It's just past 9 p.m. A customer messages a nail salon's Page: "How much is a gel manicure? Any openings tomorrow afternoon?" The person who runs the Page sees it at 8 the next morning and types a reply. The customer reads it and says nothing, because last night they already booked a salon that answered faster.
Plenty of Page owners hit this until they want a bot to help. Then someone offers a shortcut, like letting a program sit inside an account that stays logged in and click through the inbox for you. It works for a while. When the login drops, the bot goes quiet. A bot that lasts has to be built on the channel Meta actually offers, which is the Messenger Platform.
At Productize we're building a Page reply bot service on Meta's Graph API (the channel Meta opens for programs to request data and send messages on Facebook; the Messenger Platform runs on it too). Along the way we ran into things every Page owner should know before hiring someone or doing it themselves, so we wrote them down here. Where a step is developer work, we say so. You just need to know what to ask.
Step 1Borrowed-login shortcuts don't last
The shortcut that has a program reply in a person's place relies on borrowing a cookie, the data your browser keeps to remember who is logged in. It is not a channel Meta offers for automation. Having a program pose as a person to read and reply this way breaks Meta's terms of use, so the Page or account behind it risks being restricted or suspended. It isn't just fragile. And even on the days it isn't caught, when the login drops or Facebook asks to verify identity, the bot goes silent right away, and nobody notices until customers complain that they messaged and got no answer.
We ran into this ourselves at the start. Our first try had a browser on a server in a data center log in to Meta Business Suite, the web page admins use to answer Page chats, so it could read the inbox. It never got past the login: Facebook saw a new device and asked to verify identity, and there was nobody at that machine to do it. The other option is borrowing a cookie from a computer that's already logged in, but that only postpones the same problem. The next time Facebook asks to verify, the bot is stuck again. A fresh login doesn't get through, and a borrowed one doesn't last. Neither is something to build on.
So we switched to the Graph API, the path Meta provides for Page messages directly, using a Page access token instead of a login. The result: we could read all of the Page's conversations, without depending on a web page and without wondering whether the login would still be there tomorrow.
Step 2What to prepare before you have a bot
Before you have a single bot, you need these 4 things in place. The technical names in parentheses are for your developer to pick. You don't need to remember them.
- A Meta App with Messenger added. This is the bot's "identity" in Meta's eyes. Create it at developers.facebook.com and link your Page to the app.
- A Page access token that already has permission to read and reply to your Page's chats, issued by someone who can manage the Page's messages, such as a Page admin. (The permissions your developer picks are
pages_messaging, to reply to chats, andpages_manage_metadata, so Meta can notify the bot when someone writes.) - A server, a computer that stays on to receive messages. It has to be a secure site with the padlock (HTTPS) and a real certificate. Meta doesn't accept self-signed certificates.
- Someone responsible for the token, because tokens can expire. If nobody is watching, the bot stops quietly.
So who does what? Creating the app and issuing the token happen in Meta's developer website. If that isn't your thing, the developer or provider you hire can do it. But when the token is issued, someone who manages the Page has to click to allow it, because the token must come from an account with a role on the Page. If you're the Page admin, that someone is you. The server is purely developer work. You don't set it up; you just need to know what to ask, which is in the next step. The item that should truly be yours is number 4, the person who looks after the token.
That last item sounds small, but it bit us. The token for the Page chat-reading system Productize built for its own use expired on July 5, 2026, and the system stopped reading until a new token was issued. In Meta's docs this shows up as error code 190 (access token expired), and the fix is to generate a new token. Plan from day one who will renew it, and who will notice when it runs out. When you issue the token, write down when it expires.
With all 4 in place, the bot can still only talk to your own team. Real customers have to wait for Step 5.
Step 3The doorbell Meta rings when a customer writes
A developer does this step, but the Page owner should understand the picture so they can ask whether it's done properly. What tells the bot a customer has written is the webhook. Think of a shop doorbell. Instead of the bot walking over to check the inbox every 5 minutes, Meta rings the bell the moment the customer types. That lets the bot answer in seconds instead of waiting for the next round.
Same example: the customer types "How much is a gel manicure?" at 9 p.m. Here is what happens, in order.
- Meta sends that message to your webhook, along with an ID for this customer that works only with your Page (Meta calls it a PSID). The bot uses it to reply to the right person.
