM role has required social-messaging permissions
- 2.Retrieve your WABA ID and phone number ID using get-linked-whatsapp-business-account and list-linked-whatsapp-business-accounts
- 3.Create or select a message template using create-whatsapp-message-template or list-whatsapp-template-library; confirm category (UTILITY/MARKETING/AUTHENTICATION) before submission
- 4.Wait for Meta template approval (minutes to 24 hours); check template status using list-whatsapp-message-templates
- 5.Collect recipient phone number (E.164 format with + prefix), template name, language, and any parameters required
- 6.Execute send-whatsapp-message with base64-encoded JSON payload; confirm messageId indicates queued status (not delivery)
- 7.For media: upload via post-whatsapp-message-media to get reusable media ID, then reference in messages or template headers
- 8.Configure event destinations using put-whatsapp-business-account-event-destinations to track delivery and template events via SNS
Use cases
- Send transactional notifications (order confirmations, shipping updates) via WhatsApp templates
- Deliver marketing promotions and campaigns using WhatsApp marketing templates
- Send authentication codes and verification messages via WhatsApp authentication templates
- Reply to customer inquiries within the 24-hour response window with text, image, document, or video
- Upload and manage media assets (images, documents, videos) for reuse across multiple messages
- Backend engineers integrating WhatsApp messaging into applications
- DevOps teams managing WhatsApp business accounts and messaging infrastructure
- Customer support teams automating WhatsApp notifications and responses
- Marketing teams sending WhatsApp campaigns and promotions
- Product teams building messaging workflows with delivery tracking
aws-social-messaging FAQ
UTILITY templates are for transactional messages (order updates, account alerts) and have no 24h restriction. MARKETING templates are for promotions and campaigns; choosing MARKETING incorrectly increases costs. AUTHENTICATION templates are for verification codes; Meta handles OTP parameters automatically. Choose the correct category upfront — reclassification by Meta changes pricing.
Only template-based messages (UTILITY, MARKETING, AUTHENTICATION) have no 24h restriction. Freeform messages (text, image, video, document) require a 24h window after the customer's last inbound message. There is no API to check window status — you must confirm from logs or event history.
Media URLs must be publicly accessible HTTPS and remain available for 30 days (Meta can re-fetch anytime). For sensitive content (receipts, invoices, PII), upload via post-whatsapp-message-media to get a reusable media ID instead — presigned URLs cannot guarantee 30-day availability.
Follow the diagnostic flow: verify WABA registration is COMPLETE using get-linked-whatsapp-business-account, check phone number health with get-linked-whatsapp-business-account-phone-number, confirm template status is APPROVED (not PENDING/REJECTED), verify event destinations are configured for tracking, and check account quotas.
Scope permissions to specific WABA and phone number ARNs. Required actions include social-messaging:SendWhatsAppMessage, social-messaging:CreateWhatsAppMessageTemplate, social-messaging:ListWhatsAppMessageTemplates, social-messaging:PostWhatsAppMessageMedia, social-messaging:PutWhatsAppBusinessAccountEventDestinations, and supporting actions like sns:ListSubscriptionsByTopic and iam:PassRole.
Full instructions (SKILL.md)
Source of truth, from aws/agent-toolkit-for-aws.
name: aws-social-messaging description: Manages WhatsApp messaging through AWS End User Messaging Social. Covers managing templates (create, update, delete, library), sending messages (utility/marketing/auth templates and freeform), uploading and managing media, configuring event destinations for delivery tracking, and troubleshooting delivery failures. Applicable when a user needs to send WhatsApp messages, create or manage templates, upload media, configure delivery notifications, or diagnose messaging issues. version: 1
AWS End User Messaging Social — WhatsApp
Overview
WhatsApp messaging via AWS End User Messaging Social: template management, sending, media handling, event destinations, and delivery troubleshooting.
Recommended setup: Use the AWS MCP server for sandboxed execution, audit logging, and enterprise controls.
Without AWS MCP: This skill works with any agent that has AWS CLI access. All commands use standard AWS CLI syntax.
Common Tasks
1. Verify Dependencies
Constraints:
