← All guides

Multiple webhook URLs for the WhatsApp Cloud API

2026-10-09

The WhatsApp Business Cloud API delivers messages webhooks to the callback URL configured on your Meta app. Three levels exist, and knowing them saves hours:

The three webhook levels

App level: the default. One URL in App Dashboard → WhatsApp → Configuration receives events for every WABA and number the app serves. WABA level: an "alternate callback URL" can override the app URL for one WhatsApp Business Account. Phone number level: a further override for a single number. Overrides replace — they do not add. At every level it is still one URL.

Why this bites real businesses

A store using a BSP-connected tool for order confirmations typically has that tool's URL at the WABA level. The day you also want messages in your own CRM, an analytics sheet, or an n8n automation, there is nowhere to put the second URL — and swapping URLs back and forth loses events during the gap.

What works

Set one URL you control at the appropriate level, and fan out behind it. The relay must answer the hub.challenge GET within seconds, verify X-Hub-Signature-256 against your app secret on the raw body, return 200 immediately (Meta retries with backoff and will eventually disable delivery to a failing endpoint), split batched entry arrays, and route by phone_number_id or WABA id so each brand's messages reach that brand's tools. If a destination expects Meta's signature, re-sign the forwarded body with that tool's own app secret — passing the original header through fails because the body was re-wrapped.

Relayo does exactly this: one URL per app, WABA or number — routed to every tool, each copy signed the way that tool expects.

Get early access to Relayo