Meta is moving forward with the rollout of the BSUID (Business Scoped User ID) — a unique, encrypted user identifier within the WhatsApp ecosystem. This change may make the phone number unavailable in certain webhooks of the official platform, directly affecting unofficial integrations that rely solely on the phone number as their primary identifier.
TL;DR: The BSUID will replace the phone number in specific scenarios of the official WhatsApp API. Unofficial integrations that don't adapt may break or lose the ability to identify contacts correctly.
Companies running solutions built on unofficial libraries (such as Baileys, Venom, WhatsApp Web.js and similar) need to understand how far this change reaches — and assess whether migrating to Meta's official API is more strategic than waiting for the problem to hit.
What is the BSUID and why is Meta implementing it?
The BSUID is a unique, anonymous identifier assigned by Meta to each user in relation to a specific business account. Unlike the phone number, the BSUID doesn't expose personal data directly and lets the platform offer greater control over privacy and security.
The logic is simple: a phone number is sensitive information. Depending on the regulatory context (such as LGPD, GDPR and other data protection laws), Meta needs to minimize the exposure of that data in its APIs.
With the BSUID, the platform can:
- Reduce the exposure of personal data in third-party integrations
- Ensure stronger regulatory compliance worldwide
- Improve conversation traceability without relying on data that changes (numbers can be ported or recycled)
How does this affect unofficial WhatsApp APIs?
Unofficial APIs — also called multi-device solutions based on reverse engineering — work by emulating WhatsApp Web's behavior. They have no access to Meta's internal systems and depend on capturing events directly from the app's interface.
The problem: these libraries don't have access to the BSUID. They only see what WhatsApp Web exposes — and, traditionally, that includes the contact's phone number.
If Meta starts omitting the phone number from specific webhooks or events (as is already being tested in some official API flows), unofficial integrations may:
- Lose the ability to identify the contact in new events
- Break automation flows that rely on the phone number as a primary key (CRMs, ERPs, customer service platforms)
- Run into inconsistencies in databases that cross-reference the phone number with other information
Direct impact scenarios
| Scenario | Impact on unofficial APIs | Impact on the official API |
|---|---|---|
| Incoming message webhook | May not return the sender's number | BSUID available, number optional |
| Delivery status webhook | May not identify the recipient | BSUID ensures identification |
| CRM integration via phone number | Data correlation breaks | BSUID → phone mapping kept internally |
| Number portability | Risk of duplicate contacts | BSUID stays unique |
Meta's official API, on the other hand, offers mapping mechanisms between the BSUID and the phone number when needed — but that is only available to those connected through the official WhatsApp Business API.
Unofficial integrations still work today — but for how long?
To be clear: unofficial solutions still work in 2026. Companies around the world keep using libraries like Baileys, Venom and WPPConnect to automate customer service, send messages and integrate with internal systems.
The risk isn't an immediate collapse, but progressive obsolescence.
Meta doesn't need to "switch off" unofficial APIs directly. All it takes is introducing structural changes — like the BSUID — that make these integrations incompatible with the platform's new behaviors.
And there is precedent: in 2021, Meta blocked thousands of business accounts that used unauthorized automation. The company has the power — and the regulatory motivation — to tighten the rules even further.
Trade-offs of sticking with unofficial APIs
Advantages (in the short term):
- Lower or zero upfront cost (open-source libraries)
- Full customization flexibility
- Self-hosting, with no dependence on Meta's infrastructure
Risks (medium and long term):
- Features breaking silently as Meta updates the platform
- Risk of business accounts being banned (ToS violation)
- No official support for migrations or troubleshooting
- Future incompatibility with the BSUID and other Meta identifiers
Official WhatsApp API: what changes with the BSUID
Meta's official API — also called the WhatsApp Business API or Cloud API — is already being prepared to use the BSUID as the default identifier in specific flows.
In practice, this means:
- Webhooks may return the BSUID instead of the phone number in future events
- Reverse mapping (BSUID → phone) remains available through a dedicated endpoint, when allowed by the privacy policy
- Persistent identification even when a number is ported or changed
For developers and companies, adapting is relatively simple: adjust the data model to store the BSUID as the primary key and keep the phone number as complementary metadata.
Example of an adapted flow
1. Webhook receives an incoming message
→ event.from = "BSUID:abc123xyz"
→ event.phone_number = null (or optional)
2. System queries Meta's API to get the phone number (if needed)
→ GET /v1/contacts/BSUID:abc123xyz
→ Response: { phone_number: "+5511999999999" }
3. System stores the BSUID as the main ID
→ Phone number becomes an auxiliary field, no longer a unique keyThis design avoids excessive dependence on data that changes and aligns the operation with the direction Meta is taking.
Is your operation ready for this change?
The transition from phone number to BSUID isn't a one-off event, but a gradual shift. Some companies are already seeing the first signs — webhooks that don't return the phone number in newer automation flows, for example.
The strategic question isn't "if" the change will happen, but when your operation will be affected.
For teams that depend on WhatsApp integration, it's worth assessing:
- How critical WhatsApp is to your customer service or sales funnel
- How much technical effort it would take to migrate to the official API
- What an unexpected outage would cost compared with a planned migration
Companies that already run on Meta's official API — such as NotificaMe, a partner in the Rollin ecosystem — are better prepared for this evolution. They get early access to change documentation, official support and mapping tools.
Choosing to stay with unofficial APIs needs to be a conscious decision — not one made out of inertia or a lack of technical knowledge about what is changing.
Key takeaways
- Meta is implementing the BSUID as the default identifier, reducing reliance on the phone number in webhooks
- Unofficial APIs (Baileys, Venom, etc.) don't have access to the BSUID and may lose the ability to identify contacts in future flows
- The official WhatsApp API offers BSUID → phone mapping and structured support for this transition
- The risk isn't an immediate collapse, but progressive obsolescence as the platform evolves
- Companies that depend heavily on WhatsApp should consider a planned migration instead of waiting for things to break
The change is already underway. The question is whether your operation will react to it or get ahead of it.
If your company depends on WhatsApp and you haven't yet assessed the impact of the BSUID on your stack, it's worth scheduling a technical conversation. Agência Rollin helps teams map risks, design integration architecture and plan structured migrations — no improvising.
👉 Request a free analysis and understand how this change affects your business.
