Migrate OTP from SMS to WhatsApp API
Delivers a one-time verification code through a WhatsApp authentication template when your product switches OTP delivery from SMS to WhatsApp.
Use case overview
Delivers a one-time verification code through a WhatsApp authentication template when your product switches OTP delivery from SMS to WhatsApp. The copy-code button keeps entry fast in your existing login or signup form.
Template example
{{1}} is your verification code. For your security, do not share this code with anyone.
- {{1}}one-time verification code for SMS-to-WhatsApp migration (digits)
- “Copy code”button — fixed in the Meta template

When to use it
Reach for this scenario when you are replacing SMS one-time codes with WhatsApp OTP delivery and still need cold-start compliance on the first send. It fits channel migration projects, teams cutting SMS cost or improving delivery reach, and products that keep the same backend validation while switching the transport to WhatsApp for developers, small teams, and agencies.
Workflow
- Build & send
User triggers verification on a flow that previously sent SMS OTP.
POST/sendTemplate - Generates a code
Backend generates a code and sends the authentication template via WhatsApp.
POST/sendTemplate - Customer acts
User copies the code from WhatsApp and submits it in your app.
user action - Delivered
Backend validates the code and completes the same step as the old SMS path.
delivered

Technical implementation
Prerequisites
- 1MSG API Key · How to get API Key
- WhatsApp Business account · How to Connect WABA
- WhatsApp Template · How to Approve WABA Template
- Customer opt-in · How to Manage Customers Consent
Code examples
#!/usr/bin/env bash
set -euo pipefail
# === Configuration (replace "___" placeholders) ===
API_BASE_URL="https://api.1msg.io" # production 1MSG API base URL
CHANNEL_ID="___" # channel ID from 1MSG dashboard
API_TOKEN="___" # channel JWT token (Bearer)
TEMPLATE_NAME="___" # approved template name
TEMPLATE_NAMESPACE="___" # template namespace (required — send fails without it)
TEMPLATE_LANGUAGE="___" # template language code, e.g. "en"
# === Test data ===
TEST_PHONE="___" # client phone in international format
TEST_OTPCODE="___" # {{1}} otp code
PHONE_NORM="$(printf '%s' "$TEST_PHONE" | tr -cd '0-9')"
for pair in "CHANNEL_ID=$CHANNEL_ID" "API_TOKEN=$API_TOKEN" \
"TEMPLATE_NAME=$TEMPLATE_NAME" "TEMPLATE_NAMESPACE=$TEMPLATE_NAMESPACE" \
"TEMPLATE_LANGUAGE=$TEMPLATE_LANGUAGE" "TEST_PHONE=$TEST_PHONE" \
"TEST_OTPCODE=$TEST_OTPCODE"; do
val="${pair#*=}"
if [ -z "$val" ] || [ "$val" = "___" ]; then
echo "Missing configuration value: ${pair%%=*}" >&2
exit 1
fi
done
if [ -z "$PHONE_NORM" ]; then
echo "Error: phone number has no digits after normalization" >&2
exit 1
fi
URL="${API_BASE_URL%/}/${CHANNEL_ID}/sendTemplate"
# params carries body and button blocks.
# {{1}} otp code → ${TEST_OTPCODE}
read -r -d '' PAYLOAD <<JSON || true
{
"phone": "${PHONE_NORM}",
"template": "${TEMPLATE_NAME}",
"namespace": "${TEMPLATE_NAMESPACE}",
"language": { "policy": "deterministic", "code": "${TEMPLATE_LANGUAGE}" },
"params": [
{
"type": "body",
"parameters": [
{ "type": "text", "text": "${TEST_OTPCODE}" }
]
},
{
"type": "button",
"sub_type": "url",
"index": "0",
"parameters": [ { "type": "text", "text": "${TEST_OTPCODE}" } ]
}
]
}
JSON
RESPONSE="$(curl -s -w '\n%{http_code}' -X POST "$URL" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer ${API_TOKEN}" \
-d "$PAYLOAD")"
HTTP_CODE="$(printf '%s' "$RESPONSE" | tail -n1)"
BODY="$(printf '%s' "$RESPONSE" | sed '$d')"
case "$BODY" in
*'"sent":true'*) ok=1 ;;
*) ok=0 ;;
esac
if [ "$HTTP_CODE" -ge 200 ] && [ "$HTTP_CODE" -lt 300 ] && [ "$ok" -eq 1 ]; then
echo "Message sent to client."
echo "API response: $BODY"
else
echo "Send failed. HTTP status: $HTTP_CODE" >&2
echo "$BODY" >&2
exit 1
fi
Response and delivery status
HTTP 2xx and JSON "sent": true mean 1MSG accepted the message for sending — not that it already reached the customer's phone. Save the id field (looks like wamid.…) to correlate delivery callbacks.
{
"sent": true,
"message": "Sent to [email protected]",
"description": "Message has been sent to the provider",
"id": "wamid.HBgLMzgwNjM5..."
}sentAccepted for sending — not yet on the customer's phone
idStore it; delivery callbacks and
hookInfoare keyed on this
Common errors
| Status | API response | Cause | Fix |
|---|---|---|---|
| 200 | Message was not sent: template is not defined | namespace, template or language is missing from the request body. | Send all three. Take namespace and the exact template name from GET /templates; language is an object: {"policy": "deterministic", "code": "en"}. |
| 200 | template name (…) does not exist in <language> | The template is approved in a different language than the one requested. | Use the exact language code the template was approved in (for example es_MX is not the same as es). Check it in GET /templates. |
| 200 | Message was not sent: provide chatId, phone, bsuid, or username | No recipient the channel could resolve. | Pass exactly one recipient: phone (country code plus number, digits only), chatId (for example [email protected]) or bsuid. |