- The server checks the "signature" Meta attaches to every message (
X-Hub-Signature-256) to confirm it really came from Meta. Always do this step. Without it, anyone who knows your webhook address can send in fake messages. - The server tells Meta "received" (
200 OK) within 5 seconds. Otherwise Meta treats the message as undelivered. - The bot works out a reply and sends it back to the customer through the Send API, using the same customer ID.
One point is easy to miss. If the server doesn't confirm receipt, Meta resends right away, then keeps retrying at growing intervals for up to 36 hours. That's why Meta's docs tell the receiving side to filter out duplicates itself. Otherwise a customer who asks once may get the same answer two or three times.
If your developer can say they've done these 3 things (checking the signature, acknowledging within 5 seconds, and filtering duplicates), the bot will know right away that someone wrote, know who it is, and reply to the right person.
Step 4What is the 24-hour window rule?
After a customer messages your Page, the Page can reply freely for 24 hours. After that, what remains is the human agent tag, which lets your staff type replies themselves within 7 days of the customer's last message, and nothing promotional. This rule decides what your bot can say, and when.
The details worth knowing, from Meta's Send API docs:
- The window starts when the customer sends your Page a message or taps a button in the chat, such as "Get Started".
- It's usually 24 hours, but if the customer came from a click-to-Messenger ad, the window can last up to 7 days. That's separate from the human agent tag's 7 days below.
- Inside the window you can answer questions or send promotions.
- Outside the window you need a message tag, a label attached to the message that tells Meta why it's being sent, and the message can't be a deal, offer, coupon or discount. Using a tag for the wrong case can get your Page's messaging restricted.
- The tags once used for appointment, account and post-purchase updates were retired on April 27, 2026. The one that remains is the human agent tag, which lets your staff reply to a customer themselves within 7 days of the customer's last message, typing it in the Page inbox or whatever chat tool your shop uses. That's work for people, not the bot.
- Promotions can't go out with a tag at all. If you really want to send outside the window, Meta points to two other channels. Sponsored messages are paid ads that show up in the chat. One-time notifications need the customer to tap to agree to receive a follow-up first. Both have their own conditions and Meta review. Most small Pages don't need either: if you can send the promotion while the customer is still chatting, it stays inside the window.
So how much can you send outside the window? In short, assume the bot can't send on its own. Your staff can reply themselves with the human agent tag, and promotions have to go through paid ads or a customer opt-in. The right question isn't "how many messages can we send" but "what are we sending, and who is sending it".
This rule has already changed under us. The bot design draft the Productize team wrote before building once planned to use tags to send appointment reminders outside the window. While fact-checking this post, we found Meta stopped accepting that set of tags on April 27, 2026. Built from the old draft, the reminders would never have gone out at all.
That gave us a principle: design so the important things finish inside the window. Back at the nail salon, while the customer is still chatting, have the bot confirm the date, time, price and anything they need to bring in that one conversation. Don't save it to send later.
Step 5Why does the bot answer my team but not customers?
Because the app hasn't passed App Review yet. First you need to know that Meta gives apps 2 access levels. Standard Access receives messages only from people the app owner has added to the app as an admin, developer or tester. Advanced Access receives messages from the general public, and it requires passing App Review first.
Here's how it looks. The Page owner messages the bot and it answers beautifully. A teammate tries it and it answers well. Then you open it to real customers, they write in, and nothing happens. Customers have no role on the app, so their messages never reach the bot at all. The bot isn't broken.
Meta's webhook docs list 2 requirements that go together. First, the app has to be in Live mode, switched on for real use rather than development mode. Second, it needs Advanced Access to pages_messaging, which comes from passing App Review. Miss either one and the general public still can't reach the bot. Meta gates it this way because a bot can message huge numbers of people in an instant, and without a check first it easily becomes a spam cannon. What App Review asks you to submit and how long it takes isn't covered in the docs we checked. Open the App Review page on Meta's developer site when you're ready to apply, and leave room for it in your plan. Agree clearly with your developer on who clicks submit. The story of your business and why you're using a bot has to come from you. No amount of extra code speeds this step up.
While you wait, have the teammates listed as testers message the bot in every way you can think of: asking prices, booking slots, asking for things you don't sell. When the day comes that you pass, the bot is ready to talk to customers immediately.