- The AWS MCP server is recommended for seamless API execution but not required — all commands use standard AWS CLI syntax
- You MUST verify the AWS CLI is installed and configured with appropriate credentials
- You SHOULD recommend the user assume an IAM role with ephemeral credentials
- You MUST inform the user if any required tool is missing and how to install/configure it
- You MUST ask the user if they want to proceed despite any missing tools
- If the
aws socialmessagingsubcommand is not recognized, the user must update to the latest AWS CLI version - Required IAM permissions (scope to specific WABA and phone number ARNs):
- Templates:
social-messaging:CreateWhatsAppMessageTemplate,social-messaging:GetWhatsAppMessageTemplate,social-messaging:ListWhatsAppMessageTemplates,social-messaging:UpdateWhatsAppMessageTemplate,social-messaging:DeleteWhatsAppMessageTemplate,social-messaging:ListWhatsAppTemplateLibrary,social-messaging:CreateWhatsAppMessageTemplateFromLibrary - Sending:
social-messaging:SendWhatsAppMessage - Media:
social-messaging:PostWhatsAppMessageMedia,social-messaging:CreateWhatsAppMessageTemplateMedia,social-messaging:GetWhatsAppMessageMedia,social-messaging:DeleteWhatsAppMessageMedia - Events:
social-messaging:PutWhatsAppBusinessAccountEventDestinations - Diagnostics:
social-messaging:GetLinkedWhatsAppBusinessAccount,social-messaging:GetLinkedWhatsAppBusinessAccountPhoneNumber,social-messaging:ListLinkedWhatsAppBusinessAccounts - Supporting:
sns:ListSubscriptionsByTopic,iam:PassRole(for event destination role)
- Templates:
2. Manage Templates
Create, update, and delete message templates (utility, marketing, authentication).
create-whatsapp-message-template: base64-encode--template-definition(blob type)create-whatsapp-message-template-from-library: use pre-approved Meta library templateslist-whatsapp-template-library: browse available library templatesget-whatsapp-message-template: retrieve template details by--id(WABA) and--meta-template-idupdate-whatsapp-message-template: modify existing template contentdelete-whatsapp-message-template: requires--template-name(NOT--meta-template-name); always include--delete-all-languageslist-whatsapp-message-templates: response fields aretemplateStatusandtemplateCategory(NOTstatus/category)- Templates with
{{N}}parameters MUST include"parameter_format": "positional"(exception: AUTHENTICATION — Meta handles OTP parameters automatically) and"example" - Meta reviews all templates (minutes to 24h); MUST NOT send with PENDING/REJECTED
- Choosing the wrong category causes reclassification (UTILITY → MARKETING) which changes pricing — see managing-templates.md — Choosing the Right Category for guidance on selecting UTILITY vs MARKETING vs AUTHENTICATION
- You MUST confirm the intended category (UTILITY, MARKETING, or AUTHENTICATION) with the user before creating a template — explain the categorization criteria and reclassification risk if the choice is ambiguous
3. Send Messages
Template Messages (no 24h restriction)
- Use for: transactional updates (utility), promotions (marketing), verification codes (authentication)
- Collect: phone number ID, recipient (E.164 with
+), template name, language, parameters - Marketing templates may include image headers
--messageis blob type — MUST base64-encode JSON
Freeform Messages (24h window required)
- Use for: customer service replies within 24h of customer's last inbound message
- Supports: text, image, document, video, audio — see WhatsApp Cloud API media reference for supported format and size constraints
- No API to check window status — user must confirm from logs or event history
- Media URLs MUST be publicly accessible HTTPS and remain available for the full 30-day message availability window (Meta can re-fetch anytime). For sensitive content (receipts, invoices, PII), upload via
post-whatsapp-message-mediaand reference by media ID instead — presigned URLs cannot satisfy the 30-day availability requirement
Constraints for all sends:
- Before executing any API call, validate parameter formats:
- Phone number IDs match
phone-number-id-*pattern - WABA IDs match
waba-*pattern - Recipient numbers are E.164 with
+prefix (e.g.,+14155551234), or Business-Scoped User ID (BSUID) via the"recipient"field - Template names contain only lowercase letters, numbers, and underscores
- Language codes use Meta's locale format with underscores (e.g.,
en_US,pt_BR) --meta-api-versionisv{Major}.{Minor}format (e.g.,v21.0)
- Phone number IDs match
"messaging_product"MUST be"whatsapp"in the JSON body; check Meta's Graph API changelog for the supported Meta Graph API version--messageis blob type — MUST base64-encode the JSON payload- A successful
