Home › WhatsApp OTP verification service

WhatsApp OTP verification service: send and verify codes from your own number

Replio's OTP service sends one-time passcodes to your users on WhatsApp, from your own verified business number, and checks the code they type back if you want it to. It is prepaid per delivered code, carries no monthly fee, and takes one HTTP request to add to a sign-up form. This page is the plain-language version for the person deciding whether to use it; the API reference is the version for the person wiring it in.

Why codes are moving from SMS to WhatsApp

SMS was the default channel for verification codes because every phone could receive one. It is no longer the best one. International SMS is expensive and inconsistently delivered, several countries are restricting promotional and even transactional SMS, and users have learned to distrust codes from unfamiliar shortcodes because that is exactly what phishing looks like. WhatsApp fixes all three for anyone who has it: the code lands in the app people already have open, it costs a fraction of an SMS in most markets, and it arrives in a chat that carries your business name and profile. What to use instead of SMS OTP goes through the country-by-country picture in more detail.

The trade-off is honest and simple: a user who does not have WhatsApp cannot receive the code. Replio tells you that immediately (the send fails with a clear error instead of silently vanishing), so you keep SMS or email as the fallback path and most of your users never need it.

How the service works

  1. Connect your WhatsApp Business number in the Replio dashboard. Codes go out from that number, so the chat shows your business, not a shared sender. Replio connects through Meta's official API as a verified Meta Tech Provider.
  2. Pick an Authentication template. WhatsApp requires business-initiated messages to use a template Meta has approved. You do not write one: Meta's template library has ready-made authentication templates, and approval is usually quick because the wording is Meta's own. Replio picks an approved one automatically when you send.
  3. Buy credits and create a key. Credits are prepaid and sit in their own balance, separate from your support-message allowance, so a busy support month can never block a login.
  4. Send one request from your sign-up, login or reset flow with the user's number. If you already generate codes, pass yours and Replio only delivers it; nothing in your existing verification logic changes.
  5. Or let Replio verify too. Leave the code out and Replio generates a six-digit code, stores only its hash, delivers it, and gives you a verify call to check what the user typed. Expiry, single use, guess limits and superseding of old codes are handled for you.

Where businesses use it

MomentWhat the code protectsWho sends it
Sign-upThat the phone number belongs to the person registeringYour registration form, one request after the number is entered
Login (2FA)The account, when a password alone is not enoughYour login flow, on every sign-in or only on a new device
Password or PIN resetThat the reset request is genuineYour reset flow, before showing the reset form
Before a booking, order or payoutThat the contact number works, so the confirmation and the courier reach a real personYour checkout or booking step
Step-up on a sensitive actionChanging a bank account, withdrawing a balance, deleting an accountThe action itself, with a short-expiry code

Label the field "WhatsApp number" rather than "phone number", and say the code arrives on WhatsApp before the user submits. That one line of form copy prevents more failed verifications than any retry logic: a user who expects an SMS does not think to open WhatsApp, assumes the send failed, and gives up.

What it costs

You pay per delivered code, from a prepaid balance, and nothing else.

PackPricePer code
1,000 credits$35$0.035
10,000 credits$300$0.030
50,000 credits$1,250$0.025

Credits never expire. Only a delivered send costs a credit: rejected requests, rate-limited calls, failed sends and test-mode calls are free. One credit sends to almost everywhere; three destinations cost two credits (Indonesia, the United Arab Emirates and Malaysia) because WhatsApp itself charges several times more to deliver there, and every response states exactly what it cost so you never have to infer it. There is no monthly platform fee for the OTP service: credits are an add-on to the Replio account you already have, including the free plan.

For comparison, Twilio Verify charges $0.05 per verification plus the channel fee, about $0.053 for a WhatsApp code, at every volume, and requires you to bring your own WhatsApp sender. The Twilio Verify comparison and the Dexatel comparison set the numbers side by side, including the cases where each of those is the better choice.

