How Agencies Set Up WhatsApp API for Clients

How Agencies Set Up WhatsApp API for Clients

WhatsApp Business API setup for agency clients: who should own the account, how verification works, and how to run every client line from one dashboard.

Siti NabilahSiti NabilahMarketing
28 Aug 26
12m
Part of the series:WhatsApp Automation for Malaysian Businesses: The Complete 2026 Guide

Every WhatsApp Business API setup guide on page one of Google tells you which buttons to press. Not one of them answers the question that decides whether your agency keeps the retainer: when you set up the API for a client, whose Meta Business Manager should own the account? Get that wrong and you inherit the client's verification problems, their ban risk, and an awkward conversation the day they want to leave. This guide covers the WhatsApp Business API setup for agency clients the way an agency actually needs it: the ownership structure first, the click-by-click steps second, and the operating layer that makes ten client lines manageable from one screen.

Key Takeaway

The client should own their WhatsApp Business account inside their own Meta Business Manager, with your agency operating it through partner access. Agency-owned setups feel like retention insurance but they concentrate verification liability and ban risk on your agency, and they make new clients hesitate to hand you the channel at all. The setup itself takes an afternoon; business verification and number warm-up are the parts that need planning.

Who should own the WhatsApp Business account: agency or client?

The client. Every time, no exceptions, even when the client barely knows what a Business Manager is.

Here is the structure that works. The client creates (or already has) their own Meta Business Manager, registered to their company. The WhatsApp Business Account (WABA) and the phone number live inside it. Your agency connects as a partner with the permissions you need to build templates, run campaigns, and manage the inbox. You do the work; they hold the asset.

Agencies resist this because ownership feels like leverage. If the WABA sits in your Business Manager, the client cannot walk away without losing their number, their chat history, and their opted-in list. That sounds like retention insurance. In practice it works against you three ways:

  1. Verification liability lands on you. Meta verifies the legal business behind the Business Manager. If the WABA sits under your agency, the display name, the documents, and the website Meta checks are a mismatch with the brand actually messaging customers. Mismatches slow approval and invite rejections.
  2. Ban risk becomes your ban risk. If a client account gets restricted while it lives in your Business Manager, next to your other clients' assets, you have turned one client's problem into a portfolio problem.
  3. It poisons the sale. Business owners in 2026 have heard the horror stories about agencies holding ad accounts hostage. The moment a prospect asks "what happens to the number if we stop working together?" and your answer involves a migration, you have handed them a reason to delay signing.

The counterintuitive part: portability wins renewals. A client who knows they can leave without losing anything is a client who stops treating the retainer as a hostage negotiation and starts judging you on results. In Malaysia, where WhatsApp is the default business channel, that trust matters more than anywhere. Roughly nine in ten Malaysian internet users are on WhatsApp (DataReportal, Digital 2025: Malaysia), which means the number you are setting up is not a marketing experiment. It is the client's primary revenue channel, and they know it.

9 in 10
Malaysian internet users are on WhatsApp

What does the client need before setup starts?

Collect these four things before you open Meta Business Manager, because every one of them is a place where setup stalls:

SSM registration documents that exactly match the legal name the client will verify with Meta
A live website (or business page) showing the brand name, what they sell, and a way to contact them
A phone number that can receive an SMS or voice OTP, and is NOT currently registered on the WhatsApp or WhatsApp Business app (or is ready to be migrated off it)
Admin access to (or willingness to create) their own Meta Business Manager

The phone number decision deserves more thought than it usually gets. A brand-new number is clean but cold: it has no sending history, and Meta's systems treat fresh numbers cautiously. An existing number carries history and customer recognition but has to be deliberately migrated from the app to the API. For most clients we recommend migrating the number customers already know, precisely because of what fresh numbers do to deliverability (more on that below).

How to Set Up WhatsApp Business API for a Client in 6 Steps

How to Set Up WhatsApp Business API for a Client in 6 Steps

Confirm the client's Meta Business Manager — they create it under their own company email and SSM-registered name; your agency requests partner access rather than creating it for them under your account
Submit business verification — upload the client's SSM documents, confirm the website matches the legal entity, and expect days rather than hours; start this first because everything else can proceed in parallel
Choose and prepare the number — migrate the existing business number off the WhatsApp Business app, or provision a new one accepting that it starts with zero sending reputation
Create the WABA and connect the platform — the WhatsApp Business Account is created inside the client's Business Manager, then connected to your messaging platform so the team gets an inbox instead of a phone
Build and submit message templates — utility templates for confirmations and updates, marketing templates for campaigns; write them in the tone the client actually uses with customers
Ramp volume deliberately — start with replies and transactional messages to engaged customers for the first weeks, then scale broadcasts gradually as the number builds reputation

Steps one and two are where agency setups go sideways, and both failures come from the same shortcut: doing it under the agency's identity because the client is slow to respond. Resist it. A week of chasing the client for SSM documents is cheaper than a rejected verification or an ownership dispute a year later.

