WhatsApp API Switching providers? Move your WhatsApp number to CommLeap and keep its display name and quality ratingSwitching WhatsApp providers? Migrate to CommLeap
Verify API

A Verify API for OTP and two-factor authentication

CommLeap's Verify API is an OTP API that delivers one-time passwords over WhatsApp, SMS, voice and email and checks each code for you, with automatic channel fallback and fraud controls coming soon. Verify phone numbers at sign-up, protect logins and approve payments with two API calls.

WhatsApp, SMS, voice & email Automatic channel fallback Coming soon
Capabilities

A complete two-factor authentication API, not just a code sender

Verification sits on the most sensitive path in your product. CommLeap handles delivery and security policy together, with fraud controls coming soon, so your team does not have to rebuild them for every channel.

WhatsApp OTP

Meta authentication templates with a copy-code button, plus one-tap autofill on Android where supported, delivered from your WhatsApp business profile.

SMS, voice and email

Global SMS with sender registration support, text-to-speech voice calls that read the code aloud, and email codes through the Email API.

Automatic fallback Coming soon

You will be able to set a channel order and wait time. If a code is not delivered or used in time, the next channel will be tried within the same verification.

Managed or bring-your-own codes

Let CommLeap generate, store and check codes, or supply your own code when your security model requires generation to stay in-house.

Code policies

Configure code length, expiry, maximum check attempts and resend intervals per use case, from low-friction sign-up to strict payment approval.

Geo-permissions Coming soon

You will be able to allow verification only to the countries you serve, and set different channel orders per country to reflect local reach and cost.

Rate limiting Coming soon

Limits per phone number, number prefix, IP address and account will help stop bursts of requests before they turn into messages you pay for.

Fraud monitoring Coming soon

Conversion-rate monitoring by country and prefix will flag patterns associated with SMS pumping, with controls to pause or block traffic quickly.

Conversion analytics

See delivery, completion and time-to-verify by channel and country, so channel order decisions are based on your own data.

How verification works

Two API calls. Every channel.

Your application starts a verification with the user's phone number or email address and a channel. CommLeap generates the code and delivers it; once automatic fallback launches, it will also move to the next channel if needed. When the user enters the code, you call the check endpoint and get a clear approved or failed result.

  • One verification ID across resends, and across channels once fallback Coming soon launches
  • Codes expire automatically and lock after too many wrong attempts
  • Results delivered synchronously and as verification.approved or verification.failed webhooks
Explore the developer docs
Getting started

Launch phone number verification in four steps

Most teams can move to production quickly. The work that matters most is choosing the right policy and channel order for each market.

Configure your channels

Connect your WhatsApp Business account and approve an authentication template, register SMS senders where required, and add an email domain.

Set policies and limits

Define code length, expiry and attempt limits for each use case, such as sign-up, login or payments. Allowed-country and rate-limit settings are coming soon.

Integrate two endpoints

Call POST /v1/verify to send a code and POST /v1/verify/check to confirm it. A sandbox for testing the full flow is coming soon.

Monitor and tune

Review conversion by channel and country and adjust your channel choices as traffic grows. Fallback tuning and fraud alerts are coming soon.

WhatsApp OTP

Why many teams lead with WhatsApp for one-time passwords

In markets where WhatsApp is widely used, it can be a reliable and cost-effective first channel for verification codes. Messages travel over the internet rather than carrier SMS routes, so they are less exposed to the route-level issues that affect SMS in some countries, and they arrive from your business profile rather than an unfamiliar number.

  • Copy-code button, and one-tap autofill on Android where supported
  • Business name and profile shown with the code, which helps users trust the message
  • Meta charges per delivered authentication message at rates that vary by country, billed by Meta directly to your WhatsApp Business Account
  • SMS or voice fallback Coming soon for users who are not on WhatsApp or are offline

Cost and reach differ by market, so the best channel order is rarely the same everywhere. See how WhatsApp pricing works, or explore the WhatsApp Business API.

Authentication templates are a distinct Meta category

WhatsApp OTPs must use approved authentication templates, which follow a fixed format: the code, an optional security note and an optional expiry line, with a copy-code, one-tap or zero-tap autofill option. They cannot include marketing content, URLs, media or emojis. CommLeap helps you prepare templates for Meta's review in the languages you support.

Fraud protection

Defend against SMS pumping and artificially inflated traffic

SMS pumping, also known as artificially inflated traffic (AIT), happens when bots submit your sign-up or login forms to trigger messages to numbers controlled by fraudsters, who share in the termination revenue. The cost falls on you. The Verify API's fraud controls Coming soon will add several layers of defense.

01

Geo-permissions Coming soon

Block verification to countries you do not serve, which will be able to remove a large share of exposure with little effect on your real users.

02

Velocity limits Coming soon

Cap requests per number, prefix, IP address and time window, so automated bursts will be stopped before messages are sent.

03

Conversion monitoring Coming soon

Pumped traffic rarely completes verification. Falling conversion on a country or prefix will raise an alert you can act on.

04

Channel choice

Leading with WhatsApp in suitable markets reduces reliance on SMS routes, the usual target of pumping schemes.

Fraud controls, once available, reduce risk but cannot eliminate it. Combine them with bot protection on your own forms. Read more about our approach to security.

OTP API for developers

Start and check a verification in minutes

The Verify API shares authentication, idempotency and webhooks with the rest of CommLeap's APIs. Start a verification on a channel, check the code the user enters, and subscribe to results for auditing and analytics.

