Multiple webhook URLs for the WhatsApp Cloud API
2026-10-09
The WhatsApp Business Cloud API delivers messages webhooks to the callback URL
configured on your Meta app. Three levels exist, and knowing them saves hours:
The three webhook levels
App level: the default. One URL in App Dashboard → WhatsApp → Configuration receives events for every WABA and number the app serves. WABA level: an "alternate callback URL" can override the app URL for one WhatsApp Business Account. Phone number level: a further override for a single number. Overrides replace — they do not add. At every level it is still one URL.
Why this bites real businesses
A store using a BSP-connected tool for order confirmations typically has that tool's URL at the WABA level. The day you also want messages in your own CRM, an analytics sheet, or an n8n automation, there is nowhere to put the second URL — and swapping URLs back and forth loses events during the gap.
What works
Set one URL you control at the appropriate level, and fan out behind it. The relay
must answer the hub.challenge GET within seconds, verify
X-Hub-Signature-256 against your app secret on the raw body, return 200
immediately (Meta retries with backoff and will eventually disable delivery to a failing
endpoint), split batched entry arrays, and route by
phone_number_id or WABA id so each brand's messages reach that brand's tools.
If a destination expects Meta's signature, re-sign the forwarded body with that tool's own
app secret — passing the original header through fails because the body was re-wrapped.
Relayo does exactly this: one URL per app, WABA or number — routed to every tool, each copy signed the way that tool expects.
Get early access to Relayo