On this page

The two-step verification PIN is a 6-digit code Meta requires when registering a WhatsApp number directly on the Cloud API, separate from any VGraple CRM login credential, and it protects the number itself from being re-registered or migrated elsewhere without that code. VGraple CRM asks for it exactly once, during new-number registration, and never needs it again for ordinary sending and receiving.
Two-step PIN
- 1Start the Register new number flow
- 2Enter the 6-digit OTP Meta sends
- 3Set your 6-digit two-step verification PIN
- 4Submit to complete registration
- 5Store the PIN outside VGraple CRM
Before you start
- This applies specifically to numbers registered through VGraple CRM's Register new number flow (a brand-new number, verified by SMS or voice OTP), not to numbers connected through Embedded Signup, where Meta handles registration behind the scenes without prompting VGraple CRM for a PIN.
- You need the org settings permission (Owner or Admin, or a custom role granted
settings:org) to register a new number and therefore to set this PIN, the same permission required to connect any channel. - Decide on your PIN in advance and store it somewhere your team can retrieve securely later (a password manager, not a sticky note), since this exact PIN is required again if the number is ever re-registered, migrated, or recovered.
Steps
- Start the Register new number flow. Go to Settings, then Channels, then WhatsApp, and choose Register new number on an existing connected channel's options. Enter the new phone number, business display name, and whether Meta should send the verification code by SMS or voice call.

Enter the 6-digit OTP Meta sends. This confirms you control the phone number itself, a separate check from the PIN that comes next.
Set your 6-digit two-step verification PIN. This is a code you choose, not one Meta sends you; pick 6 digits and enter them on the same screen as the OTP.
Submit to complete registration. VGraple CRM sends the OTP and the PIN together to Meta's number registration endpoint. A successful response registers the number on Cloud API and creates the connected channel in your workspace immediately.
Store the PIN outside VGraple CRM. Since it is not retrievable from within the product afterward, write it down in your organisation's password manager or another secure record the moment you set it, before moving on to the next step in setup.
Why does Meta require this at all?
A WhatsApp number on the Cloud API can, in principle, be de-registered from one platform and re-registered on another, since Meta's registration API is what actually controls which system is authorised to send and receive on that number, not VGraple CRM. Without a PIN, anyone who somehow gained access to the number's registration flow (through a compromised Meta Business Manager, for instance) could move it to a different provider entirely, taking the WhatsApp identity, conversation history entitlements, and sending reputation with it. The PIN is Meta's way of keeping that specific action, re-registering or migrating the number, gated behind a secret only the legitimate business holds, independent of whatever platform-level login security a Tech Provider like VGraple CRM layers on top.
How is this different from VGraple CRM's own account security?
It is easy to conflate the two, since both are 6-digit-style codes tied to account security, but they protect entirely different layers of the stack.
| Two-step verification PIN | VGraple CRM two-factor authentication | |
|---|---|---|
| What it protects | The WhatsApp phone number's registration on Meta's Cloud API | Your login to the VGraple CRM workspace |
| Who issues it | You choose it; Meta stores and enforces it | You set it up via a TOTP authenticator app (Google Authenticator, Authy, 1Password) |
| Where it is set | Inside the Register new number flow, once, during registration | Settings, then Profile, at any time |
| Recoverable from VGraple CRM? | No; Meta's own recovery path applies | Yes; the organisation Owner can reset a locked-out member's 2FA from the team page |
| Needed for daily use? | No, only for re-registration or migration | Yes, on every login if enabled |
See the security and roles feature page for how VGraple CRM's own account-level 2FA and audit log work; they are unrelated to this page's PIN.
What happens if I need to migrate this number away from VGraple CRM later?
If a business decides to move a WhatsApp number to a different platform, or back onto the standard WhatsApp Business app, Meta's own migration and de-registration processes ask for this same PIN to confirm the request is coming from someone who legitimately controls the number, not just someone with access to the destination platform. This is precisely why VGraple CRM never displays the PIN back to you after registration: it exists to be known only by the business, not stored in a way any platform, including this one, could use to move the number without your explicit involvement.
What you will see
Once registration succeeds, the new number appears on the WhatsApp channel list in Settings, then Channels, then WhatsApp like any other connected number, with no visible indicator that it was registered by OTP versus Embedded Signup, and no PIN field shown anywhere afterward. Day-to-day sending, receiving, templates and broadcasts on that number behave identically regardless of which connection path was used to add it.
Settings and options
| Setting or field | What it does | Default |
|---|---|---|
| Two-step verification PIN | A Meta-side, 6-digit credential tied to the phone number, required for future re-registration or migration | Set once during Register new number; not shown or editable afterward inside VGraple CRM |
| OTP delivery method | SMS or voice call, chosen when starting registration | SMS, changeable to voice on the same screen if SMS fails to arrive |
| Registering permission | Who can register a new number and therefore set its PIN | Owner, Admin, or a custom role granted settings:org |
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| "Registration failed. Check your PIN and try again." | The PIN submitted did not meet Meta's format requirement, or a transient Meta-side error | Confirm the PIN is exactly 6 digits and resubmit; if it repeats, check the number is not already registered elsewhere |
| Forgot the PIN and need to re-register the number | No local recovery exists, since VGraple CRM does not store it in a retrievable form | Use Meta's own number recovery path (a wait period, then re-registration with a new PIN) through Meta Business Manager, or contact Meta Business Help Centre |
| Confusing this PIN with the VGraple CRM account password or 2FA code | The two systems are unrelated; this PIN is Meta's, not VGraple CRM's | Reset your VGraple CRM password or account 2FA from Settings, then Profile; neither action touches the WhatsApp number's PIN |
| PIN prompt never appeared when connecting a number | The number was connected through Embedded Signup, which registers the number without prompting VGraple CRM for a PIN | Expected; Embedded Signup handles registration on Meta's side without this step |
| OTP never arrives | Wrong country code, or the number cannot receive SMS in that region | Re-check the number and country code, then try Voice call instead of SMS |
Related reading
This PIN is set as part of the same flow described in connecting your WhatsApp number; read that page for the full registration walkthrough. If you later need to move this number to a different phone or reconnect it, see changing or adding a WhatsApp number. It is unrelated to your VGraple CRM account's own login security, covered on the security and roles feature page.