waba-embedded-signup
sentdm/sent-plugin
Guide WhatsApp Business Account onboarding through Sent with three distinct integration paths: dashboard Embedded Signup, WABA inheritance, and dedicated credentials.
What is waba-embedded-signup?
This skill manages WhatsApp Business Account (WABA) onboarding via the Sent platform, distinguishing between organization-level Embedded Signup, WABA inheritance for child profiles, and direct credential injection. Use it when connecting WABAs, handling Meta authorization, mapping phone numbers, managing access tokens, or troubleshooting onboarding failures.
- Separate organization Embedded Signup (dashboard-initiated) from WABA inheritance (omit credentials) and dedicated child-profile WABA (supply waba_id and access_token)
- Manage authentication using profile-specific or organization API keys with optional x-profile-id header
- Handle profile completion via POST /v3/profiles/{profileId}/complete with webhook callbacks
- Map phone numbers to profiles and verify WABA/number alignment before completion
- Route onboarding failures (422, 403, expired tokens, wrong WABA) to appropriate remediation steps
- Ensure credentials are never logged, echoed, or returned in API responses
How to install waba-embedded-signup
npx skills add https://github.com/sentdm/sent-plugin --skill waba-embedded-signup- Sent API access with organization or profile-specific API key
- Meta Business Account and WhatsApp Business Account (for dedicated WABA path)
- Webhook endpoint for profile completion callbacks (reachable and idempotent)
- Secret manager for storing and injecting access tokens
How to use waba-embedded-signup
- 1.Choose your integration path: organization Embedded Signup (dashboard), WABA inheritance (omit credentials), or dedicated WABA (supply waba_id and access_token)
- 2.For inheritance, POST to /v3/profiles with name, description, and inherit_templates=true; omit whatsapp_business_account
- 3.For dedicated WABA, POST to /v3/profiles with whatsapp_business_account object containing waba_id, access_token, and optional phone_number_id
- 4.Call POST /v3/profiles/{profileId}/complete with webHookUrl and sandbox flag to start background processing
- 5.Verify the profile WABA ID, phone number mapping, and template inheritance match your tenant architecture
- 6.Implement the completion callback endpoint to handle COMPLETED, SUBMITTED, or failed events with event field (not sub_type)
- 7.Test with sandbox=true and confirm a test template can be created before production use
Use cases
- Onboard a new tenant with inherited WABA access from the organization's connected Meta account
- Provision a dedicated WABA for a tenant by injecting waba_id and access_token during profile creation
- Complete profile setup and verify the completion callback is reachable and idempotent
- Diagnose and resolve 422 errors when credentials are omitted and no organization WABA exists
- Verify template sharing, sandbox mode, and message ID storage before production deployment
- Backend engineers building multi-tenant WhatsApp integrations on Sent
- Platform teams managing WABA connections and profile lifecycle
- DevOps/security teams handling credential injection and secret management
- Integration architects designing tenant isolation and WABA boundary models
waba-embedded-signup FAQ
Organization Embedded Signup is initiated from the Sent dashboard and connects the organization's WABA through Meta's hosted flow. WABA inheritance is a profile-creation feature where you omit whatsapp_business_account and the child profile inherits the organization's already-connected WABA.
Use dedicated credentials when a tenant needs its own separate WABA (not shared with the organization), or when the organization has no connected WABA. Supply waba_id and access_token in the profile creation request.
A 202 means background processing has started; there is no final status in that response. The actual completion status (COMPLETED, SUBMITTED, or failed) arrives asynchronously via your webhook callback.
Inject tokens from a secret manager and never log, echo, return to the browser, include in support output, or store them in general profile storage. Sent does not return tokens in API responses.
A 422 means credentials are omitted and the organization has no connected WABA. Either connect the organization WABA via the dashboard Embedded Signup flow, or provide dedicated waba_id and access_token in the profile creation request.
Full instructions (SKILL.md)
Source of truth, from sentdm/sent-plugin.
name: waba-embedded-signup description: Guides WhatsApp Business Account onboarding through Sent, separating dashboard Embedded Signup, organization WABA inheritance, and direct child-profile credentials. Use for WABA connection, Meta signup, profile creation, access-token handling, phone number mapping, completion callbacks, or WhatsApp onboarding failures.
WABA Onboarding and Embedded Signup
Keep three integration paths distinct. Calling all of them “Embedded Signup” creates wrong API designs and unsafe credential handling.
The three paths
| Path | Where it starts | Profile behavior |
|---|---|---|
| Organization Embedded Signup | Sent dashboard | Connects the organization's WABA through the hosted Meta flow. There is no public Sent endpoint that starts this flow. |
| Organization WABA inheritance | POST /v3/profiles | Omit whatsapp_business_account; the child inherits the organization's connected WABA. |
