All articles
By the Agent Messenger team 3 min read

WhatsApp MCP server: self-hosted bridge or hosted connector?

Open-source WhatsApp MCP servers and hosted ones solve the same problem differently. Compare control, effort, privacy and safeguards to choose the right one.

There is no shortage of WhatsApp MCP servers. Search for one and the first results are open-source repositories and directories listing several of them. They all promise the same thing, your AI assistant able to read and search your WhatsApp, but they get there in two quite different ways. Choosing between them is mostly a question of who you want to operate the plumbing.

The self-hosted approach

Typically you run a small bridge program on your own computer or a server, link your WhatsApp number to it, and run an MCP server that your assistant talks to. Messages are stored locally, often in a small database file. The appeal is real: your messages stay on hardware you control, there is no third party in the middle, and there is nothing to subscribe to. You can read the code, change it, and run it for free.

What self-hosting costs you

The cost of that is operations. You install and update the bridge. When WhatsApp changes something and the bridge stops syncing, you are the one who notices and fixes it. The connection usually only works while the machine is running. If you want to reach it from more than one device, or from an assistant that connects over the internet rather than locally, you are into tunnels and authentication, which are easy to get wrong, and an exposed MCP server with access to your messages is a serious thing to get wrong.

The hosted approach

You sign up, link your number with a QR code, and connect your assistant to a server address. Someone else runs the bridge, keeps it connected, and handles authentication. You trade some control for effort: your messages live on the provider's systems, so you are trusting them with that, and you pay for the service.

Questions to ask any hosted option

That trust is the thing to evaluate, and there are concrete questions to ask. How does the assistant sign in? Look for a standard OAuth flow with a consent screen, not a long-lived API key you paste around. Can you grant narrow access? Reading and sending should be separate permissions. Can you see what the assistant did? A usable activity log that records what was read, by which client, is the difference between trusting an assistant and being able to check it. What happens to your messages? A provider should state plainly how they are stored, whether they are used to train models, and how you get them deleted.

How Agent Messenger answers them

Agent Messenger is the hosted kind, and these are the points it is designed around. Assistants sign in with OAuth 2.1 and approve access on a consent screen with three separate scopes: read, manage and send. A message to more than one recipient has to be previewed first, with the exact recipient list, before it can go out. Every call is logged, including refused ones. The privacy policy says message content is stored on the service to support search, that it is stored unencrypted, that it is not used to train AI models, and that deletion is available on request. Whether that is the right trade for you depends on your situation, which is why it is written down rather than left vague.

How to choose

If your messages are sensitive enough that they must never leave your own hardware, or you enjoy running your own tooling, a self-hosted server is a good fit, and you should plan for the upkeep and for securing it properly if it is reachable from outside. If you want it to work without maintenance, from any device, with scoped permissions and an audit trail you did not have to build, a hosted connector is the more practical choice.

Habits that apply either way

Connect the account you actually need rather than every account you have. Start with read-only access and add more only when you have a reason. Check the log after the first few uses to see what the assistant read. And keep in mind that WhatsApp's own terms apply to any number you link, whichever route you take.

Put your AI on WhatsApp.

Connect a WhatsApp number, point Claude at it, and watch every read land on an audit trail.

Back to all articles