Protections you get without configuring anything

ProtectionDefaultWhy it is there
Codes per recipient5 an hourStops one number being flooded at your expense and reported as spam
Wrong guesses per code5, then the code is voidMakes guessing a six-digit code impractical
Verify attempts per recipient10 per ten minutesCloses the loophole of requesting fresh codes to reset the guess count
Code expiry5 minutes (1 to 30 configurable)A code found later is useless
Code storageSHA-256 hash only, single useNobody, including Replio, can read a live code back
Account sends60 a minute, 5,000 a dayA runaway loop cannot drain your balance; raise it for a launch by asking
Template categoryAuthentication or Utility onlyCodes on Marketing templates get numbers restricted or banned
API keysStored hashed; owner-only rotation, instantA leaked key is dead in one click

Testing before you go live

A test key is a separate credential from your live key. It validates the entire request and applies every rule above, then stops short of sending or checking anything real: no credits spent, no messages to real people, and test sends appear in your logs marked as tests. The verify call behaves the same way, accepting any code in test mode. Build on the test key, ship, and swap in the live key; both can be active at once and rotating one never touches the other.

What you need, and honest limits

You need a Replio account with a WhatsApp Business number connected, one approved Authentication (or Utility) template on that number, credits, and someone who can add one HTTP request to your form. Codes are delivered anywhere WhatsApp operates. What the service does not do: it does not send SMS or email itself (keep your existing path as the fallback for users without WhatsApp), it is not a hosted login page or an identity provider, and it does not verify documents or identities, only that a phone number is in the hands of the person typing. If you need those, pair it with a tool that does them.

Start sending codes on WhatsApp

Create a free Replio account, connect your number, and build on a test key before a single credit is spent.

Start free   Read the API reference

Frequently asked questions

What is a WhatsApp OTP verification service?
A service that delivers one-time passcodes to your users on WhatsApp instead of SMS, and optionally checks the code they type back. Replio's version sends from your own verified WhatsApp Business number, so the code arrives in a chat with your business name on it rather than from an anonymous shortcode, and it is used for sign-up verification, login two-factor codes, password resets and confirming a phone number before a booking or a payout.
Why send OTP codes on WhatsApp rather than SMS?
Three reasons. People open WhatsApp, so codes are seen quickly and rarely lost in a spam folder. In most markets a WhatsApp authentication message costs a fraction of an international SMS, and in some countries SMS OTP delivery is unreliable or being restricted outright. And the message comes from your verified business profile, which users recognise, instead of a shared sender ID that phishing messages also use. The honest caveat: a user without WhatsApp cannot receive it, so keep SMS or email as a fallback for the send_failed case.
How much does it cost per code?
Credits are prepaid and never expire: 1,000 credits for $35 ($0.035 a code), 10,000 for $300 ($0.030) or 50,000 for $1,250 ($0.025). One credit sends to almost every country; Indonesia, the UAE and Malaysia cost two credits because WhatsApp itself charges several times more to deliver there. Only a delivered code costs anything: rejected requests, rate-limited calls, failed sends and test-mode calls are free. There is no monthly fee for the OTP service on top of your Replio account.
Do I need a developer to set it up?
You need someone who can add one HTTP request to your sign-up or login form; there is no SDK to install, and the request is shown in cURL, Node.js and Python in the API reference. Everything else is clicks: connect your WhatsApp number in the Replio dashboard, pick a ready-made Authentication template from Meta's library, buy credits and create a key. If you already generate and check codes yourself, you only replace the sending step. If you do not, leave out the code and Replio generates, stores and verifies it for you.
How are the codes kept safe?
Codes Replio generates are stored only as a SHA-256 hash with a short expiry (five minutes by default, configurable from one to thirty), are single-use, allow five wrong guesses before they are void, and a fresh send cancels any earlier unused code. Each recipient can receive at most five codes an hour, which stops a single number being flooded at your expense. API keys are stored hashed, only the account owner can create or rotate them, and rotation takes effect immediately. Marketing templates are refused outright, because sending codes on one is a common way to get a number banned.
Can I test it without messaging real people?
Yes. A test key, separate from your live key, validates the whole request and applies every rule but sends nothing and bills nothing; test sends show in your logs marked as tests, and the verify endpoint accepts any code in test mode. Build and ship the integration on the test key, then swap in the live key. Both keys can exist at the same time and rotating one never touches the other.

Related