| Dedicated child-profile WABA | POST /v3/profiles | Supply whatsapp_business_account.waba_id and .access_token; phone_number_id is optional. |
If credentials are omitted and the organization has no connected WABA, profile creation returns 422. Direct WABA credentials are a profile-creation feature, not a public “Embedded Signup endpoint.”
Authentication
Use either:
- a profile-specific key in
x-api-key; or - an organization key in
x-api-keyplusx-profile-idwhen operating for an existing child profile.
Only organization keys may use x-profile-id; profile keys receive 403. x-sender-id is legacy v1/v2 terminology.
Path A: organization Embedded Signup
- An authorized organization administrator opens the Sent dashboard WhatsApp connection flow.
- The hosted Meta Embedded Signup UI collects the Meta authorization and WABA/number choices.
- Confirm the organization shows a connected WABA before creating inheriting children.
- Record non-secret identifiers and audit who completed the action.
Do not invent a POST /embedded-signup or token-exchange endpoint in Sent's public API. If building your own Meta Tech Provider integration outside the Sent dashboard, follow Meta's current documentation and keep that system separate from the Sent API contract.
Meta's browser postMessage events use an event field and nested data/session information. Do not rewrite them as Sent webhook sub_type envelopes.
Path B: inherit the organization WABA
Omit whatsapp_business_account:
{
"name": "Tenant Support",
"description": "Synthetic child profile",
"short_name": "SUPPORT",
"inherit_templates": true,
"billing_model": "organization",
"sandbox": true
}
Use this only after the organization WABA is connected. Inheritance means the tenant shares that WABA boundary; confirm this matches the tenant/brand architecture.
Path C: dedicated WABA credentials
{
"name": "Dedicated Tenant",
"whatsapp_business_account": {
"waba_id": "123456789012345",
"phone_number_id": "987654321098765",
"access_token": "<injected secret>"
},
"sandbox": true
}
waba_id and access_token are required. phone_number_id is optional: when omitted, the current contract describes provisioning and registration during onboarding.
The token needs the applicable WhatsApp Business messaging and management permissions. Inject it from a secret manager. Never log it, echo it, write it to fixtures, return it to the browser, include it in support output, or retain it in general profile storage. Sent does not return it in API responses.
Complete the profile
Call POST /v3/profiles/{profileId}/complete with the required webHookUrl:
{
"webHookUrl": "https://example.com/webhooks/profile-complete",
"sandbox": true
}
202means background processing started; there is no final status in that response.200can mean the profile was already complete and currently demonstrates lowercasecompleted.- The completion callback can report
COMPLETED,SUBMITTED, orfailed.
Treat the completion callback as its own integration surface. Its envelope uses event, not sub_type:
{
"event": "COMPLETED",
"profile_id": "00000000-0000-0000-0000-000000000000",
"timestamp": "2026-08-09T12:00:00Z"
}
Preserve unknown event strings. Verify authenticity using the mechanism Sent documents for the callback endpoint and make processing idempotent.
Verify operational readiness
- Profile WABA ID matches the intended business.
- Selected number is mapped to the intended profile.
- Template sharing/inheritance is intentional.
- A test template can be created with
sandbox: true. - The completion callback is reachable and idempotent.
- Returned message IDs are stored against the tenant/profile before webhook processing.
- Tokens and payment values are absent from logs.
For ordinary message and template webhooks, follow Sent's current events reference; those are separate from Meta browser events and profile-completion callbacks.
Failure routing
| Failure | Next action |
|---|---|
422 when credentials are omitted | Connect the organization WABA or provide dedicated credentials. |
403 with profile key and x-profile-id | Remove x-profile-id or use an authorized organization key. |
| Wrong WABA/number | Stop before completion and correct the profile mapping. |
| Expired/under-scoped token | Replace it securely; never print it while diagnosing. |
| Completion remains submitted | Inspect prerequisite and callback evidence; do not assume final failure from the 202. |
Use references/waba-embedded-signup-spec.md, references/waba-onboarding-runbook.md, and references/whatsapp-sender-profile-mapping.md. Use sender-profile-architect for tenant boundaries and waba-template-author for the first template.
Related skills
More from sentdm/sent-plugin and the wider catalog.

waba-template-author
Author, validate, and submit WhatsApp templates against Sent v3 contract with policy review.

messaging-performance-analyzer
Diagnose message delivery failures, funnel drop-offs, and performance anomalies using Sent API data.

migrate-to-sent
Plan and execute safe migration from Twilio, Sinch, Infobip, Vonage, or MessageBird to Sent v3.

rcs-agent-onboarding
Guide RCS and RBM onboarding, carrier approval, templates, and safe routing for Sent messaging.

commit-all
Gather all working tree changes into a single commit on the current branch.

dashfix
Enforce plain hyphens over typographic dashes in English prose and audit existing dash usage.