
How Agencies Set Up WhatsApp API for Clients
WhatsApp Business API setup for agency clients: who should own the account, how verification works, and how to run every client line from one dashboard.
Every WhatsApp Business API setup guide on page one of Google tells you which buttons to press. Not one of them answers the question that decides whether your agency keeps the retainer: when you set up the API for a client, whose Meta Business Manager should own the account? Get that wrong and you inherit the client's verification problems, their ban risk, and an awkward conversation the day they want to leave. This guide covers the WhatsApp Business API setup for agency clients the way an agency actually needs it: the ownership structure first, the click-by-click steps second, and the operating layer that makes ten client lines manageable from one screen.
The client should own their WhatsApp Business account inside their own Meta Business Manager, with your agency operating it through partner access. Agency-owned setups feel like retention insurance but they concentrate verification liability and ban risk on your agency, and they make new clients hesitate to hand you the channel at all. The setup itself takes an afternoon; business verification and number warm-up are the parts that need planning.
Who should own the WhatsApp Business account: agency or client?
The client. Every time, no exceptions, even when the client barely knows what a Business Manager is.
Here is the structure that works. The client creates (or already has) their own Meta Business Manager, registered to their company. The WhatsApp Business Account (WABA) and the phone number live inside it. Your agency connects as a partner with the permissions you need to build templates, run campaigns, and manage the inbox. You do the work; they hold the asset.
Agencies resist this because ownership feels like leverage. If the WABA sits in your Business Manager, the client cannot walk away without losing their number, their chat history, and their opted-in list. That sounds like retention insurance. In practice it works against you three ways:
- Verification liability lands on you. Meta verifies the legal business behind the Business Manager. If the WABA sits under your agency, the display name, the documents, and the website Meta checks are a mismatch with the brand actually messaging customers. Mismatches slow approval and invite rejections.
- Ban risk becomes your ban risk. If a client account gets restricted while it lives in your Business Manager, next to your other clients' assets, you have turned one client's problem into a portfolio problem.
- It poisons the sale. Business owners in 2026 have heard the horror stories about agencies holding ad accounts hostage. The moment a prospect asks "what happens to the number if we stop working together?" and your answer involves a migration, you have handed them a reason to delay signing.
The counterintuitive part: portability wins renewals. A client who knows they can leave without losing anything is a client who stops treating the retainer as a hostage negotiation and starts judging you on results. In Malaysia, where WhatsApp is the default business channel, that trust matters more than anywhere. Roughly nine in ten Malaysian internet users are on WhatsApp (DataReportal, Digital 2025: Malaysia), which means the number you are setting up is not a marketing experiment. It is the client's primary revenue channel, and they know it.
What does the client need before setup starts?
Collect these four things before you open Meta Business Manager, because every one of them is a place where setup stalls:
The phone number decision deserves more thought than it usually gets. A brand-new number is clean but cold: it has no sending history, and Meta's systems treat fresh numbers cautiously. An existing number carries history and customer recognition but has to be deliberately migrated from the app to the API. For most clients we recommend migrating the number customers already know, precisely because of what fresh numbers do to deliverability (more on that below).
How to Set Up WhatsApp Business API for a Client in 6 Steps
How to Set Up WhatsApp Business API for a Client in 6 Steps
Steps one and two are where agency setups go sideways, and both failures come from the same shortcut: doing it under the agency's identity because the client is slow to respond. Resist it. A week of chasing the client for SSM documents is cheaper than a rejected verification or an ownership dispute a year later.
Step six is where the real damage happens, and it is invisible in every setup guide we found ranking for this topic. In our own accounts, the moves that show up right before a WhatsApp restriction are a new template, a sudden volume jump, and switching to a fresh number. Now look at what a typical agency onboarding does in week one: registers a fresh number, submits a batch of new templates, and blasts the client's full database to show quick results. That is all three triggers at once, on day one, on a number with no history. When agencies tell us "the API got our client banned," the timeline almost always shows this pattern. The API did not get them banned. The launch plan did. If a restriction does happen, there is a recovery path, which we cover in what to do when a WhatsApp business number gets banned, but the better plan is a slow ramp that never trips the wire.
Client-owned vs agency-owned: the practical difference
| What happens when... | Client owns the WABA | Agency owns the WABA |
|---|---|---|
| Meta verification | Checks the client's real documents and website; clean match | Checks the agency's documents against the client's brand; mismatch risk |
| Account restriction | Contained to that client | Sits inside the agency's Business Manager next to other clients |
| Client wants to leave | They keep number, history, and opt-in list; you keep the reputation | Migration fight, and every prospect who hears about it trusts you less |
| New client objection | "You own everything, we just run it" closes the deal | "What happens to our number?" stalls the deal |
| Agency operating access | Partner access with the permissions you need | Full control you did not actually need |
Frequently Asked Questions
How do agencies run ten client lines without ten phones?
Setup is the visible part of the job. The part that determines whether the account is profitable for your agency is what happens after: who answers the client's leads, how fast, and how you prove it happened.
Consider a six-person performance agency in Bangsar running lead generation for three property developers and a dental chain. Four clients, four WhatsApp numbers, leads arriving from Facebook Ads and TikTok around the clock. On phones, that is four devices rotating between account managers, no record of who replied to what, and no answer when a client asks why Tuesday's leads went quiet. This is the point where the agency either builds an operating layer or quietly caps its own growth.
The operating layer looks like this in practice: each client is a separate workspace with its own inbox, contact database, and reporting, so client data never crosses. Incoming leads are auto-tagged by source, routed to the right person by rules rather than by whoever saw the message first, and followed up by sequences when the human is asleep. AI handles the first reply and qualification per each client's own rules, because a property developer's qualifying questions are nothing like a dental chain's. This is exactly the setup Raion's platform for marketing agencies is built around: one dashboard, a workspace per client, and each workspace running its own AI and routing logic.
The handoff between your campaigns and the client's sales team deserves its own attention, because leads that die after handoff still get blamed on the agency. We covered that failure mode in automating the lead handoff for performance agencies, and the enquiry-tracking side in WhatsApp lead management for marketing agencies.
Should you charge for the setup?
Yes, and most agencies undercharge because they price the clicks instead of the judgment. The clicks are worth a few hundred ringgit. Knowing to start verification first, to migrate the known number instead of provisioning a fresh one, to hold the client back from blasting their full list in week one: that judgment is what keeps the account alive, and it is worth a proper setup fee plus the ongoing retainer.
Position the ongoing piece around outcomes the client can see: response time on their leads, qualified conversations handed to their sales team, and campaign results tied to pipeline rather than clicks. The costs you are managing on their behalf, including Meta's per-message pricing, are worth explaining transparently; our breakdown of WhatsApp Business API pricing in Malaysia covers the numbers clients ask about. Verified accounts also unlock brand display perks worth bundling into your offer; the process is in our green tick verification guide. For the broader automation picture beyond the agency angle, the WhatsApp automation guide for Malaysian businesses is the full map.
The bottom line
Set up every client's WhatsApp Business API inside their own Meta Business Manager and operate it through partner access: it clears verification faster, contains ban risk, and removes the lock-in objection from your sales conversations. Treat the number warm-up as part of the deliverable, because a fresh number, new templates, and a volume spike in week one is the exact pattern that precedes restrictions. Then earn the retainer on the operating layer: per-client workspaces, routing, and AI qualification that make ten client lines run from one screen.

