Skip to main content
    MessagingError 10General

    WhatsApp Error #10 - Permission Denied

    Your WhatsApp messages are failing with Error code #10 ("Application does not have permission for this action"). This guide covers the most common causes — Facebook security checkpoints, revoked asset permissions, and token scope issues — and how to fix each one.

    3 min readUpdated 27 Apr 2026

    Meta WhatsApp Cloud API Error #10 means "Application does not have permission for this action" (HTTP 403). Voltade can no longer send messages, sync conversations, or manage templates for the affected number — even though the channel may still show as Connected in Envoy.

    There are three common causes, from most to least likely:

    1
  1. Facebook flagged a security checkpoint on the account that owns the integration. Until someone logs in and clears it, Meta silently blocks all API calls from that account.
  2. 2
  3. Asset permissions were revoked. One or more WhatsApp Business Accounts (WABAs) or Business Accounts got unticked from Voltade's access list — often silently after re-running the Embedded Signup flow for a different number.
  4. 3
  5. The access token lost required permissions. The token no longer carries whatsapp_business_management or whatsapp_business_messaging scopes, which can happen after Meta policy changes or app review revocations.

  6. This is the most common cause and the fastest fix. Meta periodically flags business accounts for security verification. When this happens, all API calls from that account return Error #10 until the checkpoint is cleared.

    1
  7. Identify who connected the number. This is the Facebook user who completed the Embedded Signup flow in Envoy for that WhatsApp number. If you're not sure, ask your team — it's usually whoever set up WhatsApp in Envoy originally.
  8. 2
  9. Have that person log in to Facebook at facebook.com using their personal account.
  10. 3
  11. Look for a security prompt — a banner or pop-up asking to confirm identity, review recent activity, or verify a login. Complete whatever Meta asks.
  12. 4
  13. Test in Envoy — send a message from the affected number. If the security checkpoint was the cause, it should work immediately.
  14. If there's no security prompt and messages still fail, move to Fix 2.


    Re-grant Asset Permissions in Business Tools

    If the security checkpoint wasn't the issue, asset-level permissions may have been revoked. This often happens when:

    • Someone ran the Embedded Signup flow again for a different number (Meta can silently untick other assets)
    • A Meta Business Suite admin manually edited integration permissions
    • Meta reset permissions during a Business Portfolio or account change

    Step 1: Open Facebook

    Business Tools

    Go to [facebook.com/settings/?tab=business_tools](https://www.facebook.com/ settings/?tab=business_tools) while logged in as the Facebook user that originally connected the WhatsApp number to Voltade.

    Step 2: Find Voltade and Click "View and

    edit"

    Scroll the list of connected business integrations until you see Voltade. Click the View and edit button next to it.

    Step 3: Tick Everything

    In the permissions panel, scroll all the way down and tick every checkbox under both:

    • WhatsApp Business Accounts — every WABA you want Voltade to manage
    • Business Accounts (Business Portfolios) — the portfolio that owns those WABAs

    Make sure no asset is left unchecked. If you're not sure which one belongs to your number, tick all of them — granting access to assets you don't use is harmless.

    Step 4: Save

    Click Save at the bottom of the panel. The change takes effect immediately.

    Step 5: Verify in

    Envoy

    1
  15. Send a test message from Envoy
  16. 2
  17. Confirm it delivers without an Error #10 response
  18. 3
  19. If you have multiple numbers, test each one

  20. Token Scope Issues

    If you have multiple WhatsApp numbers connected through Envoy and only some are failing, the issue may be token scope bleed from the Embedded Signup flow.

    How this happens: when a Facebook user triggers Embedded Signup, the generated token inherits scopes for every WABA that Facebook user has access to — not just the number they selected. If that user later loses access to one of those WABAs, or a different user re-runs signup for one number, the token for the other numbers can break.

    This is a known Meta behaviour and isn't something you can fix from Facebook Business Tools alone. Tell us what you need — we'll check the token scopes on our side and re-issue if needed.

    For more detail on this scenario, see Adding a New WhatsApp Number Disconnects Existing Numbers.


    Not Working?

    • Can't find Voltade in Business Tools? Only the Facebook user who completed the original Embedded Signup will see Voltade listed. If it's not there, ask whichever teammate set up the integration.
    • Voltade was removed entirely from your Business Portfolio? Re-ticking checkboxes won't help — the integration needs to be re-authorised. See our reconnection guide.
    • Error appeared right after migrating from another provider (e.g. Wati)? Leftover payment methods or shared WABAs from the old provider can cause conflicts. Contact us so we can check your Meta Business Manager setup.

    If none of the above resolves it:

    Tell us what you need

    Was this article helpful?