1msg official logo

Migrate OTP from SMS to WhatsApp API

Delivers a one-time verification code through a WhatsApp authentication template when your product switches OTP delivery from SMS to WhatsApp.

Use case overview

Delivers a one-time verification code through a WhatsApp authentication template when your product switches OTP delivery from SMS to WhatsApp. The copy-code button keeps entry fast in your existing login or signup form.

Template example

{{1}} is your verification code. For your security, do not share this code with anyone.

Copy code
  • {{1}}
    one-time verification code for SMS-to-WhatsApp migration (digits)
  • “Copy code”
    button — fixed in the Meta template
WhatsApp Business API for sms to whatsapp otp migration

When to use it

Reach for this scenario when you are replacing SMS one-time codes with WhatsApp OTP delivery and still need cold-start compliance on the first send. It fits channel migration projects, teams cutting SMS cost or improving delivery reach, and products that keep the same backend validation while switching the transport to WhatsApp for developers, small teams, and agencies.

Migrate without rewriting validation
One body variable carries the OTP digits in the authentication template, so your backend keeps the same generate-and-verify logic while only the delivery channel changes from SMS to WhatsApp.
Reach users where they already chat
WhatsApp delivers the code in an app users open daily, which reduces missed OTP messages compared with SMS filters and delayed carrier routing.
Compliant cold-start on first migrated send
An approved authentication template with body and copy-code button parameters opens the conversation without a session, so the first post-migration code send stays within WhatsApp policy.
Send succeeds on first try
Authentication templates require the OTP in both the message body and the copy-code button payload; supplying both avoids a body-only send that returns `sent: false`.

Workflow

  1. Build & send

    User triggers verification on a flow that previously sent SMS OTP.

    POST /sendTemplate

  2. Generates a code

    Backend generates a code and sends the authentication template via WhatsApp.

    POST /sendTemplate

  3. Customer acts

    User copies the code from WhatsApp and submits it in your app.

    user action

  4. Delivered

    Backend validates the code and completes the same step as the old SMS path.

    delivered

WhatsApp Business API for sms to whatsapp otp migration

Technical implementation

Prerequisites

  1. 1MSG API Key · How to get API Key
  2. WhatsApp Business account · How to Connect WABA
  3. WhatsApp Template · How to Approve WABA Template
  4. Customer opt-in · How to Manage Customers Consent

Code examples

#!/usr/bin/env bash
set -euo pipefail

# === Configuration (replace "___" placeholders) ===

API_BASE_URL="https://api.1msg.io"        # production 1MSG API base URL
CHANNEL_ID="___"                           # channel ID from 1MSG dashboard
API_TOKEN="___"                            # channel JWT token (Bearer)

TEMPLATE_NAME="___"                        # approved template name
TEMPLATE_NAMESPACE="___"                   # template namespace (required — send fails without it)
TEMPLATE_LANGUAGE="___"                    # template language code, e.g. "en"



# === Test data ===
TEST_PHONE="___"                 # client phone in international format
TEST_OTPCODE="___"         # {{1}} otp code

PHONE_NORM="$(printf '%s' "$TEST_PHONE" | tr -cd '0-9')"

for pair in "CHANNEL_ID=$CHANNEL_ID" "API_TOKEN=$API_TOKEN" \
            "TEMPLATE_NAME=$TEMPLATE_NAME" "TEMPLATE_NAMESPACE=$TEMPLATE_NAMESPACE" \
            "TEMPLATE_LANGUAGE=$TEMPLATE_LANGUAGE" "TEST_PHONE=$TEST_PHONE" \
            "TEST_OTPCODE=$TEST_OTPCODE"; do
    val="${pair#*=}"
    if [ -z "$val" ] || [ "$val" = "___" ]; then
        echo "Missing configuration value: ${pair%%=*}" >&2
        exit 1
    fi
done

if [ -z "$PHONE_NORM" ]; then
    echo "Error: phone number has no digits after normalization" >&2
    exit 1
fi

URL="${API_BASE_URL%/}/${CHANNEL_ID}/sendTemplate"