Step 6Where AI fits in the bot
Everything so far is the messaging system. There's no AI in it yet. AI sits in the middle, between the incoming message and the reply going out. Its job is to read the conversation, understand what the customer wants, and draft the answer.
The decision you have to make is how much the AI sends on its own. There are 2 main ways.
- AI drafts, a person sends. Safest, and a good fit at the start. Whoever runs the Page sees the draft, then edits it or clicks send. Much faster than typing, but someone still has to be there.
- AI replies on its own only for clear-cut topics, like greetings, opening hours and standard prices. Anything it's unsure about, anything about money, and complaints get handed to a person, and the bot tells the customer plainly that it's handing them over.
Back to our 9 p.m. customer. The second way answers the gel manicure price right away, then says an admin will confirm tomorrow's slot in the morning. The customer gets half the answer instantly and knows when the other half is coming, which beats a whole night of silence.
If you hire a provider, ask whether you can tune the bot's tone, or switch the AI model, without rebuilding the whole messaging system. A nail salon and a dental clinic need different tones and different limits. In what we build, the AI layer is separate from the messaging system, and what's inside it is tuned per Page.
One more thing not to skip: tell customers they're talking to a bot. Don't let them think it's a person. The trust you lose when they find out later costs far more than the time you saved.
Step 7Customer data and PDPA
If you run a bot as a service in Thailand, the messages customers type are personal data: names, phone numbers, appointment dates, and for some businesses even health information. That puts them under Thailand's Personal Data Protection Act B.E. 2562 (2019), the PDPA. These are the 4 principles we hold to when designing.
- Keep only what you use. Store just what the bot needs to remember to answer correctly.
- Say what you keep it for and how long you keep it, then actually delete it as promised.
- Say where messages are processed. If you send messages to an outside AI provider, write that into your privacy policy.
- Limit who has access. Only the people who need the token and the conversation logs should be able to reach them.
Get one thing clear first: the Page owner is the data controller under the law, the one responsible for customer data, even if someone else builds the bot. Two things you can do from day one: tell customers in the first message that they're talking to a bot, and give them a way to ask for their data to be deleted, then actually delete it when they ask.
All of this is design guidance, not legal advice. Before you go live, check the guidelines from Thailand's Personal Data Protection Committee (PDPC) and talk to a PDPA advisor, especially if you handle sensitive data like health information. Questions worth getting clear answers on: which legal basis you rely on to keep customer messages (the reason the law lets you keep them), whether you need consent, and what extra steps apply if your AI provider is overseas.
Step 8Where to start
If you want to start today, go in this order.
Before you open the bot, read Meta's docs one more time, because the rules can change without anyone telling you. Our own design draft went out of date without us noticing. As for where to begin, the first item on the checklist needs no developer: write down the questions customers ask most, for a month. When the bot is ready, those are what it can answer right away for the customer who writes at 9 p.m.
- Standard messaging window of 24 hours / 7 days, messaging type, message tags deprecated since April 27, 2026, the 7-day human agent tag, PSID, and error code 190: Meta · Send Messages
- Webhooks, the X-Hub-Signature-256 signature, 200 OK within 5 seconds, HTTPS without self-signed certificates, Standard/Advanced Access and App Review, the pages_messaging and pages_manage_metadata permissions: Meta · Messenger Platform Webhooks
- Retries for up to 36 hours and duplicate filtering: Meta · Graph API Webhooks: Getting Started
- List of message tags: Meta · Message Tags
- Send API request format: Meta · Send API Reference
- Meta's platform terms and developer policies (borrowing a login or posing as a human replier is not allowed; a Page or account can be restricted or suspended), plus Standard/Advanced access levels and App Review: Meta · Platform Terms, Developer Policies, Access Levels
- Thailand's Personal Data Protection Act B.E. 2562 (2019) and guidelines: Personal Data Protection Committee (pdpc.or.th)
- The Business Suite login that failed from a server, reading Page conversations through the Graph API, and the token that expired on July 5, 2026 come from Productize's own work (Jul to Oct 2026) · All links checked to open on Oct 10, 2026.
Read next: AI data privacy: a three-layer defense for using AI without leaking secrets
Also see: Bring Your AI into Discord, Without Handing Over the Keys · See all posts