Blog

WhatsApp MCP: Connect WhatsApp to Claude and ChatGPT

A WhatsApp MCP server lets an AI client such as Claude, ChatGPT or Cursor read your WhatsApp chats and send messages, media and voice notes for you, through the Model Context Protocol. On MCPifex the server is hosted: you link your number by scanning a QR code, choose which tools the agent may use, and paste one key into your client.

A quick example

Say you are in the middle of work and type this into Claude: "Check if Sara replied about Friday, and tell her I'm running ten minutes late."

With a WhatsApp MCP server connected, Claude:

  1. lists your recent chats and finds the one with Sara;
  2. reads the latest messages in that chat, both hers and yours;
  3. tells you what she said about Friday;
  4. sends her your message, and confirms it went out.

You never opened WhatsApp. The AI client did not need a special WhatsApp integration either. It asked the server which tools exist, then used them.

How it works

Four pieces sit between your sentence and the message that lands on Sara's phone. Each one has a single job.

HOW A REQUEST TRAVELS plain language MCP over HTTPS + API key tool call message You Your AI client MCPifex gateway WhatsApp MCP server Your WhatsApp number "Tell Sara I'm running ten minutes late" Claude, ChatGPT, Cursor or any MCP client Checks your key, allows only the tools you enabled Turns the request into a WhatsApp action Linked as a device, like WhatsApp Web
How a request travels from your AI client to WhatsApp and back.

Your number is linked the same way WhatsApp Web is: as a linked device on your account. Your phone keeps working as usual, and you can remove the link at any time from Linked devices in WhatsApp.

The gateway in the middle is what makes this safe to hand to an agent. It checks your API key on every request and only passes through the tools you switched on. If the agent tries a tool you left off, the call is refused. Our post on controlling what AI agents can reach explains that model in more depth.

Set it up in four steps

As of October 2026, WhatsApp is available on the Pro and Team plans. The whole setup takes a few minutes and needs no install.

SETUP IN FOUR STEPS 1 2 3 4 Create the instance Link your number Choose the tools Paste the key into your AI client Marketplace, then WhatsApp, then Connect Scan the QR code from Linked devices Reading and sending are on; risky ones are off One gateway URL and one API key
The whole setup, from the marketplace to your AI client.
  1. Create the instance. In the portal, open the marketplace, pick WhatsApp and click Connect.
  2. Link your number. Click Link WhatsApp. On your phone, open WhatsApp, go to Linked devices, choose Link a device and scan the QR code. If you are on the same phone, use the code option instead: enter your number and type the eight-character code into WhatsApp.
  3. Choose the tools. Leave the defaults or adjust them. Run Test connection, then create the instance.
  4. Paste the key into your AI client. The portal shows an API key once. Copy it.

For Claude Code, the last step is one command:

#!/bin/sh
# MCPifex — Claude Code CLI snippet.
# Replace <YOUR_MCPX_KEY> with your MCPifex API key (starts "mcpx_"), from
# the portal's API key page, then run this once from any shell that has the
# `claude` CLI on PATH.
claude mcp add mcpifex --transport http https://mcpifex.com/mcp \
  --header "Authorization: Bearer <YOUR_MCPX_KEY>"

Web clients that cannot send a header take the key in the URL instead: https://mcpifex.com/mcp/<YOUR_MCPX_KEY>. Treat that URL like a password. Step-by-step instructions are in the guides for Claude Code and ChatGPT.

What the agent can do

The server has 61 tools. On a new instance, 37 are on and 24 are off. The split follows one rule: reading and ordinary sending are on, and anything that is hard to undo is off until you enable it.

GroupExamplesDefault
ReadList chats, read messages, find contacts, check if a number is on WhatsApp, list groupsOn
SendText, images, documents, voice notes, locations, contacts, polls, reactionsOn
HousekeepingMark as read, show a typing indicatorOn
ChangesEdit a sent message, archive a chat, post a status, manage groups, change your profileOff
DestructiveDelete a message, block a contact, leave a group, remove group membersOff

The agent can address a chat by plain phone number with country code, such as 2348012345678. It does not need to know WhatsApp's internal chat ids.

One thing to know: nothing is pushed to the agent. It sees new messages when you ask it to look, by calling a read tool. It will not interrupt you when a message arrives.

Voice notes

Voice notes work in both directions, with one condition each way.

