WhatsApp OTP verification service: send and verify codes from your own number
Replio's OTP service sends one-time passcodes to your users on WhatsApp, from your own verified business number, and checks the code they type back if you want it to. It is prepaid per delivered code, carries no monthly fee, and takes one HTTP request to add to a sign-up form. This page is the plain-language version for the person deciding whether to use it; the API reference is the version for the person wiring it in.
Why codes are moving from SMS to WhatsApp
SMS was the default channel for verification codes because every phone could receive one. It is no longer the best one. International SMS is expensive and inconsistently delivered, several countries are restricting promotional and even transactional SMS, and users have learned to distrust codes from unfamiliar shortcodes because that is exactly what phishing looks like. WhatsApp fixes all three for anyone who has it: the code lands in the app people already have open, it costs a fraction of an SMS in most markets, and it arrives in a chat that carries your business name and profile. What to use instead of SMS OTP goes through the country-by-country picture in more detail.
The trade-off is honest and simple: a user who does not have WhatsApp cannot receive the code. Replio tells you that immediately (the send fails with a clear error instead of silently vanishing), so you keep SMS or email as the fallback path and most of your users never need it.
How the service works
- Connect your WhatsApp Business number in the Replio dashboard. Codes go out from that number, so the chat shows your business, not a shared sender. Replio connects through Meta's official API as a verified Meta Tech Provider.
- Pick an Authentication template. WhatsApp requires business-initiated messages to use a template Meta has approved. You do not write one: Meta's template library has ready-made authentication templates, and approval is usually quick because the wording is Meta's own. Replio picks an approved one automatically when you send.
- Buy credits and create a key. Credits are prepaid and sit in their own balance, separate from your support-message allowance, so a busy support month can never block a login.
- Send one request from your sign-up, login or reset flow with the user's number. If you already generate codes, pass yours and Replio only delivers it; nothing in your existing verification logic changes.
- Or let Replio verify too. Leave the code out and Replio generates a six-digit code, stores only its hash, delivers it, and gives you a verify call to check what the user typed. Expiry, single use, guess limits and superseding of old codes are handled for you.
Where businesses use it
| Moment | What the code protects | Who sends it |
|---|---|---|
| Sign-up | That the phone number belongs to the person registering | Your registration form, one request after the number is entered |
| Login (2FA) | The account, when a password alone is not enough | Your login flow, on every sign-in or only on a new device |
| Password or PIN reset | That the reset request is genuine | Your reset flow, before showing the reset form |
| Before a booking, order or payout | That the contact number works, so the confirmation and the courier reach a real person | Your checkout or booking step |
| Step-up on a sensitive action | Changing a bank account, withdrawing a balance, deleting an account | The action itself, with a short-expiry code |
Label the field "WhatsApp number" rather than "phone number", and say the code arrives on WhatsApp before the user submits. That one line of form copy prevents more failed verifications than any retry logic: a user who expects an SMS does not think to open WhatsApp, assumes the send failed, and gives up.
What it costs
You pay per delivered code, from a prepaid balance, and nothing else.
| Pack | Price | Per code |
|---|---|---|
| 1,000 credits | $35 | $0.035 |
| 10,000 credits | $300 | $0.030 |
| 50,000 credits | $1,250 | $0.025 |
Credits never expire. Only a delivered send costs a credit: rejected requests, rate-limited calls, failed sends and test-mode calls are free. One credit sends to almost everywhere; three destinations cost two credits (Indonesia, the United Arab Emirates and Malaysia) because WhatsApp itself charges several times more to deliver there, and every response states exactly what it cost so you never have to infer it. There is no monthly platform fee for the OTP service: credits are an add-on to the Replio account you already have, including the free plan.
For comparison, Twilio Verify charges $0.05 per verification plus the channel fee, about $0.053 for a WhatsApp code, at every volume, and requires you to bring your own WhatsApp sender. The Twilio Verify comparison and the Dexatel comparison set the numbers side by side, including the cases where each of those is the better choice.
Protections you get without configuring anything
| Protection | Default | Why it is there |
|---|---|---|
| Codes per recipient | 5 an hour | Stops one number being flooded at your expense and reported as spam |
| Wrong guesses per code | 5, then the code is void | Makes guessing a six-digit code impractical |
| Verify attempts per recipient | 10 per ten minutes | Closes the loophole of requesting fresh codes to reset the guess count |
| Code expiry | 5 minutes (1 to 30 configurable) | A code found later is useless |
| Code storage | SHA-256 hash only, single use | Nobody, including Replio, can read a live code back |
| Account sends | 60 a minute, 5,000 a day | A runaway loop cannot drain your balance; raise it for a launch by asking |
| Template category | Authentication or Utility only | Codes on Marketing templates get numbers restricted or banned |
| API keys | Stored hashed; owner-only rotation, instant | A leaked key is dead in one click |
Testing before you go live
A test key is a separate credential from your live key. It validates the entire request and applies every rule above, then stops short of sending or checking anything real: no credits spent, no messages to real people, and test sends appear in your logs marked as tests. The verify call behaves the same way, accepting any code in test mode. Build on the test key, ship, and swap in the live key; both can be active at once and rotating one never touches the other.
What you need, and honest limits
You need a Replio account with a WhatsApp Business number connected, one approved Authentication (or Utility) template on that number, credits, and someone who can add one HTTP request to your form. Codes are delivered anywhere WhatsApp operates. What the service does not do: it does not send SMS or email itself (keep your existing path as the fallback for users without WhatsApp), it is not a hosted login page or an identity provider, and it does not verify documents or identities, only that a phone number is in the hands of the person typing. If you need those, pair it with a tool that does them.
Start sending codes on WhatsApp
Create a free Replio account, connect your number, and build on a test key before a single credit is spent.
Start free Read the API reference