WhatsApp Us

WhatsApp OTP API · login and verification codes

WhatsApp OTP API: send login codes on WhatsApp, keep SMS as a fallback

A WhatsApp OTP API lets your app or website deliver one-time login and verification codes inside WhatsApp, using Meta’s authentication templates, instead of relying only on DLT-registered SMS. BtechWaleTech is three freelance developers in India who wire this into Android apps, iOS apps and web sign-up flows: template approval, copy-code and one-tap buttons, SMS fallback, rate limits and fraud checks. Integration starts at ₹40,000, and you keep the WhatsApp Business Account in your own name. See how it fits your wider WhatsApp Business API setup.

  • Integration from₹40,000 · US$600
  • Typical build2–4 weeks including template approval
  • Message typeMeta authentication template
  • Code expiry setting1 to 90 minutes, per Meta’s docs
  • Backup channelDLT SMS, triggered automatically
  • Account ownerYou: WABA, number and templates
  • Authentication templates
  • Copy-code button
  • One-tap autofill on Android
  • SMS fallback
  • Rate limiting
  • Your own WABA
  • Flutter, React Native, web

Three freelance developers in India · replies on WhatsApp, 7 days a week

  • 3Freelance developers who build and test the flow
  • 2Working days to an itemised quote
  • 2Months of free maintenance after launch
  • 0Platform fees added by us on your Meta bill

The short answer

Should you send OTPs through a WhatsApp OTP API instead of SMS?

Use a WhatsApp OTP API when most of your users already have WhatsApp and you want codes that arrive with a copy or one-tap autofill button. Keep DLT SMS as an automatic fallback for numbers without WhatsApp or failed deliveries. BtechWaleTech builds the full flow, templates, fallback and rate limits, from ₹40,000, typically in 2–4 weeks.

Meta bills each delivered authentication message; compare that with your SMS rates on our WhatsApp Business API cost guide, and see app vs API if you are still on the free Business app.

Last updated

WhatsApp OTP API project at a glance
What you getOTP sent on WhatsApp, verified on your server, SMS as backup
Starting priceFrom ₹40,000 (US$600)
Timeline2–4 weeks, most of it testing and approval
Buttons supportedCopy code everywhere; one-tap and zero-tap on Android
Where it plugs inSignup, login, password reset, payout or address change
Security layerHashed codes, attempt caps, per-number and per-IP throttles
After launch2 months free support, then from ₹8,000/mo

Why choose us

SMS OTP gateway, ready-made OTP service or a custom WhatsApp OTP API build

Three common ways Indian product teams handle verification codes. The right one depends on your user base, volumes and how much control you want over the flow.

SMS OTP gateway, ready-made OTP service or a custom WhatsApp OTP API build
Aspect DLT SMS gateway only Hosted OTP service (SaaS) BtechWaleTech custom integration
Channel SMS only WhatsApp plus SMS, set by the vendor WhatsApp first, SMS fallback, rules you decide
Regulatory paperwork DLT entity, header and template registration Vendor may help, DLT still needed for SMS Meta template on your WABA, DLT reused for SMS
Autofill experience Android SMS Retriever if implemented Depends on the vendor SDK Copy code everywhere, one-tap or zero-tap on Android
Who holds the WhatsApp account Not applicable Often the vendor’s shared setup Your own WABA and number, in your name
Pricing basis Per SMS from your operator or aggregator Vendor markup on top of channel charges Meta billed to you directly; build from ₹40,000
Fraud controls Whatever you code yourself Vendor-level, not tuned to your app Throttles and checks written for your traffic
Code verification Your server Vendor server, you call their API Your server; codes never leave your stack in plain text
Switching later Easy Needs code changes and new templates Portable: the module talks to Meta directly
Best for Tiny volumes, SMS-heavy audiences Teams with no backend time at all Apps with growing logins and a developer to maintain it

If your users mostly sign in from basic feature phones or your volume is a few codes a day, a plain DLT SMS route is simpler and a WhatsApp OTP API adds little.

Pricing

What a WhatsApp OTP API integration costs to build

The build is quoted separately from Meta’s message charges, which Meta bills to your own WhatsApp Business Account. Adding a WhatsApp OTP API to an app or website that already has a working backend usually falls under our AI automation and integration work, starting at ₹40,000. The quote rises when we also need to build the login screens, add Android one-tap autofill with signing-key setup, write the SMS fallback from scratch, or add fraud dashboards. If the app itself does not exist yet, the app plan starting at ₹40,000 covers login as part of the build. You see every line item before any work begins.

