Free & Open Source (AGPL v3)Official WhatsApp & Telegram APIs

Verify a phone number with two API calls.

WA OTP is an open-source verification gateway for your own applications. Send a one-time passcode to a consenting user over the official WhatsApp Cloud API or Telegram Bot API, then verify it with a second call. Self-hostable with FastAPI and PocketBase, with rate limits and single-use codes built in.

A verification layer you actually own.

Verification codes are the one thing almost every signup flow needs, and email alone does not reach users who live on messaging apps. WA OTP is the delivery layer for that step: one endpoint sends a code, one endpoint checks it, and you own the data.

It handles the parts that are easy to get wrong:

  • Delivery: Official WhatsApp Cloud API and Telegram Bot API integrations, using your own credentials when you self-host.
  • Abuse protection: Per-phone hourly throttles, attempt limits, single-use codes, and cryptographic number-matching for Telegram links.
  • Operations: A PocketBase back office with every send, failure, and audit row, plus mock delivery for local development.

WA OTP is that layer, extracted and made self-hostable. Two API calls, your own numbers and keys, and no lock-in if you outgrow it.

Two endpoints. That is the whole integration.

Your backend communicates with WA OTP using an API key. Codes are generated, hashed with SHA-256, throttled, and verified automatically.

POST /v1/otp/sendAuth: X-Api-Key

Dispatches a 6-digit one-time code to the target phone number over WhatsApp or Telegram.

curl -X POST https://api.waotp.codaipro.com/v1/otp/send \
  -H 'X-Api-Key: YOUR_API_KEY' \
  -H 'Content-Type: application/json' \
  -d '{
    "to": "919876543210",
    "channel": "whatsapp"
  }'
Response (200 OK):
{
  "ok": true,
  "mode": "platform",
  "channel": "whatsapp",
  "request_id": "req_8f2c1a",
  "expires_in": 300,
  "free_used": 42,
  "free_limit": 500
}
POST /v1/otp/verifyAuth: X-Api-Key

Confirms the user’s code. Single-use, expires in 5 minutes, and allows up to 3 attempts.

curl -X POST https://api.waotp.codaipro.com/v1/otp/verify \
  -H 'X-Api-Key: YOUR_API_KEY' \
  -H 'Content-Type: application/json' \
  -d '{
    "to": "919876543210",
    "code": "123456"
  }'
Response (200 OK):
{
  "ok": true,
  "verified": true
}

The two channels.

WhatsApp provides universal reach across India. Telegram provides an unmetered, zero-cost safety valve that never charges you a single rupee.

FeatureWhatsAppTelegram (₹0 Forever)
InterfaceOfficial WhatsApp Cloud APIOfficial Telegram Bot API
ReachAnyone with WhatsAppUsers who start your bot once
SetupMeta Business app + authentication template@BotFather and one webhook call
BillingMeta per-conversation pricing (platform free allowance)No per-message charge
Best forConsumer apps and general audiencesInternal tools, staging, and developer testing

How it works in three steps.

  1. 01

    1. Send a code

    Call POST /v1/otp/send with the recipient’s phone number and preferred channel (whatsapp or telegram). The gateway generates a 6-digit code, hashes it, and dispatches it.

  2. 02

    2. User enters the code

    The code arrives on WhatsApp or Telegram within seconds. It lives for 5 minutes, allows up to 3 attempts, and expires immediately after use.

  3. 03

    3. Verify with one call

    Call POST /v1/otp/verify from your backend with the number and code. You receive {"ok": true, "verified": true}. No state management needed on your end.

Engineered for safety and reliability.

Official provider APIs only

Codes go out through the WhatsApp Cloud API and the Telegram Bot API — documented, sanctioned interfaces with no unofficial clients or reverse-engineered protocols.

Consent-first verification

Built to verify the users of your own application after they request it. Telegram linking cryptographically matches the sender to the number, so a shared or spoofed contact cannot be used.

Single-use & replay-safe

Codes expire after 5 minutes or 3 wrong guesses. Support for the Idempotency-Key header ensures network retries never double-send or burn quota.

Concurrency-safe locking

FastAPI wraps sends in an asyncio lock per key, and verifications in a per-(owner, phone) lock, so quota cannot be double-spent and concurrent requests cannot race.

PocketBase back office

PocketBase v0.40.x acts as your operator control plane — view every send, failure, and audit ledger row out of the box with zero custom admin code.

Local mock delivery

Set WAOTP_MOCK_DELIVERY=1 during development to simulate real sends and verifications without needing live Meta tokens or Telegram bots.

Default safety limits.

Limits exist to protect you from quota exhaustion and phone harassment. In a self-hosted instance, all limits are data in PocketBase’s settings row — editable anytime without redeploying.

