security webhook reference | Developer Documentation
Review WhatsApp PIN change notices with ChatArchitect
A security notice about a business number can concern enabling or changing its two-step verification PIN, requesting that verification be turned off, or completing that process. Check the intended number and its current setting before deciding what action is needed.
A ChatArchitect client manages this PIN in WhatsApp Manager. Follow the two-step verification guide for the confirmed client workflow. The PIN is separate from the one-time SMS or voice code used during number verification.
The ChatArchitect API quick start does not specify forwarding of Meta security callbacks or an automatic PIN-management workflow. Obtain confirmation from support before integrating these notices into a custom receiver.
Distinguish a request from a completed change
Meta's security-event reference distinguishes enabling/changing the PIN, requesting to turn off two-step verification, and completing the email reset instructions. A reset request does not establish that two-step verification has already been disabled. Confirm the current state directly for the connected number.
| Situation reported | What to verify |
|---|---|
| PIN enabled or changed | Confirm the number, expected staff action and whether the current two-step setting matches your team's intention. |
| Request to turn off two-step verification | Check whether your team initiated the request and whether any completion occurred; keep request and completion separate in your records. |
| Reset or disabling process completed | Check the number's current setting and whether this was an authorized action before planning any further change. |
Check the setting in WhatsApp Manager
- Identify the business number connected to ChatArchitect, the owning business portfolio and the notice time with time zone.
- Open WhatsApp Manager through your usual trusted account entry point. Go to Account tools → Phone numbers, select the intended number and open Settings → Two-step verification.
- Check the current two-step verification state. If menu labels differ, find that setting on the selected number's page as described in the PIN guide.
- Compare the notice with an expected action by a responsible team member. A delayed notification can describe an earlier operation rather than the present state.
- If a planned change has the intended result, record its non-secret outcome. For enabling, changing or recovering the PIN, follow the normal Manager prompts and the PIN guide.
Do not send your PIN, a one-time verification code, a reset link or your App Secret to support. Provide the affected number, notice time and an error screenshot with confidential values removed when assistance is needed.
If the notice was unexpected
- Ask the responsible administrators whether they initiated the operation and confirm the affected number before making another change.
- Review the authorized people and access to the owning Meta business account using your normal account-management process. Investigate an unexplained action with the account owner.
- Check the current two-step setting and use the normal Manager controls to restore the intended state when you have the required access.
- If the setting is inaccessible or recovery cannot be completed, contact ChatArchitect support with the non-secret details and exact error. Keep the business connection intact while the issue is investigated.
When a notice and the account state disagree
| Observed result | Next check |
|---|---|
| Notice concerns a number your team did not change | Verify the business portfolio, connected number and time; review the operation with the responsible account administrator. |
| Request received but verification is still enabled | Check whether the process was completed. Do not classify a request as a completed reset. |
| Manager state differs from an older notice | Compare operation times and subsequent authorized changes; use the current setting for the next action. |
| Custom receiver has no security notice | Confirm whether forwarding is supported. Check the setting in Manager rather than treating silence as proof that nothing changed. |
| Sending problem appears at the same time | Inspect the exact sending error and delivery result; a security notice alone does not identify the cause of a failed message. |
For a custom application, confirm the event format, affected-number mapping and duplicate/ordering rules before automating alerts. Use the webhook overview and handle diagnostic records according to the data-handling guide.
See Meta's security-event reference for the direct platform interface. ChatArchitect customers use the confirmed WhatsApp Manager workflow; this article does not require a direct Meta API call.
No comments to display
No comments to display