Home/Help Center/Two-step PIN

Meta account and verification

Two-Step Verification PIN for Your WhatsApp Number

What the 6-digit two-step verification PIN protects on a WhatsApp Business number, when VGraple CRM asks for it, and how to reset one you have lost.

By Chirag Darji · Updated 27 Aug 2026 · 7 min read

On this page
  1. Before you start
  2. Steps
  3. Why does Meta require this at all?
  4. How is this different from VGraple CRM's own account security?
  5. What happens if I need to migrate this number away from VGraple CRM later?
  6. What you will see
  7. Settings and options
  8. Troubleshooting
  9. Related reading
Team members in VGraple CRM with owner, admin and agent roles and their permissions

The two-step verification PIN is a 6-digit code Meta requires when registering a WhatsApp number directly on the Cloud API, separate from any VGraple CRM login credential, and it protects the number itself from being re-registered or migrated elsewhere without that code. VGraple CRM asks for it exactly once, during new-number registration, and never needs it again for ordinary sending and receiving.

Two-step PIN

  1. 1Start the Register new number flow
  2. 2Enter the 6-digit OTP Meta sends
  3. 3Set your 6-digit two-step verification PIN
  4. 4Submit to complete registration
  5. 5Store the PIN outside VGraple CRM
The steps on this page, in order.

Before you start

  • This applies specifically to numbers registered through VGraple CRM's Register new number flow (a brand-new number, verified by SMS or voice OTP), not to numbers connected through Embedded Signup, where Meta handles registration behind the scenes without prompting VGraple CRM for a PIN.
  • You need the org settings permission (Owner or Admin, or a custom role granted settings:org) to register a new number and therefore to set this PIN, the same permission required to connect any channel.
  • Decide on your PIN in advance and store it somewhere your team can retrieve securely later (a password manager, not a sticky note), since this exact PIN is required again if the number is ever re-registered, migrated, or recovered.

Steps

  1. Start the Register new number flow. Go to Settings, then Channels, then WhatsApp, and choose Register new number on an existing connected channel's options. Enter the new phone number, business display name, and whether Meta should send the verification code by SMS or voice call.

Profile settings in VGraple CRM with two-factor authentication

  1. Enter the 6-digit OTP Meta sends. This confirms you control the phone number itself, a separate check from the PIN that comes next.

  2. Set your 6-digit two-step verification PIN. This is a code you choose, not one Meta sends you; pick 6 digits and enter them on the same screen as the OTP.

  3. Submit to complete registration. VGraple CRM sends the OTP and the PIN together to Meta's number registration endpoint. A successful response registers the number on Cloud API and creates the connected channel in your workspace immediately.

  4. Store the PIN outside VGraple CRM. Since it is not retrievable from within the product afterward, write it down in your organisation's password manager or another secure record the moment you set it, before moving on to the next step in setup.

Why does Meta require this at all?

A WhatsApp number on the Cloud API can, in principle, be de-registered from one platform and re-registered on another, since Meta's registration API is what actually controls which system is authorised to send and receive on that number, not VGraple CRM. Without a PIN, anyone who somehow gained access to the number's registration flow (through a compromised Meta Business Manager, for instance) could move it to a different provider entirely, taking the WhatsApp identity, conversation history entitlements, and sending reputation with it. The PIN is Meta's way of keeping that specific action, re-registering or migrating the number, gated behind a secret only the legitimate business holds, independent of whatever platform-level login security a Tech Provider like VGraple CRM layers on top.

How is this different from VGraple CRM's own account security?

It is easy to conflate the two, since both are 6-digit-style codes tied to account security, but they protect entirely different layers of the stack.

Two-step verification PINVGraple CRM two-factor authentication
What it protectsThe WhatsApp phone number's registration on Meta's Cloud APIYour login to the VGraple CRM workspace
Who issues itYou choose it; Meta stores and enforces itYou set it up via a TOTP authenticator app (Google Authenticator, Authy, 1Password)
Where it is setInside the Register new number flow, once, during registrationSettings, then Profile, at any time
Recoverable from VGraple CRM?No; Meta's own recovery path appliesYes; the organisation Owner can reset a locked-out member's 2FA from the team page
Needed for daily use?No, only for re-registration or migrationYes, on every login if enabled

See the security and roles feature page for how VGraple CRM's own account-level 2FA and audit log work; they are unrelated to this page's PIN.

What happens if I need to migrate this number away from VGraple CRM later?

