WhatsApp and Meta
Purpose
Catalog sync, conversational orders, and messages. Not a MarketplaceRegistry provider.
Authentication
| Piece | Role |
|---|---|
META_APP_SECRET | Webhook HMAC |
META_APP_ID, META_EMBEDDED_SIGNUP_CONFIG_ID | Embedded signup. The app id is also a public admin env (VITE_META_APP_ID) |
| Per-agent tokens | Stored for the agent |
META_CATALOG_PLACEHOLDER_IMAGE | Fallback when a product image is missing or not publicly fetchable |
Direction
Inbound: public WhatsApp webhook. Outbound: Cloud API and meta-commerce catalog sync. Catalog provisioning is Bull queue whatsapp-catalog-provisioning.
Payments
Payment webhooks are public and accept Stripe or Razorpay. Stripe secret storage is on the agent adapter, not the main env block that was read.
Code
src/modules/automation/whatsapp-agent, src/integrations/meta-commerce.
Failure
Unsigned webhooks are rejected when the app secret is unset. See Inbound flow.
Idempotency
Not established for a retried Meta delivery of the same message.