Starting prices in INR and USD
ServiceIndia (INR)Worldwide (USD)Typical timelineWhat is included
Static website from ₹10,000 from US$150 1 to 2 weeks Up to 100 pages, Responsive design, Contact form and enquiry setup, Basic SEO tags and sitemap
SEO website (299+ pages) from ₹20,000 from US$300 3 to 5 weeks 299+ SEO pages, Keyword and page planning, Schema, sitemap, and internal linking, Design to deployment included
Ecommerce store from ₹50,000 from US$750 4 to 8 weeks Product and category pages, Payment gateway setup, Order and inventory basics, Performance tuning
Android & iOS app from ₹40,000 from US$600 6 to 10 weeks Android and iOS app (Flutter or React Native), Login, forms and push notifications, Admin panel and API connection, Google Play and App Store publishing
Custom web app or software from ₹60,000 from US$900 6 to 12 weeks Custom features and APIs, User accounts and roles, Admin panel, Deployment and handover
AI automation from ₹40,000 from US$600 2 to 4 weeks Workflow mapping, Tool and CRM integrations, AI agent or automation build, Testing and handover
Monthly SEO from ₹10,000/mo from US$150/mo Ongoing, monthly Technical fixes, On-page and content work, Local SEO and listings, Search Console reporting
Maintenance and support from ₹8,000/mo from US$120/mo Ongoing, monthly Content updates, Bug fixes, Backups and security checks, Speed and uptime checks

All prices are starting points, quoted in INR for India and USD for international clients, not fixed quotes. Final cost depends on the number of pages, features, integrations, content, and timelines. Share your requirement and you get an itemised estimate with nothing hidden. See full pricing.

What is a WhatsApp OTP API and how does it work?

A WhatsApp OTP API is a server-to-server call that asks Meta to deliver a one-time passcode to a user’s WhatsApp number, using a special message format called an authentication template. Your server creates the code, Meta delivers it, and your server checks what the user types back.

The moving parts are few. You need a WhatsApp Business Account (WABA) under a Meta business portfolio, a phone number registered on the WhatsApp Business Platform, an approved authentication template, and an access token your backend uses to call the Cloud API messages endpoint. When a user taps “Send code”, your backend generates a random number, stores a hashed copy with an expiry time, and sends the plain code as the template parameter. WhatsApp shows it in a chat from your business name with a button underneath.

Verification never happens at Meta’s end. The user either types the code, taps a copy button and pastes it, or, on Android, lets WhatsApp hand it straight to your app. Your server compares it with the stored hash, checks the expiry and the attempt count, and only then marks the number as verified or opens a session.

That split matters for security and for switching. Because generation and checking stay on your side, the WhatsApp OTP API is just one delivery pipe. SMS, email or a voice call can sit behind it as alternative pipes without changing how codes are checked.

  • Your server: creates, hashes, stores and verifies the code
  • Meta’s Cloud API: delivers the authentication template to WhatsApp
  • WhatsApp app: shows the code with a copy or autofill button
  • Your app or site: collects the code and posts it back for checking

Is WhatsApp OTP better than SMS OTP for Indian users?

For most consumer apps in India, WhatsApp OTP gives a smoother login, but it is not a full replacement for SMS. The right answer is usually WhatsApp first with SMS behind it.

WhatsApp wins on presentation and recovery. The code arrives in a chat that shows your verified business name, the copy button removes typing errors, and on Android a one-tap flow can fill the code without the user leaving your app. Users who switch SIMs but keep WhatsApp on the same number still get codes, and messages sent while the phone is offline arrive once data returns.

SMS still wins on reach. It works on phones with no data connection, on feature phones and for people who never installed WhatsApp. It is also what many banks and payment flows expect by habit. If your audience includes older users in areas with patchy data, removing SMS completely will lock some of them out.

Choose WhatsApp-first when

your users are smartphone owners, most signups come from Android, codes are requested often (login, not just signup), and you already use WhatsApp for order or booking updates.

Stay SMS-first when

your users skew towards feature phones or low data, the flow is tied to a regulated payment step where your provider requires SMS, or volumes are too small to justify another integration.

Offer a choice when

you serve both groups. A small “Get code on SMS instead” link after 30 seconds keeps everyone moving without doubling your costs.

WhatsApp OTP API authentication template rules you must follow

Every code sent through a WhatsApp OTP API must use a template in Meta’s authentication category, and that category has fixed wording. You cannot write your own sentence around the code the way you can with utility or marketing templates.

According to Meta’s authentication template documentation, the body text is preset as “{{1}} is your verification code”, where {{1}} is the code you pass in. Two optional extras can be switched on: a security disclaimer (“For your security, do not share this code.”) and an expiry line that states the number of minutes. Meta’s docs set the expiry field between a minimum of 1 and a maximum of 90 minutes. We recommend switching both extras on; they cost nothing and they reduce the chance of a user reading the code aloud to a scammer.

