Callback URL and verify token
Copy both from the WhatsApp API screen of your chatbot into Meta → WhatsApp → Configuration. Meta calls the URL with your token, and the server echoes back a challenge value.
Subscribe to messages
After verifying, subscribe to the messages field. Without it, Meta verifies the URL but sends no messages.
Signature checks
Set your app secret on the server so every incoming request is verified with the X-Hub-Signature-256 header.
Common fixes
Use HTTPS, make sure the token matches exactly (no spaces), and check that your server is not blocking Meta's requests.
AnjokWA Bot is free forever — your own WhatsApp number, unlimited chatbots and seats. Want it done for you? Our experts can help (paid).
Frequently asked questions
Why does Meta say the callback URL could not be validated?
Usually the verify token does not match, the URL is not HTTPS, or the page returns something other than the challenge.