Quick answer: What do WhatsApp usernames and BSUID change for merchants?

WhatsApp usernames let consumers hide their phone number from businesses. Behind the scenes, Meta issues a Business-Scoped User ID (BSUID) per user–business portfolio. If your Shopify, CRM, CTWA attribution, or chatbot still keys only on phone numbers, new username adopters can look like strangers — or fail webhook handlers entirely.
- Usernames are optional for consumers; personal chats stay on phone numbers.
- BSUID is portfolio-scoped — the same human gets different IDs at different businesses.
- Phone numbers may still appear (recent 30-day messaging/calls, contact book, shared contact) — but you must design for BSUID-only inbound.
- Auth templates that require phone (one-tap / zero-tap / copy code) still need numbers.
- Mark360 merchants should treat BSUID as a first-class customer key alongside phone, especially for Shopify and CTWA.
Usernames vs BSUID (business view)

A username is the optional public handle a person chooses (rules commonly cited: 3–35 characters, letters/numbers/periods/underscores, etc.). A BSUID is the stable-ish identifier Meta gives your business for that person so you can recognize and message them without seeing their number.
| Phone number | BSUID | |
|---|---|---|
| Scope | Global for the user | Per business portfolio |
| Cross-business join | Same number everywhere | Different ID per business (privacy by design) |
| Auth one-tap / zero-tap / copy code | Required | Not supported for those auth types |
| Webhook reality in 2026 | May be omitted for username adopters | Present as user_id (and related fields) |
Twilio and Gallabox both stress the same ops truth: if you only store wa_id / phone, username-era inbound breaks CRM matching, bot routing, and ad attribution continuity.
What breaks in Shopify

- Customer matching: Stores that upsert Shopify customers by phone will create orphans when the first WhatsApp touch has BSUID only.
- Order notification deep links: Flows that assume “phone on the WhatsApp session = Shopify customer phone” fail when the shopper never shared a number.
- Abandoned cart / COD verification: Automations that SMS/WA the phone on the checkout record still work for checkout phones — but inbound chats from username users may not merge into that customer without an explicit link step.
- Shared inbox macros: Agent scripts that say “confirm the number on the order” need a BSUID-safe path (“we can continue on WhatsApp without your number” + optional REQUEST_CONTACT_INFO).
Merchant fix pattern: store bsuid (and parent BSUID if you use linked portfolios) on the customer metafield / contact; when phone arrives later (share button, checkout, contact book), merge records; never delete the BSUID key.
What breaks in CRM
- Phone-as-primary-key models create duplicate leads on every username-first conversation.
- Lifecycle bots (“returning VIP”) miss users who change phones (BSUID can change on number change — subscribe to
user_id_updatestyle webhooks and rewrite the key). - Lead routing by country dial code fails when phone is absent — route on language, ad payload, or form fields instead.
- Compliance exports that only list E.164 numbers under-report WhatsApp-known contacts.
Recommended CRM fields: whatsapp_bsuid, whatsapp_username (if provided), whatsapp_phone (nullable), whatsapp_contact_shared_at, last session id / ad click ids.
What breaks in CTWA attribution
- Click-to-WhatsApp ads still open chats, but if your CAPI / CRM join uses phone only, ctwa_clid → person stitching goes dark for username-first users.
- Retargeting lists built solely from phone-based WhatsApp audiences under-count.
- Sales SLAs that page a rep with “+91…” fail when the webhook has username + BSUID only — pass BSUID into the ticket title/body.
Ops pattern: persist ad click identifiers and BSUID on the conversation object immediately; ask for contact share only when fulfillment truly needs a dialable number (delivery, KYC), not as a vanity CRM habit.
API / webhook checklist (migration)

- Parse
user_id(BSUID), optional username, and do not crash whenwa_id/fromis missing. - Subscribe to identity update webhooks (BSUID change on phone change; business username status if you claim one).
- Send API: support recipient BSUID field alongside
tophone; know phone wins when both are present (per public partner docs). - Keep Meta contact book enabled unless you have a hard reason to disable (disabling can wipe stored mappings).
- Add REQUEST_CONTACT_INFO on key utility/marketing templates when you need a number — expect opt-in friction.
- Exclude unsupported auth template types from BSUID-only sends (error patterns such as 131062 are documented by partners when BSUID is used incorrectly).
- Test four scenarios: phone-only, BSUID-only, both present, BSUID rotation after number change.
Timeline merchants should internalize
- BSUID in production webhooks — already rolling in 2026 partner timelines (Gallabox cites late March 2026 production inclusion).
- Contact book — Meta-hosted safety net for post-launch interactions.
- Send-by-BSUID and contact request buttons — mid-2026 partner timelines.
- Consumer usernames GA — later 2026 by region; volume of BSUID-only sessions rises then.
Meta’s public warning (relayed by partners): if you cannot process username adopters, there may be no recourse after the fact. Build now.
Mark360 angle for merchants

Mark360’s job for Shopify and CRM-heavy teams is continuity: conversations, journeys, and agents that still recognize the same human when the phone number is hidden.
- Treat BSUID as a first-class identity in inbox profiles and automations.
- Keep CTWA → agent → drip journeys keyed on conversation + BSUID, with phone as an optional enrichment.
- Use contact-share prompts only at fulfillment or trust moments — not on every greeting.
- Align Shopify customer merge rules so COD / shipping phones and WhatsApp BSUIDs can link without duplicate spam.
- Train agents: never refuse to help a username user solely because CRM search by phone returned empty.
Competitors such as Gallabox and Twilio are publishing migration guides — the merchant differentiator is whether your commerce stack (Shopify carts, COD, CTWA) survives identity change. That is the Mark360 focus.
Soft CTA: review WhatsApp + Shopify setup on mark360.ai/whatsapp-api and related Shopify guides on the Mark360 blog.
Merchant go-live checklist

- Audit webhook logs for missing phone fields this week.
- Add BSUID columns in CRM / Shopify metafields.
- Update chatbot session keys off phone-only maps.
- Patch CTWA conversion upload joins to include BSUID + click ids.
- Pilot REQUEST_CONTACT_INFO on delivery-critical templates only.
- Run a tabletop: “username-only VIP returns after 45 days” — does anyone recognize them?
Related reading
Service message cost hedges · Meta Business Agent vs Mark360 · Shopify WhatsApp posts on mark360.ai/blog.