The button is the part you choose: copy code, one-tap autofill or zero-tap. The template is submitted with the language you need, so a Hindi and an English version are two separate template entries under the same name.

Keep the template for codes only. Do not try to slip a promotion into the authentication category; the fixed format leaves no room for it anyway, and misusing categories is a quick way to get templates rejected or your quality rating lowered. If you want to send a welcome message after signup, that belongs in a separate utility or marketing template.

  • Fixed body text with the code as the only variable
  • Optional “do not share” security line (switch it on)
  • Optional expiry line, 1–90 minutes, matching your server’s expiry
  • One OTP button: copy code, one-tap or zero-tap
  • One template per language you support

Copy code, one-tap autofill or zero-tap: which WhatsApp OTP button fits?

Start with copy code because it works on every phone; add one-tap for your Android app once the basics run; consider zero-tap only when you have a strong reason and have read Meta’s terms for it.

Copy code shows a button that copies the code to the clipboard. The user switches back to your app or browser and pastes it. It is the only option for websites and the safe default for iPhone users. Meta’s documentation also notes that on iOS 26 and later, keyboard suggestions can offer the code from the WhatsApp notification, which removes most of the switching for iPhone users without extra work on your side.

One-tap autofill is an Android feature. The template carries your app’s package name and signing-certificate hash, and when the user taps the button WhatsApp opens your app and passes the code in. Your Android developer adds the receiving code in the app. If the app is not installed, or the hash does not match a debug or release build, the button falls back to copy code, so test with the exact signing key used for the Play Store release.

Zero-tap is also Android-only. WhatsApp broadcasts the code to your app in the background, so the user never taps anything. It is the fastest experience, but it hides the code from the user’s view, so it suits flows where you already trust the device context. Our table below compares all three.

How much does a WhatsApp OTP cost compared with DLT SMS?

A WhatsApp OTP is billed by Meta per delivered authentication message, while an SMS OTP is billed by your SMS provider per message sent. Which is cheaper depends on your current SMS contract and your monthly volume, so compare real rate cards rather than rules of thumb.

Meta’s pricing documentation states that from 1 July 2025 it charges per message, and only when a template message is delivered. Authentication is one of the four categories alongside marketing, utility and service. Meta also offers volume tiers: send more utility and authentication messages in a month and the per-message rate for that market drops, with tiers counted across all WhatsApp Business Accounts in a portfolio.

Two details matter for Indian teams. First, Meta’s pricing page lists India among markets with a higher authentication-international rate, but its own explanation says that rate applies only to eligible businesses based in a different country from the user; an India-based business sending codes to +91 numbers pays the domestic authentication rate. Second, Meta introduced INR billing for eligible India-based customers from January 2026, which makes reconciling your Meta invoice with GST accounts easier.

Remember the hidden costs on both sides: SMS needs DLT registration and fees charged by your aggregator, while WhatsApp needs a verified business portfolio and someone to watch template status. Our WhatsApp Business API cost page walks through Meta’s rate card in more detail.

  • Pull last quarter’s SMS invoices and count OTP messages per month
  • Estimate what share of those users have WhatsApp (most apps can check delivery on a pilot)
  • Apply Meta’s current India authentication rate and your likely volume tier
  • Add fallback SMS for the users WhatsApp cannot reach
  • Compare the total, not the headline per-message price

Do you still need DLT registration if OTPs move to WhatsApp?

Yes, as long as SMS stays in your flow as a fallback, which it should. DLT rules apply to SMS, not to WhatsApp messages, but a fallback route is still commercial SMS.

Under TRAI’s Telecom Commercial Communications Customer Preference Regulations, 2018 (TCCCPR), commercial SMS in India can only be sent using registered headers assigned to the principal entity, and the content template has to be registered with the access provider, which scrubs outgoing messages against it. TRAI defines a header as an alphanumeric string of up to eleven characters. In short: your sender ID and your OTP text both need to be on DLT, as most Indian businesses already have them.

When we add a WhatsApp OTP API to an existing product, we reuse your current DLT header and OTP template for the fallback rather than registering new ones. The code value, expiry and wording on SMS should match what WhatsApp shows, so a user who receives both never sees two different codes.

One practical tip: if your registered SMS template says “valid for 10 minutes”, set the same expiry in the WhatsApp authentication template and in your server. Mismatched expiry messages are a common cause of support tickets after a switch.

How should SMS fallback work in a WhatsApp OTP API flow?

Send on WhatsApp first, wait a short, fixed time for a delivery signal, and send the same code by SMS if the signal does not arrive or Meta returns an error. Let the user trigger SMS manually as well.

WhatsApp tells your server what happened through webhook status updates: sent, delivered, read or failed. A failed status with an error such as “number not on WhatsApp” means you should switch to SMS immediately. No status at all after 20–30 seconds usually means the phone is offline or the number is not reachable; that is the moment to fall back, not after the code has nearly expired.