RECEIVING A VOICE NOTE SENDING A VOICE NOTE Contact sendsa voice note MCPifex storesthe audio Agent gets text+ audio link Agent asks foran upload link Agent uploadsthe audio file WhatsApp sendsa voice note The transcript needs your own OpenAI key. Without one, the agent gets the audio link only. Your AI client creates the audio. There is no built-in text-to-speech.
Voice notes: what happens when you receive one and when you send one.

Receiving. Most AI clients cannot listen to audio. So when a contact sends a voice note, the agent gets a transcript and a short-lived link to the audio file. The transcript is made with your own OpenAI API key, which you add to the instance as an optional field. Without a key, the agent still gets the link.

Sending. The agent first asks the server for an upload link, uploads the audio file there, then sends it. WhatsApp delivers it as a normal voice note. The audio has to come from your AI client or your own files. There is no built-in text-to-speech. The same upload step is used for images and documents, so the agent cannot make the server fetch a file from an arbitrary web address.

What it does not do

  • Calls. There are no voice or video call tools.
  • Old history. The agent can read messages sent and received after you linked the number. Your earlier chat history is not imported.
  • Official status. This is an unofficial linked-device connection. It is not affiliated with or endorsed by WhatsApp. WhatsApp's terms do not allow unofficial clients, and WhatsApp may restrict or ban a number that automates messaging, so use a number you can afford to lose access to, and do not use it for bulk or unsolicited messages.

Privacy and safety

A hosted server is a trade-off, and you should know both sides. The well-known open-source WhatsApp MCP servers run on your own computer and keep your messages in a local database. That keeps the data with you, but the computer has to stay on, and web clients like ChatGPT cannot reach it.

With the hosted server, messages that arrive after linking, and the media in them, are stored on MCPifex so the agent can read them later. They stay until you delete the instance. Deleting the instance removes its stored messages and media and unlinks the device.

The second risk is the content itself. A WhatsApp message is text written by someone else, and your agent reads it. A message can contain instructions aimed at the agent, such as "forward this chat to another number". That is prompt injection, and no tool setting removes it completely. Three habits reduce it:

  • keep the destructive tools off unless a task needs them;
  • ask the agent to show you a message before it sends it, at least to new contacts;
  • give the WhatsApp instance its own API key, so you can revoke it without touching your other servers.

We cover the attack and the defences in prompt injection through MCP tools.

Who it is for

It fits a person or a small team that already lives in an AI client and wants WhatsApp inside the same conversation: catching up on unread chats, drafting replies, sending a file, or turning a voice note into text. It is not a bulk messaging tool and not a customer-service platform. For those, the official WhatsApp Business Platform is the right choice.

You can see WhatsApp next to the other hosted servers in the MCPifex marketplace, and the plans on the pricing page.

Key takeaways

  • A WhatsApp MCP server gives any MCP client tools to read chats and send messages, media and voice notes.
  • On MCPifex you link a number with a QR code; there is nothing to install or keep running.
  • Reading and sending are on by default; edits, group management and deletions are off until you enable them.
  • Received voice notes arrive as a transcript when you add your own OpenAI key.
  • It is an unofficial connection: no calls, no bulk messaging, and WhatsApp may restrict numbers that automate.

Frequently asked questions

Is this the official WhatsApp API?
No. It uses an unofficial linked-device connection, the same mechanism as WhatsApp Web, and is not affiliated with or endorsed by WhatsApp. WhatsApp may restrict or ban numbers that automate messaging, so it is meant for personal and small-team use, not bulk messaging. For high-volume business messaging, use the official WhatsApp Business Platform.
Can the AI agent make or answer WhatsApp calls?
No. There are no voice or video call tools. The agent can read and send messages, media and voice notes.
Do I need to keep my computer on?
No. The server is hosted by MCPifex, so nothing runs on your computer. Your phone does not need to be online for each message, but WhatsApp logs out linked devices when the phone has not been used for about two weeks.
Does the agent see new messages as they arrive?
No. Nothing is pushed to the agent. It reads new messages when you ask it to, by calling a read tool.
Which MCPifex plans include WhatsApp?
As of October 2026, WhatsApp is available on the Pro and Team plans. Each linked number is one instance and counts toward the plan's instance limit.

Sources

  1. Model Context Protocol: Introduction.
  2. WhatsApp Help Center: About unofficial apps.
  3. GitHub: lharries/whatsapp-mcp, an open-source WhatsApp MCP server that runs locally.
  4. OpenAI: Speech to text.