messageIdmeans queued, not delivered - You MUST ask for all required parameters upfront in a single prompt
- You MUST accept parameters as individual values, JSON objects, or file references
- You MUST explain each step before executing
- You SHOULD confirm all parameters with the user before executing
- You MUST respect the user's decision to abort
- You MUST NOT send more than 5 messages per batch without user confirmation
- You MUST NOT create or access credentials directly
See sending-messages.md.
4. Manage Media
Upload, retrieve, and delete media for messages and template headers.
post-whatsapp-message-media: upload media, returns reusable media IDcreate-whatsapp-message-template-media: upload media specifically for template headersget-whatsapp-message-media: retrieve media metadata/URL by IDdelete-whatsapp-message-media: remove uploaded media
See managing-media.md.
5. Configure Event Destinations
Set up delivery tracking, template status notifications, and reclassification alerts.
Set up delivery tracking, template status notifications, and reclassification alerts. A WABA can only have one event destination. See configuring-event-destinations.md for prerequisites (IAM role, SNS topic with KMS encryption, HTTPS-only subscription endpoints, condition keys) and full security controls.
6. Troubleshoot Delivery
Diagnostic flow: WABA status → phone number → templates → event destinations → quotas.
get-linked-whatsapp-business-account: registration MUST be COMPLETEget-linked-whatsapp-business-account-phone-number: verify phone number healthlist-linked-whatsapp-business-accounts: list all WABAs- Template reclassified: detectable via event destinations (real-time) or by listing templates and comparing categories; delete and recreate
- 24h window expired: use template message instead
- Rate limiting: new WABAs have lower limits; increases with quality
- Recipient without WhatsApp: silently dropped
See troubleshooting-delivery.md.
Quick Reference — Common Errors
- Access denied: verify IAM permissions scoped to WABA/phone number ARNs
- Template rejected: body must match category; include
parameter_formatandexample - Template reclassified: configure event destinations to detect; delete and recreate
- 24h window expired: use template message instead of freeform
- Send fails:
--origination-phone-number-idis the ID (not phone number); recipient E.164 with+ - Queued but not delivered: 200 = queued; configure event destinations for status
- Media URL inaccessible: must be publicly accessible HTTPS
Security Considerations
- Use least-privilege IAM policies scoped to specific
social-messaging:actions and WABA/phone number ARNs - Use ephemeral credentials (IAM roles) instead of long-lived access keys
- Store secrets in AWS Secrets Manager or Parameter Store — never in code or environment variables
- Enable CloudTrail for auditing all
social-messagingAPI calls; encrypt logs with KMS CMK - Encrypt SNS topics for event destinations with KMS (callbacks contain recipient metadata)
- Encrypt CloudWatch Logs with KMS if monitoring social-messaging activity
- Avoid sensitive data in template parameters and freeform message content (they appear in CloudTrail logs)
- Validate recipient phone numbers to prevent unauthorized messaging
- Verify SNS subscription endpoints are authorized by your team — validate that all subscribed email addresses and systems belong to personnel/systems that should receive sensitive delivery status and recipient metadata before confirming subscriptions. Use HTTPS-only endpoints
- Add condition keys (
aws:SourceArn,aws:SourceAccount) to SNS topic policies to prevent confused deputy attacks - Implement rate limiting via service quotas and CloudWatch alarms on send rates
Additional Resources
Related skills
More from aws/agent-toolkit-for-aws and the wider catalog.

aws-step-functions
Author and edit AWS Step Functions state machines with ASL, JSONata, and workflow orchestration patterns.

aws-storage
Choose, configure, and troubleshoot AWS object, file, and block storage services for your workload.

aws-transform
Code upgrades, migrations, and transformations at scale using AWS Transform CLI.

chatting-with-aws-devops-agent
Fast conversational AWS DevOps analysis for cost, architecture, topology, and diagnostics.

cloudfront
Configure Amazon CloudFront content delivery: distributions, caching, certificates, origin protection, content security, and observability.

configuring-vpc-endpoints-for-private-aws-service-access
Configure VPC endpoints for private AWS service access using AWS PrivateLink