ControlDefault Value
WhatsApp OTPs / developer / month500 free
Telegram OTPs / developer / monthUnlimited (₹0)
OTPs / phone / hour (both channels)5
Code TTL (expiry)300 seconds (5 min)
Verification attempts per code3 attempts
API key rate limit10 req / minute
Active API keys per developer5

Architecture: FastAPI hot path + PocketBase back office.

WA OTP separates decision logic from storage:

  • FastAPI (:8000) owns every decision: Rate limiting, throttle checks, provider delivery, concurrency locks, and typed error responses live in FastAPI.
  • PocketBase (:8090) is your back office: PocketBase is bound to localhost and acts as the administrative control plane. You get an instant operator UI to inspect message logs, failures, and ledger entries with zero custom code.
  • Shared PocketBase support: Set WAOTP_PB_COLLECTIONS_PREFIX=waotp_ to namespace all tables on an existing PocketBase instance without interfering with other apps.

Self-Hosting Quickstart

Get the backend running locally with mock delivery in under two minutes:

# 1. Clone repository
git clone https://github.com/Luckyyaduvanshiofficial/wa-otp.git
cd wa-otp/backend

# 2. Setup virtual environment & run
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements-dev.txt
uvicorn app.main:app --port 8000

Who it’s for.

Indie developers shipping to mobile-first users

Building a community app, a society maintenance tool, or a local service directory whose users live on messaging apps? Add consent-based phone verification to your own signup flow without standing up telecom infrastructure.

Bootstrapped startups & indie SaaS

Verify new signups over a channel your users already have open, and keep costs predictable: the official Telegram Bot API for internal and test flows, the WhatsApp Cloud API for end users.

Privacy-focused self-hosters

Deploy the FastAPI and PocketBase containers on your own VPS. User phone numbers, logs, and keys stay inside your own infrastructure with zero phoning home.

Acceptable use.

WA OTP is verification infrastructure, not a bulk-messaging service. It is intended to confirm the phone number of a user who has asked to be verified by your own application.

  • Send codes only to numbers whose owners have consented to verification for your service.
  • No unsolicited or marketing messages, no spoofing, and no attempts to disguise your identity to recipients.
  • You are responsible for complying with the WhatsApp Business Terms and the Telegram Terms of Service, and for the lawful basis on which you process phone numbers.
  • Abuse triggers rate limits and key revocation. Deployments ship with per-phone hourly throttles, attempt caps, and single-use codes by default.

Straight answers.

Who is WA OTP for?
Developers who need to verify the phone number of someone who has signed up to their own application — an account-activation code, a login confirmation, or a password reset. It is an OTP delivery API, not a bulk-messaging or marketing tool, and it must only be used to message people who have consented to verification.
Which providers does it send through?
The WhatsApp Cloud API and the Telegram Bot API — both official, documented interfaces. There are no unofficial clients, reverse-engineered protocols, or shared sender lines. When you self-host, the messages go out through your own Meta and Telegram credentials, under those providers’ terms.
Why deliver over Telegram as well as WhatsApp?
The Telegram Bot API has no per-message billing, which makes it practical for internal dashboards, staging environments, and developer testing. The WhatsApp Cloud API gives you the reach of a channel most users already have installed.
What is the acceptable-use policy?
Send one-time codes only to numbers that belong to users who requested verification for your own service. Bulk or unsolicited messaging, marketing, spoofing, and messaging people who have not opted in are prohibited and are grounds for key revocation. Every deployment ships with abuse controls — 5 OTPs per phone per hour, 3 verification attempts per code, and single-use codes that expire in 5 minutes.
How does Telegram verify a phone number securely?
When an unlinked user requests an OTP, the API generates a cryptographically signed deep link to your Telegram bot. The user taps "Connect Telegram" and shares their contact. The bot verifies that contact.user_id matches the sender ID so nobody can share a friend’s number. Once linked, OTPs deliver instantly.
What is required to run WhatsApp OTP in production?
Meta Cloud API requires a verified Meta Business Account (GST/Incorporation), an international recurring credit card (due to RBI mandate rules), a clean phone number not active on standard WhatsApp, and an approved authentication template. For self-hosters with a verified Meta account, you simply drop your credentials into settings and WhatsApp goes live immediately.
Can I self-host WA OTP on my own server?
Yes. WA OTP is licensed under AGPL-3.0 and designed to run as two lightweight processes: FastAPI (hot path on port 8000) and PocketBase v0.40.x (control plane & back office on port 8090). A Next.js dashboard is also provided.
Is my user data private?
Completely. There is zero telemetry, no third-party analytics, and no phoning home. In a self-hosted instance, every phone number, message log, and API key lives in your own PocketBase database. OTP codes and API keys are stored only as SHA-256 hashes.
Can I test without any Meta or Telegram credentials?
Yes. Running with WAOTP_MOCK_DELIVERY=1 fakes upstream provider delivery while keeping every database row, quota check, throttle limit, and ledger entry completely real. You get a full, realistic integration test with zero setup.

Ready to add consent-based phone verification?