  • Same fallback and fallback_after parameters as the Messages API Coming soon
  • Per-request overrides for code length, expiry and locale
  • Webhooks include every delivery attempt and the channel that succeeded
Developer overview
Compare

Choosing a channel for OTP: WhatsApp, SMS, voice or email

No single channel is best everywhere. Most enterprises combine two or three, ordered by market. This comparison covers the qualitative trade-offs; actual reach and cost depend on your countries and audience.

ConsiderationWhatsAppSMSVoiceEmail
ReachStrong where WhatsApp is widely adopted; requires the app and a data connectionAlmost any mobile phone, no app neededMobile and landline numbersAnyone with an email address
User experienceBranded message with copy-code button and Android autofill where supportedFamiliar; OS autofill on many devicesCode read aloud; helpful for accessibility and landlinesRequires switching to the inbox; can be slower
Delivery dependenciesInternet connectivity and an approved authentication templateCarrier routes and local sender registration rulesCall answer and network qualityDomain authentication and spam filtering
Cost considerationsPer delivered authentication message; rates set by Meta, vary by country and are billed by Meta directly to your WhatsApp Business AccountVaries widely by country and route; exposed to pumping fraudPer-minute rates; typically used as fallbackGenerally low per message
Good fit forPrimary channel in WhatsApp-first marketsBroad default and fallbackLast-resort fallback and accessibilityWeb sign-up, account recovery and low-risk flows

Channel reach, delivery and pricing vary by country, device and audience, and change over time. Security guidance also differs by channel: NIST SP 800-63B treats SMS and voice codes as a restricted authenticator and does not allow email for out-of-band authentication, so match each channel to the risk of the action it protects. Explore the SMS API and Voice API for channel details.

Use cases

Verification for every step of the customer lifecycle

Apply a different policy to each moment, so low-risk actions stay quick and high-risk ones get the scrutiny they need.

Sign-up and phone verification

Confirm that new users own the number or email they register with, reducing fake accounts and invalid contact data.

Login two-factor authentication

Add a possession factor to password logins, triggered every time or only for new devices and unusual locations.

Step-up for payments

Require a fresh code before high-value transfers, new payees or card changes. See banking and payments use cases.

Password reset

Let users reset credentials with a code sent to a verified channel, with short expiry and strict attempt limits.

Account recovery

Offer a secondary channel, such as email or voice, when a user has lost access to their usual number.

Sensitive account changes

Confirm changes to contact details, addresses or security settings before they take effect.

FAQ

Verify API questions, answered

What is an OTP API?

An OTP API generates and delivers one-time passwords to a user's phone or email and then confirms whether the code they enter is correct. CommLeap's Verify API handles code generation, delivery over WhatsApp, SMS, voice or email, expiry, attempt limits and checking, so you only make two API calls: one to start a verification and one to check the code.

How does WhatsApp OTP work?

WhatsApp OTPs are sent using Meta authentication templates, a message category reserved for one-time codes. The message contains the code, an optional security note and expiry time, and a copy-code button. On Android, one-tap or zero-tap autofill can pass the code directly into your app where supported. Authentication templates must be approved by Meta before use, and CommLeap helps you set them up. Learn more about the WhatsApp Business API.

Is WhatsApp OTP cheaper than SMS?

It can be in many markets, but not everywhere. Meta charges per delivered authentication message at rates that vary by country, with a higher authentication-international rate in some countries, and SMS costs vary by country and route. Meta bills WhatsApp messaging charges directly to your WhatsApp Business Account; CommLeap invoices its own fees and non-WhatsApp channel usage (SMS, voice, email) separately. CommLeap shows the expected cost per channel for your target countries so you can choose channels on real figures. Read our WhatsApp pricing guide.

What happens if the first channel fails?

Automatic channel fallback is coming soon. When it launches, you will define a fallback order and a wait time. If the first message is not delivered, or the user does not complete verification within the wait time, CommLeap will send a new attempt on the next channel, and the same verification will stay active, so your application checks the code in the same way regardless of which channel delivered it. Until then, your application chooses the channel for each verification request.

Can we generate our own codes?

Yes. By default CommLeap generates, stores and checks codes for you. If your security architecture requires it, you can pass your own code in the request and CommLeap delivers it over your chosen channels; your system then performs the check.

How does the Verify API protect against SMS pumping?

SMS pumping, also called artificially inflated traffic, happens when bots trigger verification messages to numbers that generate revenue for fraudsters. Dedicated fraud controls are coming soon: they will let you restrict verification to the countries you serve, rate-limit by phone number, prefix and IP address, and monitor conversion rates to flag unusual patterns. Today, code policies such as attempt limits and resend intervals help limit abuse, and we recommend bot protection on your sign-up forms.

Which use cases does the Verify API support?

Common uses include sign-up and phone number verification, login two-factor authentication, step-up verification for payments or sensitive account changes, password reset and account recovery. See authentication solutions for industry examples.

How is the Verify API priced?

Verification is priced per attempt or per successful verification depending on your plan. CommLeap invoices its own fees and non-WhatsApp channel usage (SMS, voice, email) separately; Meta bills WhatsApp authentication-template charges directly to your WhatsApp Business Account. Contact us for pricing based on your countries and volumes.

Make verification fast and dependable for your users

Share your markets, volumes and current OTP setup. We'll recommend a channel strategy and code policies, and can add you to early access for automatic fallback and fraud controls (coming soon).

  • Solution design with a named specialist
  • WhatsApp onboarding and verification support
  • Transparent, volume-based pricing