On this page

Error 190 means the access token VGraple CRM is using to talk to Meta on your behalf is no longer valid, and until it is replaced, sending and several background operations stop working. It is one of the more disruptive failures because it is completely silent to customers, nothing about your WhatsApp number changes visibly, but VGraple CRM detects it proactively and the fix is a one-click reconnect.
Symptom
Sends, template syncs, media downloads, or profile lookups start failing, and the underlying error reads close to Meta's own title, "Access token has expired" or "Invalid OAuth access token." Before this typically escalates into a stream of failed sends, VGraple CRM's background token health check catches it: the WhatsApp channel card in Settings, then Channels, then WhatsApp shows a "needs attention" status, and the org owner receives an alert across in-app, push and email naming the affected number and offering a one-click reconnect.
Why it happens
The access token behind every connected WhatsApp number is tied to the Meta identity (a system user, or the admin who completed Embedded Signup) that granted it. A handful of distinct events can invalidate it. The most common is the admin account resetting their Facebook password, which can invalidate tokens issued under that identity depending on Meta's own security posture at the time. Another common cause is someone removing the system user, the app, or the WhatsApp Business Account's connection from the Meta Business Portfolio, whether deliberately during a cleanup or accidentally while managing unrelated permissions. Meta also periodically runs security checks that can invalidate existing tokens as a precaution, unrelated to anything the business did. Embedded Signup long-lived user tokens themselves also have a natural lifespan of roughly 60 days and need to be refreshed before they lapse on their own, which is a scheduled event rather than a failure, but produces the same 190 error if it is not caught in time.

Fix
- Go to the WhatsApp channel card. Settings, then Channels, then WhatsApp. A number affected by this shows a "needs attention" status rather than its normal connected state.
- Click the reconnect option and complete Embedded Signup again. This issues a fresh token; it does not delete or rebuild the channel, its templates, its message history, or its conversation data, all of that stays intact.
- Confirm the same admin account and Meta Business Portfolio are used as the original connection, unless the intent is to deliberately switch which account owns the connection.
- After reconnecting, check for anything that failed during the outage window. Sends that failed with 190 are not automatically retried once the token is fixed; review the affected broadcasts or conversations and resend anything that still needs to go out.
- If reconnecting repeatedly fails or the token invalidates again shortly after, check whether something in the Meta Business Portfolio (a removed permission, a policy restriction on the WhatsApp Business Account) is the underlying cause rather than the token refresh itself.
How VGraple CRM handles it automatically
A background health check verifies every active WhatsApp channel's access token roughly once every 24 hours using Meta's own token debug endpoint, rather than waiting to discover a problem from a failed send. When a token's status changes into an alertable state, expiring soon or already expired or invalid, the org owner is notified once for that transition, not repeatedly on every subsequent check, so a genuine problem gets one clear alert rather than a daily nag. An expiring token surfaces the alert with the exact expiry date and a reconnect link before it actually lapses, giving the owner a window to act before any sending is interrupted at all; an already-expired or invalid token surfaces immediately with the same reconnect path.
Example
A real-estate agency's Meta admin resets their Facebook password after a routine security prompt. The WhatsApp number's access token is invalidated as a result. Within the health check's daily cycle, VGraple CRM detects the token is no longer valid and alerts the org owner by push and email: "co.vgraple.crm's WhatsApp connection expired. Reconnect the number in Settings to restore service." The owner reconnects through Embedded Signup in under a minute, and sending resumes with no other configuration lost.
Prevention
The clearest prevention is stability in who administers the Meta side of the connection: unnecessary changes to the admin account's own security settings, or removals and re-additions of the system user in the Meta Business Portfolio, are the events most likely to invalidate a working token. Beyond that, there is limited proactive prevention available on the business's side, since token invalidation is ultimately a Meta-side event; the meaningful protection is early detection, which the daily health check and owner alert already provide, so that a token issue is caught and fixed within a day rather than discovered from a backlog of failed sends days later.
What is the difference between error 190 and a channel showing disconnected?
Error 190 specifically means the token itself is the problem, expired, revoked, or invalidated, while the channel's basic configuration (the phone number, the WhatsApp Business Account link) remains intact and does not need to be rebuilt. A channel showing fully disconnected, by contrast, usually means the underlying connection to Meta was removed entirely, which is a more involved situation typically requiring connecting the WhatsApp number again from the start rather than a simple reconnect. In both cases, the message history, contacts, and templates recorded on the VGraple CRM side are preserved regardless, since none of that data lives in the token, only the ability to call Meta's API depends on it being valid.