Use one code for both channels. Generating a fresh code for SMS invalidates the WhatsApp one and confuses users who then receive both. Record which channel delivered and which one the user actually used; after a month you will know your real WhatsApp reach instead of guessing.

  • Step 1: user requests a code; server stores a hashed code with expiry
  • Step 2: send the authentication template through the WhatsApp OTP API
  • Step 3: watch for a delivered webhook for up to 20–30 seconds
  • Step 4: on failure or silence, send the same code by DLT SMS
  • Step 5: after 30–45 seconds show “Send by SMS instead” and “Call me” links
  • Step 6: log channel, delivery time and success for reporting

How a WhatsApp OTP API integration is built, step by step

The integration is mostly backend work: one endpoint to request a code, one to verify it, and a webhook listener for delivery status. The app or website only needs an input screen and two API calls.

We start by setting up the WABA, phone number and template in your Meta business portfolio, then create a system user token with only the permissions the OTP service needs. On the server we write a small OTP module. It generates a six-digit code from a cryptographically secure random source, stores a hash (never the plain code) with the phone number, expiry and attempt counter, and calls the Cloud API messages endpoint with the template name, language code and the code as both the body parameter and the button parameter.

The verify endpoint compares the submitted code with the stored hash in constant time, checks expiry, increments the attempt counter and deletes the record on success. Delivery webhooks land on a separate endpoint that validates Meta’s signature header before trusting anything in the payload.

On the client we build or adjust the OTP screen: a single numeric field with autocomplete hints for one-time codes, a resend timer, a channel switch link and clear error messages. For Android one-tap we add the receiving activity and test with the Play Store signing key. For a React Native or Flutter app this sits in a small native module.

Rate limiting and fraud protection for a WhatsApp OTP API

Every OTP endpoint is a target, because each request costs you money and bots can request codes in bulk. Put limits in place before launch, not after the first unusual bill.

The common abuse pattern is simple: a script hits your “send code” endpoint with thousands of numbers, some of them premium or foreign ranges, and you pay for every delivery. WhatsApp reduces some of the premium-number risk that SMS carries, but you still pay per delivered message and your messaging limit can be eaten up by junk requests. The defence is layered and cheap to build.

We also watch the verify side. Without an attempt cap, a six-digit code can be guessed by brute force; with a cap of five attempts per code and a short expiry the odds become negligible. After repeated failures we lock the number for a period and flag the account for review.

  • Per-number cap: for example three code requests per ten minutes
  • Per-IP and per-device caps, stricter for new devices
  • Country allow-list: only the calling codes you actually serve
  • Invisible bot check or proof-of-work on the request form
  • Attempt cap per code and a lock after repeated failures
  • Alerting when hourly requests jump well above the normal pattern
  • Never reveal whether a number is registered in error messages

WhatsApp OTP API throughput and messaging limits

Meta limits how fast and how widely a business can send, and OTP traffic counts towards those limits. Plan for them before a launch day spike.

Meta’s Cloud API documentation says a business phone number can send up to 80 messages per second by default, with higher throughput available on request. It also sets a pair rate limit: one message every six seconds to the same user, with short bursts allowed that then reduce what you can send next. That pair limit is why your resend button needs a timer; a user hammering “resend” will simply hit the limit.

Separately, messaging limits cap how many unique users you can reach outside a customer service window within a moving 24-hour period. Meta’s docs say a newly created business portfolio starts at 250, and the limit can rise through 2,000, 10,000 and 100,000 to unlimited. Meta applies that limit at portfolio level, shared by every number in it, so a marketing number and an OTP number compete for the same allowance.

For a new app expecting thousands of signups in week one, this is the single biggest launch risk. Start sending real OTPs a few weeks before launch, complete business verification early and keep marketing broadcasts away from the portfolio until your limit has grown.

Meta Cloud API directly or through a provider: choosing your WhatsApp OTP API route

Go direct to Meta’s Cloud API if you have a backend team that can maintain a small module; use a Business Solution Provider (BSP) if you want a dashboard, support desk and bundled SMS fallback and do not mind a platform fee.

Direct access means the only bill for messages comes from Meta, you control tokens and templates, and there is no extra hop between your server and WhatsApp. The trade-off is that you own error handling, webhooks, template monitoring and upgrades when Meta changes API versions.

A BSP wraps the same Cloud API with its own interface. Some add useful features such as automatic SMS failover or analytics. Check three things before you sign: that the WABA is created in your business portfolio (so you can leave), what they add per message or per month, and whether their OTP API passes the code through their logs.

We build either way. For many Indian startups a direct integration with a thin fallback to an SMS aggregator is the leanest setup, and that is what our WhatsApp Business API integration service covers in general.