# params carries body and button blocks.

# {{1}} otp code → ${TEST_OTPCODE}
read -r -d '' PAYLOAD <<JSON || true
{
  "phone": "${PHONE_NORM}",
  "template": "${TEMPLATE_NAME}",
  "namespace": "${TEMPLATE_NAMESPACE}",
  "language": { "policy": "deterministic", "code": "${TEMPLATE_LANGUAGE}" },
  "params": [
    {
      "type": "body",
      "parameters": [
        { "type": "text", "text": "${TEST_OTPCODE}" }
      ]
    },
    {
      "type": "button",
      "sub_type": "url",
      "index": "0",
      "parameters": [ { "type": "text", "text": "${TEST_OTPCODE}" } ]
    }

  ]
}
JSON

RESPONSE="$(curl -s -w '\n%{http_code}' -X POST "$URL" \
    -H "Content-Type: application/json" \
    -H "Authorization: Bearer ${API_TOKEN}" \
    -d "$PAYLOAD")"

HTTP_CODE="$(printf '%s' "$RESPONSE" | tail -n1)"
BODY="$(printf '%s' "$RESPONSE" | sed '$d')"

case "$BODY" in
    *'"sent":true'*) ok=1 ;;
    *) ok=0 ;;
esac

if [ "$HTTP_CODE" -ge 200 ] && [ "$HTTP_CODE" -lt 300 ] && [ "$ok" -eq 1 ]; then
    echo "Message sent to client."
    echo "API response: $BODY"
else
    echo "Send failed. HTTP status: $HTTP_CODE" >&2
    echo "$BODY" >&2
    exit 1
fi

Response and delivery status

HTTP 2xx and JSON "sent": true mean 1MSG accepted the message for sending — not that it already reached the customer's phone. Save the id field (looks like wamid.…) to correlate delivery callbacks.

200 OKResponse
{
  "sent": true,
  "message": "Sent to [email protected]",
  "description": "Message has been sent to the provider",
  "id": "wamid.HBgLMzgwNjM5..."
}
  • sent

    Accepted for sending — not yet on the customer's phone

  • id

    Store it; delivery callbacks and hookInfo are keyed on this

Delivery statuses and webhooks →

Common errors

StatusAPI responseCauseFix
200Message was not sent: template is not definednamespace, template or language is missing from the request body.Send all three. Take namespace and the exact template name from GET /templates; language is an object: {"policy": "deterministic", "code": "en"}.
200template name (…) does not exist in <language>The template is approved in a different language than the one requested.Use the exact language code the template was approved in (for example es_MX is not the same as es). Check it in GET /templates.
200Message was not sent: provide chatId, phone, bsuid, or usernameNo recipient the channel could resolve.Pass exactly one recipient: phone (country code plus number, digits only), chatId (for example [email protected]) or bsuid.

All error codes →

Common questions

Related

OTP Verification
KYC action required alert via WhatsApp API
The scenario sends the client a personalized WhatsApp template when KYC or compliance review flags a required action with a deadline.
OTP Verification
Identity verification request via WhatsApp API
The scenario sends the client a personalized WhatsApp template when identity or KYC verification is required but not yet started.
OTP Verification
Secure portal login OTP via WhatsApp API
The scenario sends a WhatsApp authentication template with a one-time verification code when the user must confirm sign-in to a protected or secure service.
OTP Verification
App signup verification code via WhatsApp API
Sends a WhatsApp authentication template with a one-time registration confirmation code in the message body and a copy-code button.
OTP Verification
OTP to confirm secure actions via WhatsApp API
The scenario sends a WhatsApp authentication template with a one-time verification code when the user must confirm a secure action before it executes.
OTP Verification
Access verification code via WhatsApp API
Sends a one-time access confirmation code through a WhatsApp authentication template when the user must verify identity before using a protected service.
OTP Verification
Login authorization OTP via WhatsApp API
Sends a one-time authorization code through a WhatsApp authentication template when the user must confirm sign-in or access.
OTP Verification
New device login OTP via WhatsApp API
The scenario sends the user a WhatsApp authentication template with a one-time verification code when a login attempt is flagged as coming from a new device.

Build for WhatsApp in hours
without infrastructure hassle