Step six is where the real damage happens, and it is invisible in every setup guide we found ranking for this topic. In our own accounts, the moves that show up right before a WhatsApp restriction are a new template, a sudden volume jump, and switching to a fresh number. Now look at what a typical agency onboarding does in week one: registers a fresh number, submits a batch of new templates, and blasts the client's full database to show quick results. That is all three triggers at once, on day one, on a number with no history. When agencies tell us "the API got our client banned," the timeline almost always shows this pattern. The API did not get them banned. The launch plan did. If a restriction does happen, there is a recovery path, which we cover in what to do when a WhatsApp business number gets banned, but the better plan is a slow ramp that never trips the wire.

Client-owned vs agency-owned: the practical difference

What happens when...Client owns the WABAAgency owns the WABA
Meta verificationChecks the client's real documents and website; clean matchChecks the agency's documents against the client's brand; mismatch risk
Account restrictionContained to that clientSits inside the agency's Business Manager next to other clients
Client wants to leaveThey keep number, history, and opt-in list; you keep the reputationMigration fight, and every prospect who hears about it trusts you less
New client objection"You own everything, we just run it" closes the deal"What happens to our number?" stalls the deal
Agency operating accessPartner access with the permissions you needFull control you did not actually need

Frequently Asked Questions

Yes. The standard structure is: the client owns their Meta Business Manager and WhatsApp Business Account, and the agency is added as a partner with permission to manage messaging, templates, and campaigns. The agency does all the setup work; the assets stay registered to the client's legal entity.
Whoever owns the Meta Business Manager the WABA was created in. This is decided at setup, not by who did the work or who pays the platform bill. Set it up inside the client's Business Manager and the client owns it, which is the arrangement that protects both sides.
SSM registration documents matching the legal name on their Meta Business Manager, a live website or business page that clearly belongs to the same brand, and a phone number that can receive a one-time code. Mismatched names between the SSM record, the Business Manager, and the website are the most common reason verification stalls.
The technical connection takes under a day. Business verification is the variable: it can clear in a couple of days or take weeks if documents and website details do not match cleanly. The number warm-up is the part agencies skip: plan for two to four weeks of gradual volume ramp before full-scale broadcasts on a fresh number.
Yes, on a platform built with per-client workspaces. Each client gets a separate workspace with its own number, inbox, contact data, AI rules, and team access, and the agency switches between them from one login instead of juggling phones or browser profiles.

How do agencies run ten client lines without ten phones?

Setup is the visible part of the job. The part that determines whether the account is profitable for your agency is what happens after: who answers the client's leads, how fast, and how you prove it happened.

Consider a six-person performance agency in Bangsar running lead generation for three property developers and a dental chain. Four clients, four WhatsApp numbers, leads arriving from Facebook Ads and TikTok around the clock. On phones, that is four devices rotating between account managers, no record of who replied to what, and no answer when a client asks why Tuesday's leads went quiet. This is the point where the agency either builds an operating layer or quietly caps its own growth.

The operating layer looks like this in practice: each client is a separate workspace with its own inbox, contact database, and reporting, so client data never crosses. Incoming leads are auto-tagged by source, routed to the right person by rules rather than by whoever saw the message first, and followed up by sequences when the human is asleep. AI handles the first reply and qualification per each client's own rules, because a property developer's qualifying questions are nothing like a dental chain's. This is exactly the setup Raion's platform for marketing agencies is built around: one dashboard, a workspace per client, and each workspace running its own AI and routing logic.

The handoff between your campaigns and the client's sales team deserves its own attention, because leads that die after handoff still get blamed on the agency. We covered that failure mode in automating the lead handoff for performance agencies, and the enquiry-tracking side in WhatsApp lead management for marketing agencies.

Should you charge for the setup?

Yes, and most agencies undercharge because they price the clicks instead of the judgment. The clicks are worth a few hundred ringgit. Knowing to start verification first, to migrate the known number instead of provisioning a fresh one, to hold the client back from blasting their full list in week one: that judgment is what keeps the account alive, and it is worth a proper setup fee plus the ongoing retainer.

Position the ongoing piece around outcomes the client can see: response time on their leads, qualified conversations handed to their sales team, and campaign results tied to pipeline rather than clicks. The costs you are managing on their behalf, including Meta's per-message pricing, are worth explaining transparently; our breakdown of WhatsApp Business API pricing in Malaysia covers the numbers clients ask about. Verified accounts also unlock brand display perks worth bundling into your offer; the process is in our green tick verification guide. For the broader automation picture beyond the agency angle, the WhatsApp automation guide for Malaysian businesses is the full map.

The bottom line

Key Takeaway

Set up every client's WhatsApp Business API inside their own Meta Business Manager and operate it through partner access: it clears verification faster, contains ban risk, and removes the lock-in objection from your sales conversations. Treat the number warm-up as part of the deliverable, because a fresh number, new templates, and a volume spike in week one is the exact pattern that precedes restrictions. Then earn the retainer on the operating layer: per-client workspaces, routing, and AI qualification that make ten client lines run from one screen.

Ready to grow with Raion

Run every client WhatsApp line from one dashboard

Per-client workspaces, per-client AI rules, and lead routing built for agencies managing five or fifteen accounts at once.