WhatsApp CTA-URL tap-to-open link buttons
A CTA-URL button is a labelled link button attached below a free-form WhatsApp message: the customer sees your message text with one button under it, and tapping the button opens your URL in their browser. You choose the label and the URL at send time, and because the message ships inside the 24-hour customer-service window, nothing waits for Meta template review. This guide shows the send request, what a tap produces on your webhook endpoint, the rules the URL and label have to follow, and when a template URL button is the better fit.Why no template review is needed
Meta splits WhatsApp outbound into two regimes: pre-approved templates for business-initiated contact, and free-form messages inside the 24-hour customer-service window that the customer opens by messaging you. A CTA-URL button belongs to the free-form regime. It is an interactive message type (cta_url) sent exactly like a session text message, with a link button attached, so it is allowed whenever a session text message is allowed and refused whenever one would be refused.
The trade-off is reach. Once the window lapses, only a template can reach the customer, and that includes messages with a CTA-URL button. Plan CTA-URL sends for conversations the customer has recently started.
The send request
POST /api/v1/whatsapp/messages/send-interactive with an action of display_text + url sends a CTA-URL button:
A non-HTTPS URL is rejected with a 422 before anything is sent. The same route also sends tap-to-reply buttons (
action: { buttons }, up to three) and list menus (action: { button, sections }); only the display_text + url shape produces a CTA-URL button.
A successful send returns the message id and status, and your webhook subscribers receive message.sent as with any other send. If the 24-hour window is closed for this customer the send is refused; check window status before you send, or fall back to a template.
What a tap produces
WhatsApp does not send a “button tapped” webhook for CTA-URL buttons; the tap simply opens the link in the customer’s browser. Orbit makes the tap observable another way: before the message leaves, yoururl is rewritten to a tracked short link, so the button opens your short-link address and the recipient is redirected on to the destination through GET /l/:code. The redirect records the click and fires a short_link.click webhook on your endpoint:
message_id ties the click to the send that carried the button; url is your original destination, not the short address. The click lands in the same per-link stats and campaign rollups as every other tracked link; see Short links, landing pages, and the publish lifecycle for the model and Short links with click tracking for reading the numbers.
Two behaviors to plan around:
- Links you write into the free-form
bodyare shortened and tracked the same way, so a tap on a body link and a tap on the button produce the same event. - Link tracking is on by default. If your organization turns off the
whatsapp_auto_shorten_urlssetting, the button opens your URL directly and no click events fire.
URL and label rules
- HTTPS only.
urlmust be anhttps://link; the API rejects anything else with a 422. - Label the destination honestly.
display_textis what the customer taps on. Keep it a short instruction that matches the page it opens (“Track order”, “View invoice”), never a disguise for a different destination. - Track your own links for your own measurement. Click tracking exists for attribution, so you can see which message drove the tap. Pointing a tracked button at a destination the customer would not expect from you violates Meta’s content rules for WhatsApp and your own compliance posture; see WhatsApp content policy.
Worked example: order update with a tracked CTA
- The customer messages you (“Where is my order?”), opening the 24-hour window.
- You send the order update with a CTA-URL button:
- The response returns the message id with
"status": "sent", and your endpoint receivesmessage.sentfor it. The customer sees the text with a Track order button. - The customer taps the button. Their browser opens the short-link address, is redirected to
https://shop.example.com/orders/10482/status, and your endpoint receives theshort_link.clickpayload above withmessage_idmatching the send.
short_link.click never arrives for a send, check that link tracking is on for your organization and that your webhook subscription includes short_link.click.
CTA-URL button vs. template URL button
One rule decides it: an open window plus a link that varies per send points at a CTA-URL button; business-initiated or reusable points at a template.