# whatsapp-agentkit: the repository is a prompt, an unset webhook secret accepts everything, and no dependency manifest exists for the server it generates

> whatsapp-agentkit is a Spanish-language instruction set for Claude Code. You clone it, run a shell script that only checks your environment, start Claude Code, and type one slash command. The assistant interviews you in ten questions and then writes, tests and deploys a FastAPI WhatsPress bot for your business. It is aimed at people in Latin America who do not program, and it is unusually honest about its own failure modes.

**Hainrixz/whatsapp-agentkit** — Construye tu agente de WhatsApp con IA en menos de 30 minutos. Claude Code te entrevista y escribe todo el código. Zernio o Meta Cloud API. Sin saber programar.

- Repository: https://github.com/Hainrixz/whatsapp-agentkit
- Website: https://hainrixz.github.io/whatsapp-agentkit/
- Stars: 520 · Forks: 162
- Language: Python
- License: MIT
- Published: 2026-09-15 · Updated: 2026-09-15 · Language: en
- Canonical page: https://hysenlabs.com/projects/hainrixz-whatsapp-agentkit

## The repository is an instruction set, not an agent

The top level holds `.claude/`, `.env.example`, `.gitignore`, `CLAUDE.md`, `LICENSE`, `README.md`, `docs/`, `knowledge/`, `scripts/`, and `start.sh`. There is no `agent/` directory and no Python module. The project says so directly: it is not a template you copy and adapt, it is an instruction system that Claude Code reads in order to interview you about your business and then write, test and deploy the complete agent for you, including the server, the WhatsApp connection, each customer's memory, and the prompt that gives it personality. The file tree the assistant is told to produce, with `agent/main.py`, `brain.py`, `memory.py`, `tools.py`, and a `providers/` package, does not exist until it runs. So the MIT licence covers the scaffolding, and the code you end up running is written per user with no licence attached to it and no review from the project's author.

## An unset webhook secret starts the agent and lets everything through

The flow diagram states that `main.py` verifies the webhook signature. The prose immediately qualifies that. Every webhook is signed with HMAC-SHA256 and the agent checks it before touching the message, and without that check anyone who knows your URL could inject messages into your agent. Then comes the disclosure: the check needs `ZERNIO_WEBHOOK_SECRET`, or `META_APP_SECRET`, and if you leave it empty the agent starts anyway, so you can test without getting stuck, but it warns in the logs and lets everything through. `.env.example` ships that variable empty with a comment telling you to invent the value yourself. So the default state of a fresh install is an unauthenticated webhook whose only signal is a line in a log, and the diagram's unconditional step and the prose's optional one describe different systems. The project does tell you to load the secret before putting the agent in front of real customers, which is the right instruction in the right place.

## No dependency manifest exists for the server the agent runs

Phase 1 of the build has Claude Code check Python 3.11 or newer, create the folders, install the dependencies, and prepare the `.env`. There is no `requirements.txt`, no `pyproject.toml`, no lockfile, and no pinned version anywhere in the ten repository entries. The dependencies of the delivered product are whatever the assistant decides to install while writing it. That sits awkwardly against the project's own pitch, which is that ninety percent of the work in standing up a WhatsApp agent is not the AI but the plumbing of webhooks, signatures, tokens, retries and deployment, and that this plumbing is already solved and audited here. The design choices that make the plumbing correct are documented well: reply within about five seconds or the provider retries, up to seven times, so the webhook acknowledges immediately and the work happens afterwards; delivery is at-least-once, so events are deduplicated by id in the database. None of that is verified by a manifest you can inspect.

## The recommended provider is a reseller, and the account id arrives in the payload

Two options are compared and one is recommended for almost everyone: Zernio, a service that runs on top of Meta's Cloud API and handles the connection for you, against connecting to Meta's Cloud API directly. The table is candid about the differences. Zernio needs no Facebook app, no App Review, and no separate business verification, gives two connected accounts free without a card, and offers a shared test number limited to fifty messages per twenty-four hours. Meta direct needs a Business app, App Review, and a verified Business account, though Meta also supplies a test number once the app exists. In both cases conversation fees are paid to Meta. Migration is described as a single sentence to Claude Code. One detail in the configuration file is easy to miss: `ZERNIO_ACCOUNT_ID` is marked optional, used only to check the connection at startup, with a note that the account id comes from the webhook itself. That means the payload names the account, which is harmless only while signature verification is actually on.