Tech stack choices for a WhatsApp OTP API integration

Any backend that can make HTTPS calls can send WhatsApp OTPs, so we build in the stack you already run rather than adding a new service for the sake of it.

Typical combinations we work with: Node.js with Express or NestJS, Python with Django or FastAPI, PHP with Laravel, and serverless functions on AWS Lambda or Google Cloud. Codes and counters sit well in Redis because of its built-in expiry; if you do not run Redis, a database table with an expiry column and a clean-up job is fine for moderate volumes.

If your app uses Firebase Authentication, phone sign-in there uses SMS; a WhatsApp OTP can still be used by verifying on your own backend and then minting a custom token for Firebase. For web apps built on Next.js the OTP routes live in the same API layer as the rest of your auth.

Secrets

Keep the Meta access token and app secret in environment variables or a secrets manager, never in the mobile app. Rotate the token if a developer leaves.

Logging

Log request IDs, phone number hashes, channel and status. Do not log plain OTP values anywhere, including error trackers.

Version pinning

Pin the Graph API version in your calls and schedule an upgrade review when Meta announces deprecations.

How long does WhatsApp OTP API integration take?

Plan for two to four weeks from kickoff to production, and expect the calendar, not the code, to set the pace. Meta business verification and template review can take longer than the development itself if documents are not ready.

Week one usually covers WABA and number setup, template submission and the backend OTP module against a test number. Week two brings the client screens, webhooks and SMS fallback. Week three is testing: real Android and iPhone devices, low-network conditions, release signing keys for one-tap, and abuse tests on the request endpoint. A fourth week appears when we are also building login screens from scratch or when verification is delayed.

You can shorten the path by preparing your GST certificate or other business documents, a website that matches your business name, and access to your Meta business portfolio before we start. See the timeline table below for the phase-by-phase view.

Who owns the WhatsApp Business Account, number and OTP code?

You should own all of it: the Meta business portfolio, the WABA, the phone number, the templates, the access tokens and the source code of the OTP module. We work inside your accounts with permissions you grant and can revoke.

This matters more for OTPs than for most integrations, because login is the front door of your product. If a vendor controls the WABA and a dispute happens, your users cannot sign in. When the business portfolio and WABA are in your name, switching developers or providers is a token change, not a migration.

At handover you get the repository, a short runbook (how to rotate tokens, how to add a template language, what each alert means) and a walkthrough call in English or Hindi. The first two months of maintenance after launch are free; after that, support starts at ₹8,000/mo if you want us to stay on.

Worked example: a hypothetical test-prep app moving OTPs to WhatsApp

Say a test-prep app in Jaipur has an Android app, an iPhone app and a web dashboard, and students log in with phone OTPs several times a week. SMS delivery is fine most days but slow during exam-result peaks, and many students mistype codes on small screens. This scenario is hypothetical and meant to show the decisions, not a real client result.

We would keep their DLT SMS route untouched and add a WhatsApp OTP API in front of it. The Android app gets one-tap autofill with the Play Store signing key; iPhone and web users get the copy-code button. The server sends WhatsApp first, falls back to SMS after 25 seconds without a delivered status, and shows a “Send by SMS” link after 40 seconds.

Rate limits go in on day one: three requests per number per ten minutes, stricter caps for new devices, India-only calling codes, and an hourly alert. The template is submitted in English and Hindi with the security line and a 10-minute expiry that matches the SMS text.

After a month the app’s own logs, not our promises, show what share of logins completed on WhatsApp, how long delivery took on each channel and how much SMS spend moved. That data decides whether to keep WhatsApp-first for everyone or only for Android.

WhatsApp OTP API integration across India

We work remotely with product teams in every state, and login needs look similar everywhere: fast codes on budget Android phones, a backup for weak networks, and costs that stay predictable as signups grow.

Fintech and lending apps in Mumbai and SaaS products in Bengaluru tend to want strict fraud controls first. Ecommerce and D2C brands in Delhi, Surat and Jaipur care most about checkout logins that do not break during sales. Edtech and coaching platforms in Hyderabad, Pune and Kochi often need Hindi, Telugu, Marathi or Malayalam template versions. Clinics and diagnostic apps in Lucknow and Indore use OTPs for report access, where SMS fallback matters for older patients.

Wherever you are, the process is the same: a WhatsApp conversation with the developers, an itemised quote in about two working days, and development inside your own Meta and cloud accounts.

WhatsApp OTP API go-live checklist

Run through this list before you switch real users to WhatsApp codes. Each item has caused a failed launch somewhere, and each takes minutes to check.