If a business decides to move a WhatsApp number to a different platform, or back onto the standard WhatsApp Business app, Meta's own migration and de-registration processes ask for this same PIN to confirm the request is coming from someone who legitimately controls the number, not just someone with access to the destination platform. This is precisely why VGraple CRM never displays the PIN back to you after registration: it exists to be known only by the business, not stored in a way any platform, including this one, could use to move the number without your explicit involvement.

What you will see

Once registration succeeds, the new number appears on the WhatsApp channel list in Settings, then Channels, then WhatsApp like any other connected number, with no visible indicator that it was registered by OTP versus Embedded Signup, and no PIN field shown anywhere afterward. Day-to-day sending, receiving, templates and broadcasts on that number behave identically regardless of which connection path was used to add it.

Settings and options

Setting or fieldWhat it doesDefault
Two-step verification PINA Meta-side, 6-digit credential tied to the phone number, required for future re-registration or migrationSet once during Register new number; not shown or editable afterward inside VGraple CRM
OTP delivery methodSMS or voice call, chosen when starting registrationSMS, changeable to voice on the same screen if SMS fails to arrive
Registering permissionWho can register a new number and therefore set its PINOwner, Admin, or a custom role granted settings:org

Troubleshooting

SymptomLikely causeFix
"Registration failed. Check your PIN and try again."The PIN submitted did not meet Meta's format requirement, or a transient Meta-side errorConfirm the PIN is exactly 6 digits and resubmit; if it repeats, check the number is not already registered elsewhere
Forgot the PIN and need to re-register the numberNo local recovery exists, since VGraple CRM does not store it in a retrievable formUse Meta's own number recovery path (a wait period, then re-registration with a new PIN) through Meta Business Manager, or contact Meta Business Help Centre
Confusing this PIN with the VGraple CRM account password or 2FA codeThe two systems are unrelated; this PIN is Meta's, not VGraple CRM'sReset your VGraple CRM password or account 2FA from Settings, then Profile; neither action touches the WhatsApp number's PIN
PIN prompt never appeared when connecting a numberThe number was connected through Embedded Signup, which registers the number without prompting VGraple CRM for a PINExpected; Embedded Signup handles registration on Meta's side without this step
OTP never arrivesWrong country code, or the number cannot receive SMS in that regionRe-check the number and country code, then try Voice call instead of SMS

This PIN is set as part of the same flow described in connecting your WhatsApp number; read that page for the full registration walkthrough. If you later need to move this number to a different phone or reconnect it, see changing or adding a WhatsApp number. It is unrelated to your VGraple CRM account's own login security, covered on the security and roles feature page.

Frequently asked questions

What does the two-step verification PIN actually protect?
It is Meta's own security measure on the WhatsApp phone number itself, separate from your VGraple CRM login. It prevents someone from re-registering your number on the Cloud API, or migrating it to a different platform or provider, without knowing this PIN.
Is this the same as VGraple CRM's two-factor authentication (2FA)?
No, and they protect different things. VGraple CRM's account 2FA (TOTP, set up from Settings, then Profile) protects who can log into your VGraple CRM workspace. The two-step verification PIN is a Meta-side credential tied to the phone number itself, required by WhatsApp's own registration API, and has nothing to do with your VGraple CRM login.
When am I asked to set this PIN?
Only when registering a brand-new number directly through Cloud API's OTP flow, in Settings, then Channels, then WhatsApp, using Register new number. A number connected through Embedded Signup does not go through this step inside VGraple CRM, since Meta handles registration as part of that flow instead.
What happens if I forget my two-step verification PIN?
It cannot be recovered or looked up, since VGraple CRM does not store it in reversible form beyond what registration requires and Meta does not expose a lookup endpoint for it. If you no longer know it and need to re-register or migrate the number, Meta's own recovery path applies: after a wait period the number can be re-registered with a new PIN, or reset through Meta Business Manager.
Does VGraple CRM store my PIN?
The PIN is sent directly to Meta's registration endpoint as part of the one-time registration call and is not displayed or retrievable afterward inside VGraple CRM. Keep your own copy somewhere secure at the time you set it, since it is required again for any future migration or re-registration of that number.
Do I need this PIN for day-to-day sending?
No. Once a number is registered, normal sending and receiving through VGraple CRM never asks for the PIN again. It only resurfaces if the number needs to be re-registered, migrated to another platform, or recovered after certain account issues.

Run your WhatsApp on VGraple CRM

Free forever plan, official Meta WhatsApp Business API, set up in 15 minutes. No card needed.