Meta Flows End-to-End Encryption
Meta WhatsApp Flows encrypt all form payloads using AES-GCM combined with an RSA-2048 keypair.
Key Generation
Generate an RSA-2048 private key:
openssl genrsa -out private_key.pem 2048
openssl rsa -in private_key.pem -outform DER | openssl base64 -A > private_key_base64.txtUpload the corresponding public certificate to Meta Business Manager under Flow Settings.
Configuring SMSPort Decryption
- Open Workspace Settings > Modular Integrations > Meta Cloud API.
- Paste the contents of
private_key_base64.txtinto the Flows Private Key field. - When form submissions arrive, SMSPort's background worker decrypts the JSON payload in real time before triggering any visual bot cards.