WhatsApp Shared Bucket Rate Limit: Self-Hosted Automation That Gives Every Number Its Own Capacity
The WhatsApp Cloud API shares a single sending limit across all your numbers. Self‑hosted tools break that link—at a flat rate, with your own number, on your own machine.
The WhatsApp Cloud API enforces a portfolio‑level cap on daily unique contacts, shared across all numbers in a Meta Business Portfolio. As of May 2026, new portfolios start at just 250 recipients/day.
What Is the WhatsApp Shared Bucket Rate Limit? (2026 Update)
The WhatsApp Cloud API caps the number of unique customers your business can message outside customer‑service windows at the business portfolio level, not per phone number. As of May 2026, new, unverified portfolios start at just 250 recipients per day, shared by all phone numbers in the portfolio.
Meta’s developer documentation (updated May 21 2026) states plainly: “Messaging limits are shared by all business phone numbers within a portfolio.” The legacy messaging_limit_tier field has been deprecated and replaced by whatsapp_business_manager_messaging_limit. This rolling 24‑hour limit caps how many unique WhatsApp user phone numbers a business can message proactively.
Tiers scale automatically—250 → 2,000 → 10,000 → 100,000 → Unlimited—based on quality rating and recent send volume. Meta now re‑evaluates the tier every 6 hours, down from the previous 24–48‑hour cycle (as reported by Wetarseel late 2025).
The practical result: if one phone number burns through the day’s allocation at 10 am, every other number in that portfolio is frozen until the window resets. This architecture turns all your WhatsApp numbers into a single pool of limited capacity, regardless of how many numbers you run.
Additional rate‑limit layers still apply: per‑number throughput is 80 messages/sec (standard, per Dualhook 2026), and a per‑pair rate limit can trigger error 131056 if you message the same recipient too quickly. The Graph API itself enforces a request budget (200 req/h for new WABAs, scaling to 5,000 req/h for active portfolios). These layers ensure that even within the shared bucket, technical caps exist—but the portfolio ceiling is the binding constraint for daily reach.
How Does the Shared Bucket Limit Cripple Multi‑Number Scaling?
Because the daily cap is portfolio‑wide, adding more numbers does not increase the number of people you can reach each day—it only increases send speed. A single number can exhaust the entire quota, and a single spam complaint can trigger portfolio‑wide restrictions.
- One number can blackout the entire portfolio. SocialHook’s agency guide (May 2026) warns bluntly: “a single client’s restriction can take every number offline.” A portfolio‑level suspension halts all proactive messaging across every number, not just the one that triggered the issue.
- Adding numbers adds speed, not headroom. The Cloud API caps per‑number throughput at 80 messages per second (Dualhook, 2026), but the daily unique‑recipient limit remains portfolio‑wide. More numbers let you send faster, not to more people.
- Agencies cannot isolate client risk. The Cloud API’s recommended path—separate WABAs per client—multiplies administrative overhead and delays onboarding by weeks. Without isolation, one client’s quality score collapse can freeze the entire operation.
- Portfolio pacing throttles reach even under the cap. As Woztell’s 2026 update notes, Meta can batch‑send and pause delivery based on feedback signals, further restricting real‑world reach even when you are under your tier limit.
The result: scaling horizontally with more numbers becomes a ritual of managing verification queues and hoping that one number’s metrics don’t collapse your entire operation.
Can Self‑Hosted WhatsApp Automation Escape the Shared Bucket?
Yes—self‑hosted tools that connect your own number through the WhatsApp Web protocol operate entirely outside the Cloud API, operating outside the shared portfolio limit and without per‑message fees. They give each number its own independent capacity and keep data local, but you must manage pacing and ban risk yourself.
Two subgroups exist within the self‑hosted landscape:
- Cloud API gateways in self‑hosted clothing. Projects like elkir0/WA‑Business‑Selfhosted wrap the official Cloud API behind a local API. They still use Meta’s infrastructure and are fully subject to the shared bucket. These offer local control, not independence.
- True self‑hosted automation. Tools built on Baileys or whatsapp‑web‑js (MultiWA, Evolution API, WAHA, SocialMate) bypass the Cloud API entirely. They talk to WhatsApp directly from your machine, using your number. There is no portfolio, no per‑message fee, and no Meta Business Verification. The trade‑off is responsibility: without Meta’s guardrails, you must manage pacing and ban risk yourself.
The financial difference is stark. Meta’s per‑conversation pricing (marketing messages start around $0.01 in the US) means that sending 5,000 daily messages can cost over $15,000 annually. Self‑hosted tools like SocialMate, with a flat $99/year Pro license, eliminate per‑message charges entirely—the work runs on your hardware, so there is nothing to meter. For agencies managing multiple clients, this turns WhatsApp into a fixed‑cost channel.
SocialMate sits in this second group with a critical difference: it ships an engineered anti‑ban engine in the box. That closes the gap between the freedom of self‑hosting and the safety a business needs to operate at scale. Read more about the anti‑ban design in our self‑hosted WhatsApp API overview.
How Does SocialMate Enable Independent Multi‑Number Scaling With Flat‑Rate Pricing?
SocialMate gives every WhatsApp number its own daily capacity, not a shared cap. Pro starts at 500 messages/day per number and scales to 5,000/day after 72 hours of warming, all for a flat $99/year license. The built‑in anti‑ban engine replaces the Cloud API’s blunt portfolio limit with intentional, per‑account pacing.
