Meta Flows End-to-End Encryption

Meta WhatsApp Flows encrypt all form payloads using AES-GCM combined with an RSA-2048 keypair.


Key Generation

Generate an RSA-2048 private key:

openssl genrsa -out private_key.pem 2048
openssl rsa -in private_key.pem -outform DER | openssl base64 -A > private_key_base64.txt

Upload the corresponding public certificate to Meta Business Manager under Flow Settings.


Configuring SMSPort Decryption

  1. Open Workspace Settings > Modular Integrations > Meta Cloud API.
  2. Paste the contents of private_key_base64.txt into the Flows Private Key field.
  3. When form submissions arrive, SMSPort's background worker decrypts the JSON payload in real time before triggering any visual bot cards.