Waba Embedded Signup

sentdm/sent-plugin/plugins/sent/skills/waba-embedded-signup

作者 sentdme3d91640fb6f48601c17ddb4ff3df2d3a5f81d6f無授權條款48 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫6 天前更新

Guides WhatsApp Business Account onboarding through Sent, separating dashboard Embedded Signup, organization WABA inheritance, and direct child-profile credentials. Use for WABA connection, Meta signup, profile creation, access-token handling, phone number mapping, completion callbacks, or WhatsApp onboarding failures.

僅含說明DevOps & Cloud
AI 產生的概覽

指導透過 Sent 完成 WhatsApp Business 帳號接入,涵蓋嵌入式註冊、WABA 繼承與專用憑證。

功能
此技能說明 Sent 中三條不同的 WhatsApp Business 帳號接入路徑:透過儀表板完成的組織嵌入式註冊、建立子設定檔時繼承組織 WABA,以及為子設定檔提供專用 WABA 憑證。它記錄驗證標頭、設定檔建立內容、設定檔完成呼叫與其回呼封包、上線就緒檢查,以及故障處理路徑。產出的是指引與參考資料,而非程式碼或檔案。
適用情境
適用於連接 WhatsApp Business 帳號、處理 Meta 註冊、建立或完成 Sent 設定檔、對應電話號碼、管理存取權杖,或診斷 422、403 等 WhatsApp 上線故障的情況。
執行需求
不隨附指令碼,僅為說明與參考文件。需要可存取 Sent API 與儀表板、Meta 嵌入式註冊,以及用於注入存取權杖的密鑰管理服務。

WABA Onboarding and Embedded Signup

Keep three integration paths distinct. Calling all of them “Embedded Signup” creates wrong API designs and unsafe credential handling.

The three paths

PathWhere it startsProfile behavior
Organization Embedded SignupSent dashboardConnects the organization's WABA through the hosted Meta flow. There is no public Sent endpoint that starts this flow.
Organization WABA inheritancePOST /v3/profilesOmit whatsapp_business_account; the child inherits the organization's connected WABA.
Dedicated child-profile WABAPOST /v3/profilesSupply whatsapp_business_account.waba_id and .access_token; phone_number_id is optional.

If credentials are omitted and the organization has no connected WABA, profile creation returns 422. Direct WABA credentials are a profile-creation feature, not a public “Embedded Signup endpoint.”

Authentication

Use either:

  • a profile-specific key in x-api-key; or
  • an organization key in x-api-key plus x-profile-id when operating for an existing child profile.

Only organization keys may use x-profile-id; profile keys receive 403. x-sender-id is legacy v1/v2 terminology.

Path A: organization Embedded Signup

  1. An authorized organization administrator opens the Sent dashboard WhatsApp connection flow.
  2. The hosted Meta Embedded Signup UI collects the Meta authorization and WABA/number choices.
  3. Confirm the organization shows a connected WABA before creating inheriting children.
  4. Record non-secret identifiers and audit who completed the action.

Do not invent a POST /embedded-signup or token-exchange endpoint in Sent's public API. If building your own Meta Tech Provider integration outside the Sent dashboard, follow Meta's current documentation and keep that system separate from the Sent API contract.

Meta's browser postMessage events use an event field and nested data/session information. Do not rewrite them as Sent webhook sub_type envelopes.

Path B: inherit the organization WABA

Omit whatsapp_business_account:

json
{  "name": "Tenant Support",  "description": "Synthetic child profile",  "short_name": "SUPPORT",  "inherit_templates": true,  "billing_model": "organization",  "sandbox": true}

Use this only after the organization WABA is connected. Inheritance means the tenant shares that WABA boundary; confirm this matches the tenant/brand architecture.

Path C: dedicated WABA credentials

json
{  "name": "Dedicated Tenant",  "whatsapp_business_account": {    "waba_id": "123456789012345",    "phone_number_id": "987654321098765",    "access_token": "<injected secret>"  },  "sandbox": true}

waba_id and access_token are required. phone_number_id is optional: when omitted, the current contract describes provisioning and registration during onboarding.

The token needs the applicable WhatsApp Business messaging and management permissions. Inject it from a secret manager. Never log it, echo it, write it to fixtures, return it to the browser, include it in support output, or retain it in general profile storage. Sent does not return it in API responses.

Complete the profile

Call POST /v3/profiles/{profileId}/complete with the required webHookUrl:

json
{  "webHookUrl": "https://example.com/webhooks/profile-complete",  "sandbox": true}
  • 202 means background processing started; there is no final status in that response.
  • 200 can mean the profile was already complete and currently demonstrates lowercase completed.
  • The completion callback can report COMPLETED, SUBMITTED, or failed.

Treat the completion callback as its own integration surface. Its envelope uses event, not sub_type:

json
{  "event": "COMPLETED",  "profile_id": "00000000-0000-0000-0000-000000000000",  "timestamp": "2026-08-09T12:00:00Z"}

Preserve unknown event strings. Verify authenticity using the mechanism Sent documents for the callback endpoint and make processing idempotent.

Verify operational readiness

  • Profile WABA ID matches the intended business.
  • Selected number is mapped to the intended profile.
  • Template sharing/inheritance is intentional.
  • A test template can be created with sandbox: true.
  • The completion callback is reachable and idempotent.
  • Returned message IDs are stored against the tenant/profile before webhook processing.
  • Tokens and payment values are absent from logs.

For ordinary message and template webhooks, follow Sent's current events reference; those are separate from Meta browser events and profile-completion callbacks.

Failure routing

FailureNext action
422 when credentials are omittedConnect the organization WABA or provide dedicated credentials.
403 with profile key and x-profile-idRemove x-profile-id or use an authorized organization key.
Wrong WABA/numberStop before completion and correct the profile mapping.
Expired/under-scoped tokenReplace it securely; never print it while diagnosing.
Completion remains submittedInspect prerequisite and callback evidence; do not assume final failure from the 202.

Use references/waba-embedded-signup-spec.md [blocked], references/waba-onboarding-runbook.md [blocked], and references/whatsapp-sender-profile-mapping.md [blocked]. Use sender-profile-architect for tenant boundaries and waba-template-author for the first template.

來源與署名

來源:sentdm/sent-plugin位於plugins/sent/skills/waba-embedded-signup提交e3d9164

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架