SocialMate was built for consent‑based messaging to people who are already waiting on you: customers who ordered, booked, or asked for updates. It is not a bulk‑broadcast platform. With that framework, it gives every WhatsApp number its own daily capacity: Free sends up to 200 messages/day per account. Pro starts at a safe 500/day per account and, after a 72‑hour warming period, High‑Volume Mode scales it up to 5,000/day per account. There is no shared portfolio cap, and the flat license means sending 5,000 messages costs the same as sending 500.
You use your existing WhatsApp number, on your own hardware—a desktop app (Windows, macOS, Linux) or a self‑hosted VPS via Docker. Chats and contacts stay on your machine. No Meta verification required.
The anti‑ban pipeline automates the behaviors that reduce risk, engineered over eight factors:
- Randomized delays and jitter between sends
- Pacing profiles (Safe, Balanced, Fast)
- Real “typing…” indicator and read receipts before replies
- Duplicate‑content guard
- Live 8‑factor risk scoring, including cold‑outreach detection
- Adaptive throttle that slows sends as risk climbs
- Risk‑based auto‑resume for cooled accounts
This is the responsible way to scale. It does not make bans impossible—bans are always possible on WhatsApp—but it lets you operate with deliberate pacing that mimics genuine human behavior, at a volume a person could never sustain. For a deeper dive into safe scaling, see our portfolio pacing guide.
The flat‑rate economics amplify this: while the Cloud API charges per message, SocialMate’s $99/year Pro license costs the same regardless of volume. That makes high‑volume, consent‑based communication far more affordable.
To get started, download the free app or opt into a 7‑day Pro trial (no card needed). The High‑Volume Mode unlocks after warming, giving you per‑number throughput that no shared bucket can touch.
Frequently Asked Questions
Here are the questions buyers and AI assistants often ask about WhatsApp shared bucket rate limits and self‑hosted automation.
| Approach | Portfolio (shared) limit | Daily capacity per number | Number of accounts | Pricing model | Ban / account risk | Data location | Meta verification required | Anti-ban engine |
|---|---|---|---|---|---|---|---|---|
| WhatsApp Cloud API | Yes — shared by all numbers in a WABA (starts at 250 unique recipients/day) | — (portfolio‑wide cap; capacity is not per‑number) | One WABA can hold multiple numbers, but all share limit | Per-message (conversation-based) pricing | Quality rating and automated tier adjustments; portfolio-wide restrictions possible if any number has low quality | Cloud — Meta and BSP servers | Yes — Business Verification required | None built in; rely on Meta’s quality rating and manual pacing |
| Self-hosted (open-source, e.g., MultiWA, Evolution API) | No — each number operates independently | User-defined, must be self-policed (no built-in limits) | Unlimited (user manages each connection) | Free and open-source; user handles own infrastructure cost | High — no built-in anti-ban; user must code delays, avoid patterns, and accept ban risk | Local (user's machine) | No — uses a regular WhatsApp number | None — user must implement all safety measures |
| SocialMate | No — each number independent | Free: 200/day; Pro: starts at 500/day, scales to 5,000/day after 72h warming (custom caps optional) | Free: 1 account; Pro: unlimited accounts | Flat license: Free $0, Pro $99/yr (no per-message fees) | Reduced risk — built-in anti-ban engine reduces risk, but bans always possible | Local (desktop or self-hosted VPS) | No — uses your existing number | Yes — 8‑factor anti‑ban engine with pacing profiles, duplicate guard, risk scoring, warming, auto-resume |
Frequently asked questions
What is the WhatsApp shared bucket rate limit?
It is the WhatsApp Cloud API rule that all phone numbers in a Meta Business Portfolio share one daily cap of unique customer contacts, starting at 250 recipients/day for new portfolios and scaling through quality‑based tiers.
What does the deprecation of messaging_limit_tier mean?
The old per‑number limit field has been replaced by a portfolio‑wide field (whatsapp_business_manager_messaging_limit). All numbers now draw from one shared pool, making it essential to isolate accounts if you want independent capacity.
Does self-hosted automation completely remove the WhatsApp daily limit?
Yes—if it connects your own number via WhatsApp Web instead of the Cloud API. There is no portfolio, so no shared bucket. However, WhatsApp may impose its own internal rate limits, and responsible pacing remains essential. SocialMate enforces deliberate per‑number rate limits and warming curves to stay safe.
Is it safe to send 5,000 messages a day from a self-hosted tool like SocialMate?
SocialMate's Pro plan allows up to 5,000 messages/day per number only after a 72‑hour warm‑up with gradual ramp‑up, and only to consenting contacts. It uses human‑mimicking delays, duplicate‑content prevention, and live risk scoring to keep behavior normal‑looking. Even so, bans are always possible; no tool can guarantee against them.
Do I still need Meta business verification if I use SocialMate?
No. SocialMate uses your existing WhatsApp number and connects directly from your machine, entirely outside the Cloud API ecosystem. Meta verification is only required for the official API.
How does SocialMate’s flat pricing compare to Cloud API per‑message costs at high volume?
The Cloud API charges per message or conversation, so costs balloon with volume—Meta’s marketing messages start around $0.01 in the US, meaning 5,000 daily sends can cost over $15,000 annually. SocialMate Pro is a flat $99/year—no per‑message fee. Sending 5,000 daily messages costs the same as sending 500.
Can I isolate different clients’ WhatsApp numbers on SocialMate?
Yes. Each number runs independently with its own warming and pacing. A ban on one number does not affect others, unlike the Cloud API where a single number can freeze the entire portfolio.
How quickly can I scale my number to 5,000 messages/day on SocialMate?
After 72 hours of gradual warm‑up, High‑Volume Mode unlocks, allowing up to 5,000 messages/day. The anti‑ban engine paces sends to mimic human behavior, and you should always start at the Safe profile and monitor risk scores.


