WhatsApp apps must send consumer_phone_number in E.164 form. consumer_instagram_username is for
Instagram entities only and is rejected on a WhatsApp app, including when sent alongside a phone number.
At most 20 entries per app; the 21st answers 400.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
Request parameters
| Parameter | Type | Required | In | Description |
|---|---|---|---|---|
Authorization | string | Yes | Header | Partner app token, sent raw. Bearer <token> is also accepted. |
Content-Type | string | Yes | Header | application/json |
appId | string (uuid) | Yes | Path | Partner Portal app id. Stands in for Meta's entity_id. |
consumer_phone_number | string | No | Body | E.164, with leading +. Required for WhatsApp apps. |
consumer_instagram_username | string | No | Body | Instagram entities only, without @. Rejected on WhatsApp apps. |
Example request
curl --location --request POST 'https://partner.gupshup.io/partner/app/<appId>/bizai/agent_config/allowlist' \
--header 'Authorization: <PARTNER_APP_TOKEN>' \
--header 'Content-Type: application/json' \
--data '{
"consumer_phone_number": "+919999999999"
}'Response parameters — 201
201| Parameter | Type | Description |
|---|---|---|
id | string | Resource id. Meta pfbid… id. |
consumer_phone_number | string | e.g. +919999999999. |
consumer_instagram_username | string | Instagram username without @. Instagram entities only. |
Example response — 201 Created
201 Created{
"id": "pfbid0BJwAllowlistExampleId",
"consumer_phone_number": "+919999999999"
}Error responses
400 Bad Request — The app is not live, or WASS does not consider it live.
{
"message": "App is not live.",
"status": "error"
}400 Bad Request — The app has no phone number attached. Checked before the live check.
{
"message": "Phone id not found for the given App",
"status": "error"
}401 Unauthorized — Authorization is missing or invalid, belongs to another app, or appId is unknown or not a UUID.
{
"status": "error",
"message": "Unauthorised access to the resource. Please review request parameters and headers and retry"
}405 Method Not Allowed — Any method other than GET, POST, PUT or DELETE, e.g. PATCH.
{
"status": "error",
"message": "Request method 'PATCH' is not supported"
}429 Too Many Requests — More than 30 /bizai/** requests in 60 seconds for this app. The 31st is rejected.
{
"status": "error",
"message": "Too Many Requests"
} 429Per-app rate limit exceeded. Retry after the 60-second window.
