1msg official logo

OTP to confirm secure actions via WhatsApp API

The scenario sends a WhatsApp authentication template with a one-time verification code when the user must confirm a secure action before it executes.

Use case overview

The scenario sends a WhatsApp authentication template with a one-time verification code when the user must confirm a secure action before it executes. The copy-code button lets the user paste the code into your confirmation screen without retyping digits from the chat.

Template example

{{1}} is your verification code. For your security, do not share this code with anyone.

Copy code
  • {{1}}
    one-time secure-action verification code (digits)
  • “Copy code”
    button — fixed in the Meta template
WhatsApp Business API for secure action confirmation otp

When to use it

Reach for this scenario when a user starts a secure or sensitive action in your system — payment approval, transfer confirmation, data export, or a privileged operation — and you need a one-time code on WhatsApp before the action executes. There is usually no open chat yet, so a free-text message is not allowed on cold start. It fits fintech and admin portals, step-up gates before high-impact changes, and teams wiring secure-action confirmation into web apps, mobile apps, or backends through the 1MSG API.

Confirm intent before a secure action runs
The backend generates a short-lived code when the user starts a sensitive operation and sends it in one body variable through an authentication template, bound to the pending action until validation completes.
Faster code entry on mobile
The copy-code button carries the same OTP as the message body, so the user pastes the digits into your confirmation dialog instead of retyping them from chat.
Verification without an open chat
Authentication-category templates deliver the OTP even when no support session is open, so secure-action confirmation works on cold start without needing an active conversation first.
Fewer rejected API sends
Authentication templates require the OTP in both the message body and the copy-code button; supplying both avoids body-only requests that return `sent: false`.

Workflow

  1. Trigger

    The user initiates a secure or sensitive action in your app or portal.

    event · triggered

  2. Capture event

    Your backend generates a one-time verification code and resolves the user's WhatsApp number.

    phone: "+…"

  3. Build & send

    A template message is built with the code in the body and the same value in the copy-code button parameter.

    POST /sendTemplate

  4. Delivered

    The user receives the WhatsApp message and copies or reads the code.

    delivered

  5. Status tracked

    Your backend validates the submitted code and completes or rejects the secure action; delivery errors are handled per platform rules.

    status: "read"

WhatsApp Business API for secure action confirmation otp

Technical implementation

Prerequisites

  1. 1MSG API Key · How to get API Key
  2. WhatsApp Business account · How to Connect WABA
  3. WhatsApp Template · How to Approve WABA Template
  4. Customer opt-in · How to Manage Customers Consent

Code examples

#!/usr/bin/env bash
set -euo pipefail

# === Configuration (replace "___" placeholders) ===

API_BASE_URL="https://api.1msg.io"        # production 1MSG API base URL
CHANNEL_ID="___"                           # channel ID from 1MSG dashboard
API_TOKEN="___"                            # channel JWT token (Bearer)

TEMPLATE_NAME="___"                        # approved template name
TEMPLATE_NAMESPACE="___"                   # template namespace (required — send fails without it)
TEMPLATE_LANGUAGE="___"                    # template language code, e.g. "en"



# === Test data ===
TEST_PHONE="___"                 # client phone in international format
TEST_CODE="___"         # {{1}} otp code

PHONE_NORM="$(printf '%s' "$TEST_PHONE" | tr -cd '0-9')"

for pair in "CHANNEL_ID=$CHANNEL_ID" "API_TOKEN=$API_TOKEN" \
            "TEMPLATE_NAME=$TEMPLATE_NAME" "TEMPLATE_NAMESPACE=$TEMPLATE_NAMESPACE" \
            "TEMPLATE_LANGUAGE=$TEMPLATE_LANGUAGE" "TEST_PHONE=$TEST_PHONE" \
            "TEST_CODE=$TEST_CODE"; do
    val="${pair#*=}"
    if [ -z "$val" ] || [ "$val" = "___" ]; then
        echo "Missing configuration value: ${pair%%=*}" >&2
        exit 1
    fi
done

if [ -z "$PHONE_NORM" ]; then
    echo "Error: phone number has no digits after normalization" >&2
    exit 1
fi

URL="${API_BASE_URL%/}/${CHANNEL_ID}/sendTemplate"

