Send one-time passwords to your users on WhatsApp with two API calls: one to send the code, one to verify it. Start free with 100 OTPs a month from our WhatsApp number, with no Meta account and no DLT registration.
curl -X POST https://app.waloops.com/api/otp/send.php \
-H "X-API-Key: YOUR_API_KEY" \
-d '{"phone":"919876543210"}'
// 200 OK
{ "success": true, "expires_in": 300 }
In India and many other countries, WhatsApp is the app people already have open. The WhatsApp OTP vs SMS OTP comparison covers it in detail.
Indian SMS needs DLT entity, header and template registration before your first message. WhatsApp OTPs use a template Meta approves, and on our shared number that's already done.
SMS codes get delayed or filtered by operators. WhatsApp messages arrive over the internet in seconds, so fewer users give up waiting for the code.
Codes arrive in a chat from a verified business, with the security warning built into the message, so users know it's really you.
Two endpoints, JSON in and out, authenticated with your API key in the X-API-Key header. Phone numbers include the country code, digits only.
| phone | Required. With country code, e.g. 919876543210 |
| purpose | Optional label for your logs, e.g. login, signup, checkout |
Returns {"success": true, "expires_in": 300}. A 6-digit code is sent on WhatsApp and is valid for 5 minutes.
| phone | Required. The same number you sent the code to |
| code | Required. What the user typed |
Returns {"verified": true}, or {"verified": false, "error": "Incorrect code"}. A code can be used once.
# 1. Send a code
curl -X POST https://app.waloops.com/api/otp/send.php \
-H "X-API-Key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"phone": "919876543210", "purpose": "login"}'
# 2. Verify what the user typed
curl -X POST https://app.waloops.com/api/otp/verify.php \
-H "X-API-Key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"phone": "919876543210", "code": "483920"}'
| Rule | Value | Response when hit |
|---|---|---|
| Code length | 6 digits | – |
| Code lifetime | 5 minutes | "This code has expired" |
| Wrong attempts per code | 5 | "Too many incorrect attempts. Request a new code." |
| Resend to the same number | Once every 30 seconds | HTTP 429 |
| Monthly quota | Depends on plan | HTTP 429 with the plan limit |
| Missing or invalid phone | – | HTTP 400 |
The same API key works for the API and our WordPress plugin. No per-message charges from WALoops on any of these plans.
Sent from the WALoops WhatsApp number. No Meta setup.
Get a free API keyUse our shared number, or connect your own WhatsApp Business number.
Start IntroductionSent from your own connected WhatsApp Business number, with your brand name.
Start StarterOn your own number, Meta bills authentication messages to your WhatsApp Business account at its own rate. See the WhatsApp pricing guide.
Free API key, 100 OTPs a month, no credit card.
✓ No credit card required ✓ 7-day free trial ✓ Cancel anytime