Home/Help Center/Error 190

Troubleshooting

Error 190: Access Token Expired or Invalid

Error 190 means the WhatsApp access token is no longer valid. Why it happens (password resets, permission changes) and the one-click reconnect that fixes it.

By Chirag Darji · Updated 27 Aug 2026 · 5 min read

On this page
  1. Symptom
  2. Why it happens
  3. Fix
  4. How VGraple CRM handles it automatically
  5. Prevention
  6. What is the difference between error 190 and a channel showing disconnected?
Broadcast delivery settings in VGraple CRM: quiet hours and marketing frequency cap

Error 190 means the access token VGraple CRM is using to talk to Meta on your behalf is no longer valid, and until it is replaced, sending and several background operations stop working. It is one of the more disruptive failures because it is completely silent to customers, nothing about your WhatsApp number changes visibly, but VGraple CRM detects it proactively and the fix is a one-click reconnect.

Symptom

Sends, template syncs, media downloads, or profile lookups start failing, and the underlying error reads close to Meta's own title, "Access token has expired" or "Invalid OAuth access token." Before this typically escalates into a stream of failed sends, VGraple CRM's background token health check catches it: the WhatsApp channel card in Settings, then Channels, then WhatsApp shows a "needs attention" status, and the org owner receives an alert across in-app, push and email naming the affected number and offering a one-click reconnect.

Why it happens

The access token behind every connected WhatsApp number is tied to the Meta identity (a system user, or the admin who completed Embedded Signup) that granted it. A handful of distinct events can invalidate it. The most common is the admin account resetting their Facebook password, which can invalidate tokens issued under that identity depending on Meta's own security posture at the time. Another common cause is someone removing the system user, the app, or the WhatsApp Business Account's connection from the Meta Business Portfolio, whether deliberately during a cleanup or accidentally while managing unrelated permissions. Meta also periodically runs security checks that can invalidate existing tokens as a precaution, unrelated to anything the business did. Embedded Signup long-lived user tokens themselves also have a natural lifespan of roughly 60 days and need to be refreshed before they lapse on their own, which is a scheduled event rather than a failure, but produces the same 190 error if it is not caught in time.

WhatsApp broadcast campaign report in VGraple CRM with delivered, read and replied stats per contact

Fix

  1. Go to the WhatsApp channel card. Settings, then Channels, then WhatsApp. A number affected by this shows a "needs attention" status rather than its normal connected state.
  2. Click the reconnect option and complete Embedded Signup again. This issues a fresh token; it does not delete or rebuild the channel, its templates, its message history, or its conversation data, all of that stays intact.
  3. Confirm the same admin account and Meta Business Portfolio are used as the original connection, unless the intent is to deliberately switch which account owns the connection.
  4. After reconnecting, check for anything that failed during the outage window. Sends that failed with 190 are not automatically retried once the token is fixed; review the affected broadcasts or conversations and resend anything that still needs to go out.
  5. If reconnecting repeatedly fails or the token invalidates again shortly after, check whether something in the Meta Business Portfolio (a removed permission, a policy restriction on the WhatsApp Business Account) is the underlying cause rather than the token refresh itself.

How VGraple CRM handles it automatically

A background health check verifies every active WhatsApp channel's access token roughly once every 24 hours using Meta's own token debug endpoint, rather than waiting to discover a problem from a failed send. When a token's status changes into an alertable state, expiring soon or already expired or invalid, the org owner is notified once for that transition, not repeatedly on every subsequent check, so a genuine problem gets one clear alert rather than a daily nag. An expiring token surfaces the alert with the exact expiry date and a reconnect link before it actually lapses, giving the owner a window to act before any sending is interrupted at all; an already-expired or invalid token surfaces immediately with the same reconnect path.

Example

A real-estate agency's Meta admin resets their Facebook password after a routine security prompt. The WhatsApp number's access token is invalidated as a result. Within the health check's daily cycle, VGraple CRM detects the token is no longer valid and alerts the org owner by push and email: "co.vgraple.crm's WhatsApp connection expired. Reconnect the number in Settings to restore service." The owner reconnects through Embedded Signup in under a minute, and sending resumes with no other configuration lost.

Prevention

The clearest prevention is stability in who administers the Meta side of the connection: unnecessary changes to the admin account's own security settings, or removals and re-additions of the system user in the Meta Business Portfolio, are the events most likely to invalidate a working token. Beyond that, there is limited proactive prevention available on the business's side, since token invalidation is ultimately a Meta-side event; the meaningful protection is early detection, which the daily health check and owner alert already provide, so that a token issue is caught and fixed within a day rather than discovered from a backlog of failed sends days later.

What is the difference between error 190 and a channel showing disconnected?

Error 190 specifically means the token itself is the problem, expired, revoked, or invalidated, while the channel's basic configuration (the phone number, the WhatsApp Business Account link) remains intact and does not need to be rebuilt. A channel showing fully disconnected, by contrast, usually means the underlying connection to Meta was removed entirely, which is a more involved situation typically requiring connecting the WhatsApp number again from the start rather than a simple reconnect. In both cases, the message history, contacts, and templates recorded on the VGraple CRM side are preserved regardless, since none of that data lives in the token, only the ability to call Meta's API depends on it being valid.

Frequently asked questions

What does error 190 mean?
Any call to Meta's API, sending a message, checking a template, fetching a profile, fails because the access token being used is no longer valid: it expired, was revoked, or the permissions behind it changed.
Do I lose messages while the token is invalid?
Sends fail during this period. Inbound webhooks (incoming customer messages) typically continue arriving for a while even without a valid outbound token, but reconnecting quickly matters since delivery status updates and media downloads can also be affected.
Why did my token stop working with no warning?
The most common causes are the admin account behind the connection resetting their Facebook password, someone removing the system user or app from the Meta Business Portfolio, or a routine Meta security check invalidating existing tokens.
How do I fix it?
Reconnect the number through Embedded Signup from the WhatsApp channel card in Settings. This re-establishes a fresh token without needing to rebuild the channel, templates, or conversation history from scratch.
Is error 190 charged?
No. No calls succeed while the token is invalid, so nothing is billed during that window.
How does VGraple CRM catch this before I notice sends failing?
A background health check verifies every connected number's token roughly once a day via Meta's own token debug endpoint, and alerts the org owner the moment a token is found expiring soon or already invalid, before it necessarily shows up as a wave of failed sends.

Run your WhatsApp on VGraple CRM

Free forever plan, official Meta WhatsApp Business API, set up in 15 minutes. No card needed.