Every day your team answers the same WhatsApp questions: opening hours, prices, shipping, how to order, where is my order. After hours the messages pile up, and customers who wait too long buy elsewhere. Hiring more staff is not always an option.
A WhatsApp chatbot can handle repetitive questions automatically and pass complex cases to a person. But a poorly designed bot frustrates customers, and using the wrong access method can get your business number banned. This guide covers your technology options, flow design, the platform rules you must know, and a Laravel webhook implementation.
Three Ways to Automate WhatsApp
| Option | Strengths | Limits | Best for |
|---|---|---|---|
| WhatsApp Business app (free) | Greeting and away messages, quick replies, catalog; no code | Not a real bot; no connection to your data | Small businesses with low chat volume |
| WhatsApp Business Platform (official API via Meta's Cloud API or a Business Solution Provider such as Twilio or 360dialog) | Official, stable, interactive buttons, integrates with your systems | Business verification, paid template messages, strict policies | Businesses that need data integration |
| Unofficial gateways (WhatsApp Web automation) | Cheap and quick | Violate WhatsApp's terms, ban risk, no stability guarantees | Not recommended for a primary business number |
If the bot must look up stock, order status, or customer records, the official API is effectively the only route. You can call the Cloud API directly (you need a Meta Business account, a phone number not registered on the regular WhatsApp app, and an app in Meta for Developers) or go through a provider that adds a dashboard and onboarding help.
Platform Rules You Must Know
- The 24-hour customer service window: after a customer messages you, you can reply freely for 24 hours. Outside that window you may only send pre-approved message templates.
- Template categories: utility (transaction updates), authentication (one-time codes), and marketing. Rates differ by category and country, and Meta revises its pricing model periodically, so check the official pricing page.
- Opt-in: customers must agree to receive messages before you start a conversation, for example via a checkbox at checkout.
- Quality rating: frequent blocks and reports lower your number's quality and can limit how many people you can message.
Designing the Conversation
- Study real chats. Read your last 100-200 conversations and group the questions; a handful of topics usually dominate.
- Automate the top 5-7 topics. Everything else goes to a person.
- Build a main menu with interactive messages: up to 3 reply buttons, or a list message with up to 10 options.
- Keep answers short: one message, one piece of information, followed by the next options.
- Offer an exit everywhere: a "Talk to a person" button.
- Define after-hours behavior: answer what the bot can and state when a human will reply.
Hi, thanks for contacting Example Store.
Choose a topic:
[Track my order]
[Prices & products]
[Talk to a person]
For free-text questions that do not match the menu, an AI model can detect intent and answer from your FAQ. Restrict it to the FAQ content you provide and hand off when the answer is not there, so the bot never invents prices or policies.
A Laravel Webhook
With the Cloud API, Meta posts every incoming message to your webhook. There are two parts: verification (GET) when you register the URL, and message delivery (POST).
// routes/web.php
Route::get('/webhooks/whatsapp', [WhatsAppWebhookController::class, 'verify']);
Route::post('/webhooks/whatsapp', [WhatsAppWebhookController::class, 'receive']);
// bootstrap/app.php (exclude from CSRF)
->withMiddleware(function (Middleware $middleware) {
$middleware->validateCsrfTokens(except: ['webhooks/whatsapp']);
})
class WhatsAppWebhookController extends Controller
{
public function verify(Request $request)
{
// PHP converts dots in query keys to underscores
if ($request->query('hub_mode') === 'subscribe'
&& $request->query('hub_verify_token') === config('services.whatsapp.verify_token')) {
return response($request->query('hub_challenge'), 200);
}
abort(403);
}
public function receive(Request $request)
{
$signature = 'sha256=' . hash_hmac('sha256', $request->getContent(), config('services.whatsapp.app_secret'));
abort_unless(hash_equals($signature, (string) $request->header('X-Hub-Signature-256')), 401);
$message = data_get($request->all(), 'entry.0.changes.0.value.messages.0');
if ($message) {
HandleWhatsAppMessage::dispatch($message);
}
return response()->json(['ok' => true]);
}
}
Verify the X-Hub-Signature-256 header so only Meta can trigger the bot, and acknowledge the webhook fast while doing the real work on a queue. Slow responses cause retries, and your bot may reply twice; store processed message IDs to prevent duplicates. See Laravel queues and jobs for the queue setup.
Http::withToken(config('services.whatsapp.token'))
->post('https://graph.facebook.com/' . config('services.whatsapp.version')
. '/' . config('services.whatsapp.phone_number_id') . '/messages', [
'messaging_product' => 'whatsapp',
'to' => $message['from'],
'type' => 'text',
'text' => ['body' => 'Order #1023 is packed and ships tomorrow.'],
])->throw();
Keep the token, app secret, and phone number ID in .env, never in code. For more on this, read web application security best practices.
Handing Off to a Human
A bot customers cannot escape is the top source of complaints. Hand off when:
- The customer taps "Talk to a person" or types words like "agent", "complaint", or "refund".
- The bot fails to understand two messages in a row.
- The topic is sensitive: failed payments, damaged goods, personal data.
On handoff, store the conversation state (for example handled_by = human) so the bot stops replying, and send the agent a summary so the customer does not have to repeat themselves.
Measuring Whether the Bot Works
Log each conversation with a topic, whether the bot resolved it, and whether it was escalated. Then track the bot resolution rate, escalation rate per topic, and the wait time after handoff. A topic with high escalation needs a clearer answer or belongs with humans. Review these numbers every two weeks and improve one flow at a time.
Common Mistakes
- Menus that go too deep. Past three levels, people give up.
- Brochure-length replies. Short messages read better in chat.
- Promotional blasts without opt-in, which quickly damage your quality rating.
- Skipping real-device testing. Buttons and lists render differently from dashboard previews.
- Never reading the logs. Messages the bot failed to understand are a free improvement backlog.
Go-Live Checklist
- Business account and phone number are verified with Meta.
- The webhook verifies signatures and processes messages on a queue.
- Duplicate messages are blocked by storing message IDs.
- Every flow offers "Talk to a person".
- Templates for messages outside the 24-hour window are approved.
- Customer opt-in is recorded in your database.
- After-hours replies say when a human will respond.
Start with simple FAQs and one data integration, such as order tracking, then improve based on real conversation logs. If your orders are not yet digital, begin with how to digitize a small business. Several Laravel apps on GudangCode already store order data that can plug into a webhook like this one.