What is an unofficial WhatsApp API? How QR-based APIs work — and the risks
Search for "WhatsApp API" and you'll find two very different worlds. The official WhatsApp Business API, sold through Meta's Business Solution Providers, requires business verification, template approval and per-conversation fees. And then there's a growing category of unofficial WhatsApp APIs — services that connect your own WhatsApp number through a QR scan, exactly like WhatsApp Web does. TextMeFlow is in that second category, so let's be honest about how it works and what the trade-offs are.
How a QR-based WhatsApp API works
WhatsApp supports linked devices: your phone holds the account, and up to several companion devices (your browser, your desktop app) hold a paired session. An unofficial API uses that same multi-device protocol. You scan a QR code once, the service persists the session, and from then on it can send and receive messages on behalf of your number — driven by an HTTP API instead of a keyboard.
That's the whole trick. There's no Meta contract, no business verification, no template review. Your number stays yours; the API is effectively a programmable linked device.
What you gain
- Speed: from signup to first message in minutes, not weeks of verification.
- Your own number: customers see the number they already know, not a new business identity.
- No per-message conversation fees: you pay a flat subscription for capacity.
- Freedom in message content: no pre-approved template catalogue — any text, any time, within the rules below.
What you risk — and this part matters
Meta does not endorse unofficial APIs. A number that behaves like a spam cannon — hundreds of identical messages to people who never opted in — can get banned, sometimes permanently. Anyone who sells you an unofficial API without mentioning this is not being straight with you.
The risk is manageable, though, and behaviour is the deciding factor. Numbers that message people who expect the message, at a human-ish pace, with easy opt-out, keep working for years. That's why TextMeFlow ships an enforced anti-spam pipeline rather than a checkbox: per-number rate limits (1 msg/sec, 60/min, 1,000/hour), a risk score on outgoing batches, automatic STOP handling and quiet hours. The anti-spam documentation describes exactly what's enforced and why.
When the official API is the better choice
An unofficial API is not the right tool for everything. If you're a bank sending authentication codes at massive scale, if you need Meta's green verified badge, or if your compliance department requires a Meta-contracted provider — use the official Business API. The trade-off is real: verification effort and per-conversation cost in exchange for Meta's blessing.
For a B&B sending booking confirmations, a garage sending "your car is ready" photos, or a SaaS sending alerts to its own customers, the unofficial route is dramatically simpler — and with opt-in and rate limiting, the ban risk stays low.
Questions to ask any unofficial API provider
- Where is my data hosted? TextMeFlow: EU (Paris, France), with an automatic GDPR data processing agreement on paid plans.
- What happens when I hit limits? Explicit quotas with a warning at 80% — never silent throttling. See rate limits & quotas.
- Is anti-ban protection enforced or advisory? Enforced, at the API layer.
- Can I receive replies? Yes — HMAC-signed webhooks with retries.
- Can I leave easily? Your number is yours; unlink it any time from your phone's linked-devices screen.
Try it without commitment
The honest way to evaluate an unofficial WhatsApp API is to run a small real workload on it. TextMeFlow's free plan gives you 50 messages per month, forever — enough to wire up a booking confirmation or an alert flow and see it work end to end. Create a free account and send your first message in about five minutes.
Zelf WhatsApp-berichten versturen via API?
Gratis voor altijd tot 50 berichten/maand. QR scannen en binnen 5 minuten verstuur je je eerste bericht.
Gratis voor altijd