  • Business portfolio verified and display name approved
  • Authentication template approved in every language you serve
  • Template expiry, server expiry and SMS text all state the same minutes
  • One-tap tested with the release signing key, not only debug builds
  • Webhook endpoint validates Meta’s signature and handles retries
  • SMS fallback fires on failure and on silence, with the same code
  • Per-number, per-IP and per-device limits active and tested with a script
  • Plain OTPs absent from logs, analytics and crash reports
  • Alerts set for request spikes, template status changes and token expiry
  • Messaging limit known, and marketing sends kept off the portfolio during launch

If you want these checks done as a fixed step in your release process, we can add them to your CI pipeline as part of ongoing maintenance.

Buttons

WhatsApp OTP button types compared

Summarised from Meta’s authentication template documentation. Always check the current docs before release, because Meta updates these flows.

WhatsApp OTP button types compared
ButtonWorks onUser effortExtra workUse it for
Copy code Android, iPhone, web loginsTap, switch app, pasteNone beyond the templateEvery flow, and the fallback for the others
One-tap autofill Android appsOne tap on the buttonPackage name, signing hash, app-side handlerAndroid app logins and signups
Zero-tap Android appsNoneSame as one-tap plus Meta’s zero-tap termsHigh-frequency logins on trusted devices
No button (SMS fallback) Any phoneRead and typeDLT header and templateUsers without WhatsApp or data
iOS keyboard suggestion iOS 26 and later, per Meta’s docsTap the suggestionNone on your sideiPhone users receiving copy-code templates

Build cost

WhatsApp OTP API project scope and starting prices

Build prices are starting points and exclude Meta’s per-message charges, which are billed to your own account. See all starting prices.

WhatsApp OTP API project scope and starting prices
ScopeStarts at (India)Starts at (abroad)Typical timeIncludes
WhatsApp OTP added to existing backend From ₹40,000From US$6002–4 weeksTemplate, send and verify endpoints, webhooks, limits
OTP login plus SMS fallback From ₹40,000From US$6002–4 weeksAbove plus DLT SMS route and channel switching
New web app with OTP login From ₹60,000From US$9006–12 weeksFull web app, auth, roles and dashboards
New Android and iOS app with OTP login From ₹40,000From US$6006–10 weeksFlutter or React Native app, one-tap on Android
Website with OTP-gated area From ₹10,000From US$1501–2 weeks plus integrationStatic site plus a small login service
Maintenance after 2 free months From ₹8,000/moFrom US$120/moMonthlyToken rotation, API upgrades, template changes

Timeline

WhatsApp OTP API rollout by phase

A typical sequence for adding WhatsApp OTP to a live app. Verification delays on Meta’s side can stretch phase one.

WhatsApp OTP API rollout by phase
PhaseTimeWhat happensWhat you provide
Accounts Days 1–5Business portfolio checks, WABA, number, template submissionBusiness documents, admin access
Backend module Days 3–10Code generation, hashing, send and verify endpointsServer or cloud access
Client screens Days 8–14OTP input, resend timer, channel switch, one-tap handlerApp repository access
Fallback and webhooks Days 10–16Delivery status tracking, SMS failover with same codeDLT header and OTP template ID
Testing Days 14–21Real devices, weak network, release keys, abuse scriptsTest phones and a few beta users
Launch and watch Days 21–28Gradual rollout, alerts, first metrics reviewGo-ahead for each rollout step

Across India

WhatsApp OTP API work for businesses in these cities

We work remotely with teams in every state. These city pages explain what local businesses there usually ask us to build.

  • Fintech login flows in Mumbai

    Lending, broking and payments startups in Mumbai need OTP flows with tight throttles, audit logs and SMS fallback for users on older phones.

  • SaaS sign-up in Bengaluru

    Bengaluru product teams often want WhatsApp codes for trial sign-ups and admin logins, with the module written into their existing Node or Python backend.

  • D2C checkout OTPs in Delhi

    Delhi NCR brands running sale days need login codes that keep flowing during traffic peaks and do not burn the messaging limit meant for order updates.

  • Edtech apps in Hyderabad

    Coaching and test-prep apps in Hyderabad log students in daily, so Telugu and English templates and one-tap Android autofill save a lot of support tickets.

  • Marketplace apps in Pune

    Pune startups building service marketplaces use OTP for both customers and partners, with separate rate limits for each side of the platform.

  • Textile trade portals in Surat

    Surat wholesalers moving buyers onto ordering portals want WhatsApp codes because their buyers already talk to them on WhatsApp all day.

  • Travel and tourism apps in Jaipur

    Jaipur tour and hotel booking apps serve visitors from many states, so WhatsApp codes help when a guest’s SMS is delayed on roaming.

  • Clinic report access in Lucknow

    Diagnostic labs and clinics in Lucknow gate report downloads behind OTP, where Hindi templates and SMS fallback suit older patients.

  • Retail loyalty apps in Indore

    Indore retailers launching loyalty and ordering apps want quick phone logins that work on budget Android phones common among their customers.

