WhatsApp MCP: Connect WhatsApp to Claude and ChatGPT
A WhatsApp MCP server lets an AI client such as Claude, ChatGPT or Cursor read your WhatsApp chats and send messages, media and voice notes for you, through the Model Context Protocol. On MCPifex the server is hosted: you link your number by scanning a QR code, choose which tools the agent may use, and paste one key into your client.
A quick example
Say you are in the middle of work and type this into Claude: "Check if Sara replied about Friday, and tell her I'm running ten minutes late."
With a WhatsApp MCP server connected, Claude:
- lists your recent chats and finds the one with Sara;
- reads the latest messages in that chat, both hers and yours;
- tells you what she said about Friday;
- sends her your message, and confirms it went out.
You never opened WhatsApp. The AI client did not need a special WhatsApp integration either. It asked the server which tools exist, then used them.
How it works
Four pieces sit between your sentence and the message that lands on Sara's phone. Each one has a single job.
Your number is linked the same way WhatsApp Web is: as a linked device on your account. Your phone keeps working as usual, and you can remove the link at any time from Linked devices in WhatsApp.
The gateway in the middle is what makes this safe to hand to an agent. It checks your API key on every request and only passes through the tools you switched on. If the agent tries a tool you left off, the call is refused. Our post on controlling what AI agents can reach explains that model in more depth.
Set it up in four steps
As of October 2026, WhatsApp is available on the Pro and Team plans. The whole setup takes a few minutes and needs no install.
- Create the instance. In the portal, open the marketplace, pick WhatsApp and click Connect.
- Link your number. Click Link WhatsApp. On your phone, open WhatsApp, go to Linked devices, choose Link a device and scan the QR code. If you are on the same phone, use the code option instead: enter your number and type the eight-character code into WhatsApp.
- Choose the tools. Leave the defaults or adjust them. Run Test connection, then create the instance.
- Paste the key into your AI client. The portal shows an API key once. Copy it.
For Claude Code, the last step is one command:
#!/bin/sh
# MCPifex — Claude Code CLI snippet.
# Replace <YOUR_MCPX_KEY> with your MCPifex API key (starts "mcpx_"), from
# the portal's API key page, then run this once from any shell that has the
# `claude` CLI on PATH.
claude mcp add mcpifex --transport http https://mcpifex.com/mcp \
--header "Authorization: Bearer <YOUR_MCPX_KEY>"
Web clients that cannot send a header take the key in the URL instead: https://mcpifex.com/mcp/<YOUR_MCPX_KEY>. Treat that URL like a password. Step-by-step instructions are in the guides for Claude Code and ChatGPT.
What the agent can do
The server has 61 tools. On a new instance, 37 are on and 24 are off. The split follows one rule: reading and ordinary sending are on, and anything that is hard to undo is off until you enable it.
| Group | Examples | Default |
|---|---|---|
| Read | List chats, read messages, find contacts, check if a number is on WhatsApp, list groups | On |
| Send | Text, images, documents, voice notes, locations, contacts, polls, reactions | On |
| Housekeeping | Mark as read, show a typing indicator | On |
| Changes | Edit a sent message, archive a chat, post a status, manage groups, change your profile | Off |
| Destructive | Delete a message, block a contact, leave a group, remove group members | Off |
The agent can address a chat by plain phone number with country code, such as 2348012345678. It does not need to know WhatsApp's internal chat ids.
One thing to know: nothing is pushed to the agent. It sees new messages when you ask it to look, by calling a read tool. It will not interrupt you when a message arrives.
Voice notes
Voice notes work in both directions, with one condition each way.
Receiving. Most AI clients cannot listen to audio. So when a contact sends a voice note, the agent gets a transcript and a short-lived link to the audio file. The transcript is made with your own OpenAI API key, which you add to the instance as an optional field. Without a key, the agent still gets the link.
Sending. The agent first asks the server for an upload link, uploads the audio file there, then sends it. WhatsApp delivers it as a normal voice note. The audio has to come from your AI client or your own files. There is no built-in text-to-speech. The same upload step is used for images and documents, so the agent cannot make the server fetch a file from an arbitrary web address.
What it does not do
- Calls. There are no voice or video call tools.
- Old history. The agent can read messages sent and received after you linked the number. Your earlier chat history is not imported.
- Official status. This is an unofficial linked-device connection. It is not affiliated with or endorsed by WhatsApp. WhatsApp's terms do not allow unofficial clients, and WhatsApp may restrict or ban a number that automates messaging, so use a number you can afford to lose access to, and do not use it for bulk or unsolicited messages.
Privacy and safety
A hosted server is a trade-off, and you should know both sides. The well-known open-source WhatsApp MCP servers run on your own computer and keep your messages in a local database. That keeps the data with you, but the computer has to stay on, and web clients like ChatGPT cannot reach it.
With the hosted server, messages that arrive after linking, and the media in them, are stored on MCPifex so the agent can read them later. They stay until you delete the instance. Deleting the instance removes its stored messages and media and unlinks the device.
The second risk is the content itself. A WhatsApp message is text written by someone else, and your agent reads it. A message can contain instructions aimed at the agent, such as "forward this chat to another number". That is prompt injection, and no tool setting removes it completely. Three habits reduce it:
- keep the destructive tools off unless a task needs them;
- ask the agent to show you a message before it sends it, at least to new contacts;
- give the WhatsApp instance its own API key, so you can revoke it without touching your other servers.
We cover the attack and the defences in prompt injection through MCP tools.
Who it is for
It fits a person or a small team that already lives in an AI client and wants WhatsApp inside the same conversation: catching up on unread chats, drafting replies, sending a file, or turning a voice note into text. It is not a bulk messaging tool and not a customer-service platform. For those, the official WhatsApp Business Platform is the right choice.
You can see WhatsApp next to the other hosted servers in the MCPifex marketplace, and the plans on the pricing page.
Key takeaways
- A WhatsApp MCP server gives any MCP client tools to read chats and send messages, media and voice notes.
- On MCPifex you link a number with a QR code; there is nothing to install or keep running.
- Reading and sending are on by default; edits, group management and deletions are off until you enable them.
- Received voice notes arrive as a transcript when you add your own OpenAI key.
- It is an unofficial connection: no calls, no bulk messaging, and WhatsApp may restrict numbers that automate.
Frequently asked questions
- Is this the official WhatsApp API?
- No. It uses an unofficial linked-device connection, the same mechanism as WhatsApp Web, and is not affiliated with or endorsed by WhatsApp. WhatsApp may restrict or ban numbers that automate messaging, so it is meant for personal and small-team use, not bulk messaging. For high-volume business messaging, use the official WhatsApp Business Platform.
- Can the AI agent make or answer WhatsApp calls?
- No. There are no voice or video call tools. The agent can read and send messages, media and voice notes.
- Do I need to keep my computer on?
- No. The server is hosted by MCPifex, so nothing runs on your computer. Your phone does not need to be online for each message, but WhatsApp logs out linked devices when the phone has not been used for about two weeks.
- Does the agent see new messages as they arrive?
- No. Nothing is pushed to the agent. It reads new messages when you ask it to, by calling a read tool.
- Which MCPifex plans include WhatsApp?
- As of October 2026, WhatsApp is available on the Pro and Team plans. Each linked number is one instance and counts toward the plan's instance limit.
Sources
- Model Context Protocol: Introduction.
- WhatsApp Help Center: About unofficial apps.
- GitHub: lharries/whatsapp-mcp, an open-source WhatsApp MCP server that runs locally.
- OpenAI: Speech to text.
Ready to try it?
Host any MCP server behind one endpoint and control exactly what your agents can reach.