## The interview collects a key in a chat before the project is pushed

Question six of the ten is your Anthropic API key, asked in the same conversation where you are also describing your pricing and your opening hours. `.env.example` reinforces the arrangement, saying Claude Code helps fill the values in during setup and never to upload the `.env` file to GitHub. A key pasted into an interactive CLI session lands in that session's transcript, which is a different store from an environment file, and it will be on screen while you answer question seven. Phase 5 then walks you through pushing the generated project to GitHub, connecting it to Railway, loading environment variables, and configuring the webhook. That sequence makes the `.env` instruction load-bearing, and the repository's own `.gitignore` does not travel with the generated project unless the assistant copies it. If you intend to commit the result, check the ignore rules in the generated repository before the first push rather than after.

## A reasoning parameter ships enabled against a 4096 token cap

The Anthropic block of the example environment file lists three models with per-million-token prices: `claude-opus-5` at five and twenty-five, `claude-sonnet-5` at three and fifteen, and `claude-haiku-4-5` at one and five. Two are on version five and one is on version four-five, so the naming across three lines of one file uses two conventions. `ANTHROPIC_MODEL` is set to the middle option. Two settings below it are worth reading together. `ANTHROPIC_EFFORT=low` is not empty, even though the comment above it says to leave it blank so the parameter is not sent, because older models reject it. And `ANTHROPIC_MAX_TOKENS` is commented out at a default of 4096, with a warning that in current models the internal reasoning counts against that same cap. So the shipped default sends a reasoning parameter and leaves the response ceiling at a value the same file warns is shared with that reasoning.

## One of the two provider adapters is only a parenthetical

The generated tree lists `providers/` containing `base.py` described as the common interface, `__init__.py` that picks the provider automatically, and `zernio.py` described as the adapter, or `meta.py`. So the Meta Cloud adapter exists only as a note inside the comment for the other one, and the file that selects between them is told to choose automatically. Meanwhile `.env.example` leaves `WHATSAPP_PROVIDER` with no default value at all, so the choice is made by question ten of the interview rather than by a default. The quick start is three lines:

```bash
git clone https://github.com/Hainrixz/whatsapp-agentkit.git
cd whatsapp-agentkit
bash start.sh
```

followed by launching `claude` and typing `/build-agent`. The page is explicit that `start.sh` only verifies your environment and that the real system starts with the slash command, so the three-line quick start does less than Phase 1 does. The slash command itself lives in the `.claude/` directory, which means the entire product is one command in a dot-directory.

## Conclusion

This is a good fit if you run a small business, do not write code, and want a WhatsApp agent this week on a free tier, and it is honest in a way most scaffolding of this kind is not: it names the retry storm it is avoiding, tells you the webhook signature check can be skipped, and tells you to load it before taking real customers. Two things follow from what the repository is. First, everything you get is generated for you, so review the server the assistant wrote rather than trusting the MIT licence on a repository that contains no server. Second, the signature secret is the only thing between a stranger who knows your URL and your agent, so treat an unset secret as an open door and set it before Phase 5. Keep the generated project in its own repository with a lockfile, since this one has no dependency manifest to copy.

## FAQ

### What does whatsapp-agentkit actually contain in the repository?

Ten top level entries: `.claude/`, `.env.example`, `.gitignore`, `CLAUDE.md`, `LICENSE`, `README.md`, `docs/`, `knowledge/`, `scripts/`, and `start.sh`. There is no agent code, no dependency manifest, and no lockfile. Claude Code writes the server per user.

### What happens if I leave the webhook secret empty?

The agent starts anyway, warns in the logs, and lets every request through without HMAC verification. The page tells you to load `ZERNIO_WEBHOOK_SECRET`, or `META_APP_SECRET`, before putting the agent in front of real customers.

### Should I use Zernio or the Meta Cloud API with whatsapp-agentkit?

The page recommends Zernio for almost everyone: no Facebook app, no App Review, no separate business verification, two connected accounts free without a card, and a shared test number capped at 50 messages per 24 hours. Meta direct is for people who already have a Meta app set up. Conversation fees go to Meta either way.

### Which Claude models does whatsapp-agentkit support?

Three are listed in the example environment file: `claude-opus-5`, `claude-sonnet-5` as the default, and `claude-haiku-4-5`. An `ANTHROPIC_EFFORT` value is sent by default and `ANTHROPIC_MAX_TOKENS` defaults to 4096 when uncommented.

## Sources

- [Hainrixz/whatsapp-agentkit on GitHub](https://github.com/Hainrixz/whatsapp-agentkit)
- [Issues](https://github.com/Hainrixz/whatsapp-agentkit/issues)
- [License: MIT](https://github.com/Hainrixz/whatsapp-agentkit/blob/main/LICENSE)
- [Project website](https://hainrixz.github.io/whatsapp-agentkit/)
- [README](https://github.com/Hainrixz/whatsapp-agentkit/blob/main/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/hainrixz-whatsapp-agentkit