  • Healthcare portals in Kochi

    Kochi hospitals and clinics serving Gulf-based families need codes that reach Indian numbers used abroad, where WhatsApp often lands faster than SMS.

  • Manufacturing dealer portals in Coimbatore

    Coimbatore pump and textile machinery makers run dealer portals where OTP login replaces shared passwords and keeps access tied to a phone number.

  • Real estate apps in Gurgaon

    Gurgaon property platforms verify buyer and broker numbers before sharing listings, so OTP fraud controls matter as much as delivery speed.

  • Food delivery apps in Kolkata

    Kolkata restaurants and cloud kitchens building their own ordering apps want a WhatsApp login that matches the channel customers already order on.

  • Government-service helpers in Patna

    Patna service portals and CSC-style businesses serve users on low data, so they keep SMS as the default and offer WhatsApp as a faster option.

  • Co-operative bank apps in Rajkot

    Rajkot credit societies and co-operative lenders adding apps often need Gujarati templates and strict attempt limits on every OTP screen.

How it works

How we add a WhatsApp OTP API to your product

  1. Share the current login flow

    Send screenshots or a short screen recording of your signup and login, plus your stack and rough monthly OTP volume. We reply on WhatsApp with questions the same week.

  2. Get an itemised quote

    Within about two working days you receive a scope with each piece listed: template setup, backend module, fallback, one-tap, limits. Nothing is billed before you approve it in writing.

  3. Prepare Meta and DLT access

    You add us to your business portfolio and share DLT template details. We submit the authentication template and set up the number while coding starts.

  4. Build and test on staging

    We write the OTP module, webhooks and screens against a test number, then run real-device tests on Android and iPhone, including weak networks and abuse scripts.

  5. Roll out in steps

    Start with a slice of Android users, compare delivery and completion with SMS, then widen. Fallback stays on the whole time, so nobody gets locked out.

  6. Hand over and support

    You get the code, a runbook and a walkthrough. Two months of maintenance are free; token rotation and API upgrades are covered in that period.

Questions

WhatsApp OTP API: questions people ask

What is a WhatsApp OTP API?

It is an API call from your server to Meta’s WhatsApp Business Platform that delivers a one-time passcode to a user’s WhatsApp number using an authentication template. Your server creates and verifies the code; WhatsApp only carries it. The message shows your business name and a copy or autofill button, and it can replace or sit alongside SMS OTP in your login, signup or password-reset flow.

Is WhatsApp OTP free?

No. Meta charges per delivered authentication template message, at a rate that depends on the recipient’s country and your monthly volume tier. Service replies inside a customer service window are free, but OTPs are business-initiated authentication messages and are billed. Integration work is separate: with BtechWaleTech it starts at the AI automation price listed on our pricing page, and Meta’s charges go on your own account.

How much does WhatsApp OTP cost in India compared with SMS?

It depends on your SMS contract and volume, so compare actual rate cards. Meta bills authentication messages per delivery, with lower rates as monthly volume grows, and India-based businesses messaging Indian numbers pay the domestic rate rather than the authentication-international rate. SMS has per-message charges plus DLT costs. Many teams end up paying for both, because SMS stays as a fallback for users WhatsApp cannot reach.

Can I send OTP on WhatsApp without the Business API?

Not properly. The free WhatsApp Business app has no API, and automating it with unofficial tools breaks WhatsApp’s terms and can get the number banned, which would stop every login. A WhatsApp OTP API needs the official WhatsApp Business Platform, either directly through Meta’s Cloud API or through a Business Solution Provider, with an approved authentication template.

Can I change the wording of a WhatsApp OTP message?

Only slightly. Meta’s authentication templates use fixed body text, with the code as the variable, plus two optional lines: a security disclaimer and an expiry notice set between 1 and 90 minutes. You choose the button type and the languages. If you need to say more, such as a welcome note, send it separately using a utility or marketing template after the user verifies.

What is one-tap autofill for WhatsApp OTP?

It is an Android feature where the user taps a button in the WhatsApp message and the code is passed directly into your app, with no copying or typing. The template includes your app’s package name and signing-certificate hash, and the app needs a small piece of handling code. If the app is missing or the hash does not match, WhatsApp falls back to showing a copy-code button.

Does WhatsApp OTP autofill work on iPhone?

One-tap and zero-tap are Android-only. On iPhone, users get the copy-code button, copy the code and paste it into your app or website. Meta’s documentation notes that on iOS 26 and later, keyboard suggestions can offer the code from the WhatsApp notification, which makes entry faster without changes on your side. Test on real devices before promising a specific experience to users.

Do I still need DLT registration if I use WhatsApp OTP?