# params carries body and button blocks.

# {{1}} otp code → ${TEST_CODE}
read -r -d '' PAYLOAD <<JSON || true
{
  "phone": "${PHONE_NORM}",
  "template": "${TEMPLATE_NAME}",
  "namespace": "${TEMPLATE_NAMESPACE}",
  "language": { "policy": "deterministic", "code": "${TEMPLATE_LANGUAGE}" },
  "params": [
    {
      "type": "body",
      "parameters": [
        { "type": "text", "text": "${TEST_CODE}" }
      ]
    },
    {
      "type": "button",
      "sub_type": "url",
      "index": "0",
      "parameters": [ { "type": "text", "text": "${TEST_CODE}" } ]
    }

  ]
}
JSON

RESPONSE="$(curl -s -w '\n%{http_code}' -X POST "$URL" \
    -H "Content-Type: application/json" \
    -H "Authorization: Bearer ${API_TOKEN}" \
    -d "$PAYLOAD")"

HTTP_CODE="$(printf '%s' "$RESPONSE" | tail -n1)"
BODY="$(printf '%s' "$RESPONSE" | sed '$d')"

case "$BODY" in
    *'"sent":true'*) ok=1 ;;
    *) ok=0 ;;
esac

if [ "$HTTP_CODE" -ge 200 ] && [ "$HTTP_CODE" -lt 300 ] && [ "$ok" -eq 1 ]; then
    echo "Message sent to client."
    echo "API response: $BODY"
else
    echo "Send failed. HTTP status: $HTTP_CODE" >&2
    echo "$BODY" >&2
    exit 1
fi

Response and delivery status

HTTP 2xx and JSON "sent": true mean 1MSG accepted the message for sending — not that it already reached the customer's phone. Save the id field (looks like wamid.…) to correlate delivery callbacks.

200 OKResponse
{
  "sent": true,
  "message": "Sent to [email protected]",
  "description": "Message has been sent to the provider",
  "id": "wamid.HBgLMzgwNjM5..."
}
  • sent

    Accepted for sending — not yet on the customer's phone

  • id

    Store it; delivery callbacks and hookInfo are keyed on this

Delivery statuses and webhooks →

Common errors

StatusAPI responseCauseFix
200Message was not sent: template is not definednamespace, template or language is missing from the request body.Send all three. Take namespace and the exact template name from GET /templates; language is an object: {"policy": "deterministic", "code": "en"}.
200template name (…) does not exist in <language>The template is approved in a different language than the one requested.Use the exact language code the template was approved in (for example es_MX is not the same as es). Check it in GET /templates.
200Message was not sent: provide chatId, phone, bsuid, or usernameNo recipient the channel could resolve.Pass exactly one recipient: phone (country code plus number, digits only), chatId (for example [email protected]) or bsuid.

All error codes →

Common questions

Related

OTP Verification
Identity verification request via WhatsApp API
The scenario sends the client a personalized WhatsApp template when identity or KYC verification is required but not yet started.
OTP Verification
Secure portal login OTP via WhatsApp API
The scenario sends a WhatsApp authentication template with a one-time verification code when the user must confirm sign-in to a protected or secure service.
OTP Verification
App signup verification code via WhatsApp API
Sends a WhatsApp authentication template with a one-time registration confirmation code in the message body and a copy-code button.
OTP Verification
Migrate OTP from SMS to WhatsApp API
Delivers a one-time verification code through a WhatsApp authentication template when your product switches OTP delivery from SMS to WhatsApp.
OTP Verification
Access verification code via WhatsApp API
Sends a one-time access confirmation code through a WhatsApp authentication template when the user must verify identity before using a protected service.
OTP Verification
Login authorization OTP via WhatsApp API
Sends a one-time authorization code through a WhatsApp authentication template when the user must confirm sign-in or access.
OTP Verification
New device login OTP via WhatsApp API
The scenario sends the user a WhatsApp authentication template with a one-time verification code when a login attempt is flagged as coming from a new device.
OTP Verification
New sign-in confirmation code via WhatsApp API
Sends a one-time login confirmation code through a WhatsApp authentication template when your backend detects a sign-in from a new device, browser, or location.

Build for WhatsApp in hours
without infrastructure hassle