Connections, accounts, QR linking and account lifecycle

Understand the private connector token

This guide explains that that a cryptographically random token is generated and encrypted at rest; administrators do not type or reveal it during normal setup. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.

Audience: CRM administrators and WhatsApp account ownersPermission: AdministratorModule v1.0.0 · 2026.07.30-r20.5
Jump to steps
Where to goAdmin Area → WhatsApp → Connections
Before you start
  • Verify the module is active and select the intended WhatsApp account before changing any operational record.
  • Use an account with the stated native CRM capability and per-account access.
  • Test with controlled customer/contact data before relying on live verification, email or CRM automation.

What you’ll accomplish

Know that a cryptographically random token is generated and encrypted at rest; administrators do not type or reveal it during normal setup. These instructions follow the supplied r20.5 controller, model, view, installer, connector and automation flow.

Follow these steps

  1. Go to Admin Area → WhatsApp → Connections.
  2. Find the account, conversation, setting, session or evidence relevant to “Understand the private connector token”.
  3. Check the displayed value or behaviour against this guide’s code-backed rules.
  4. Do not change unrelated account, CRM or connector settings while verifying the result.
  5. Verify the expected state in the related Inbox, Connections, customer history, native CRM record or Audit Trail.

Fields and options to review

Account namerequired, maximum 191 characters
AvailabilityActive or inactive
Live QRgenerated by the private connector
Delete confirmationexact uppercase DELETE

Rules the system enforces

  • Each account receives a unique account key, encrypted connector token, loopback connector endpoint and isolated session directory.
  • The account creator is granted View, Reply, Convert and Manage for the new account.
  • Account deletion is a soft operational deletion after successful isolated runtime removal; messages, verification evidence, portal history and audit remain.
  • Know that a cryptographically random token is generated and encrypted at rest; administrators do not type or reveal it during normal setup.

How to confirm it worked

  • The requested action completes without a permission, validation, connector or native CRM error.
  • The selected account or conversation shows the expected state without changing another account’s data.
  • Where the action creates evidence, confirm the message, native record, verification event, portal history or audit entry is present.

Security, privacy and troubleshooting checks

  • Never expose connector tokens, loopback ports, authentication directories or raw customer verification replies.
  • Use the supported Connections, Access Control, Settings and Audit Trail pages rather than editing runtime or database records directly.
  • If the expected control is missing, verify both native capability and per-account permission before treating it as an installation fault.