If you keep SMS as a fallback, yes. TRAI’s TCCCPR 2018 requires commercial SMS in India to use registered headers and content templates on DLT, and a fallback OTP is commercial SMS. WhatsApp messages themselves are not sent over DLT. Most businesses already have a DLT header and OTP template, and we reuse them for the fallback route.

What happens if the user does not have WhatsApp?

Meta returns a failure status for that number, and a well-built flow switches to SMS straight away using the same code. If there is no delivery signal within about 20–30 seconds, the flow should fall back too. We also show a manual “Send by SMS instead” link after a short timer, so users with WhatsApp installed but no data connection can still log in.

How long does a WhatsApp OTP API integration take?

Usually two to four weeks for an existing app or website. The code takes about half that time; the rest goes to Meta business verification, template approval and testing on real Android and iPhone devices, including one-tap with release signing keys. Having your business documents and Meta business portfolio access ready at kickoff is the best way to keep it short.

How do I stop bots from abusing my OTP endpoint?

Layer simple controls: cap requests per phone number, per IP and per device; allow only the country codes you serve; add an invisible bot check on the request form; cap verification attempts per code; lock numbers after repeated failures; and alert on unusual spikes. Every delivered WhatsApp authentication message is billed, so these limits protect your budget as well as your users.

What are WhatsApp’s sending limits for OTP messages?

Meta’s docs say a business number can send up to 80 messages per second by default, and only one message every six seconds to the same user, with limited bursts. Separately, a new business portfolio can reach 250 unique users in a moving 24-hour window outside service windows, rising in steps to unlimited. That limit is shared across numbers in the portfolio, so plan launches carefully.

Should I use a WhatsApp BSP or Meta’s Cloud API directly?

Go direct if you have a developer to maintain a small backend module; you pay only Meta and control everything. Use a Business Solution Provider if you want a dashboard, support desk or built-in SMS failover and accept a platform fee. Either way, make sure the WhatsApp Business Account sits in your own business portfolio so you can change provider later.

Is WhatsApp OTP more secure than SMS OTP?

It removes some SMS-specific risks, such as interception on the carrier network, because WhatsApp codes do not travel over the SMS network at all. But the real security comes from your server: short expiry, hashed storage, attempt caps and rate limits. A poorly built WhatsApp flow is less secure than a careful SMS one.

Can the same WhatsApp number send OTPs and marketing messages?

It can, but think twice. All numbers in a business portfolio share one messaging limit, and a marketing campaign that draws blocks or poor feedback can affect the number’s quality rating. Many teams use a dedicated number for authentication and utility messages and keep promotions separate, so a bad campaign never delays login codes.

Which programming languages can send WhatsApp OTPs?

Any language that can make an HTTPS request: Node.js, Python, PHP, Java, Go, .NET and others. The Cloud API is a REST endpoint that takes JSON. We usually write the OTP module in your existing backend stack, whether that is Express, NestJS, Django, FastAPI or Laravel, so your team can maintain it without learning a new tool.

Can WhatsApp OTP be used for website login, not only apps?

Yes. On a website the user enters their number, receives the code on WhatsApp and taps the copy-code button, then pastes it in the browser. One-tap and zero-tap do not apply to websites. We add session handling, resend timers and an SMS fallback link, the same way we would for an app.

Who owns the WhatsApp Business Account after the project?

You do. We set up or connect the WhatsApp Business Account, phone number and templates inside your own Meta business portfolio, and the OTP code lives in your repository. We work with access you grant and can remove at any time. That way login, the most critical feature of your product, never depends on a vendor’s account.

Do you provide support after the WhatsApp OTP API goes live?

Yes. Every project includes two months of free maintenance after launch, covering fixes, token rotation and Graph API version upgrades. After that, maintenance starts at ₹8,000/mo if you want us to continue. Larger changes, such as adding new languages or channels, are quoted separately and itemised before any work starts.

How do I pay for a WhatsApp OTP integration?

Clients in India pay by UPI or bank transfer; international clients pay in USD by Wise, bank wire or PayPal. Payment stages and terms are set out in your written quote, and nothing is billed before you approve it. Meta’s message charges are separate and paid directly to Meta from your own account.

WhatsApp par OTP bhejne ke liye kya chahiye?

Aapko Meta business portfolio, WhatsApp Business Account, ek registered phone number, approved authentication template aur ek backend chahiye jo code banakar Cloud API ko bheje. SMS fallback ke liye aapka DLT header aur template bhi chahiye. BtechWaleTech yeh poora setup 2–4 hafte mein karta hai, aur account hamesha aapke naam par rehta hai.

Next step

Want login codes on WhatsApp without losing SMS users?

Send us your current login flow and monthly OTP volume on WhatsApp. You will get an itemised quote in about two working days, and the WhatsApp Business Account stays in your name.