People Put Claude Code Inside WhatsApp — and Some Are Getting Their Numbers Banned
It showed up in three different accounts this week: put Claude Code in your WhatsApp and command your server from your phone. The idea is real and it works. What the caption leaves out is the price.
What it actually is
Claude Code runs in a terminal, on your server. A bridge connects a WhatsApp account to that terminal: you send a message, Claude Code runs, it replies in the chat. You write code, run commands and see the output — all from inside a WhatsApp conversation.
There are two paths, and the difference between them is everything.
Path 1: unofficial libraries (Baileys, OpenWA)
They're free, they set up in minutes, and they connect to regular WhatsApp — your number, your account. This is the route almost every viral tutorial takes.
The risk: WhatsApp does not permit automation through unofficial libraries, and their anti-abuse systems look for exactly this pattern. The risk of the number being restricted or banned is not zero — and when it happens, you lose the number, not just the bot. The repos themselves warn: use a throwaway number, never your personal or work one; keep messages conversational; don't message anyone who didn't message you first.
Path 2: the official API (Twilio / Meta Business)
It goes through WhatsApp's official infrastructure. No ban risk. In exchange, it needs a Meta Business account, a Twilio number with WhatsApp, and a public webhook — more setup, and it stops being "five minutes."
The bigger catch, true for both paths
You're giving a language model, reachable by message, access to:
- your machine's shell and files,
- your cloud services (if you connect Gmail, Sheets, etc. MCPs),
- your WhatsApp number.
Whoever messages that number — or whoever can write into the place Claude Code reads context from — is talking to your machine. Well-built bridges lock this down: only one authorized number triggers the agent, and destructive commands require explicit confirmation in the chat before they run. If the bridge you pick doesn't do both, don't use it.
The honest version
Commanding Claude Code from your phone is genuinely useful when you're away from the computer. But:
- throwaway number, always;
- official API if the number matters;
- a bridge that requires an authorized number + confirmation on destructive commands;
- and no sensitive code on a machine that answers messages.
It's a powerful tool. It's also a new attack surface, answering in your pocket.
Want the calm version of AI news like this, once a week? Subscribe to the Sharp AI Hub newsletter →