Back to Blog

    WhatsApp OTP and Authentication Templates: How Verification Code Messages Work

    Illustration for WhatsApp OTP and Authentication Templates: How Verification Code Messages Work, VedLink AI blog

    A customer is checking out on your website. They enter their mobile number, wait for an SMS code, and the SMS arrives late, or lands in a crowded inbox, or never arrives. They leave. If you sell online or run an app with login, a slow OTP quietly costs you orders.

    WhatsApp has a dedicated message type for exactly this: the **authentication template**. This guide explains what it is, how it differs from other templates, what Meta allows and does not allow, and how a small business can put it to use.

    What Is an Authentication Template?

    On the WhatsApp Business API, any message you start outside the 24-hour customer service window must use a pre-approved template. Meta sorts templates into categories: marketing, utility, authentication and service. **Authentication** templates are only for one-time passcodes that confirm a person's identity, such as a login code or a transaction verification code.

    Because these messages are security-sensitive, Meta keeps their format tightly controlled. You choose a few options, and Meta supplies the wording. Our general explainer on WhatsApp message template approval covers the other categories.

    What an Authentication Template Looks Like

    The message body is a short, preset line that shows the code, such as "123456 is your verification code." You can switch on two optional additions:

    A security line: a reminder not to share the code with anyone.

    An expiry line: a note that the code expires in a set number of minutes.

    The template also carries a button. Meta offers a **copy code** button, which copies the code with one tap, and **one-tap autofill**, which can fill the code into your Android app automatically. Autofill needs a connection between WhatsApp and your own app, so it suits businesses with a mobile app rather than a plain website. If you only have a website, copy code is the practical choice.

    What Is Not Allowed

    Meta's rules for this category are strict, and breaking them usually means rejection or reclassification. In general, authentication templates cannot include:

    Links or URLs in the body.

    Media , such as images or documents.

    Emojis or extra free-form text beyond the options Meta provides.

    Promotion of any kind. If you want to say "shop more", send a separate marketing template to opted-in customers.

    Rules and formats change, so check Meta's current documentation or your provider's template builder before you submit.

    When Businesses Use OTP on WhatsApp

    You do not need to be a large app company to benefit. Practical uses for Indian small and mid-sized businesses include:

    Account login or sign-up on your own website, app or customer portal.

    Cash-on-delivery confirmation , where the customer shares a code to confirm an order before it ships.

    Booking verification for clinics, salons or coaching classes where fake or mistyped numbers cause no-shows.

    Delivery handover codes , where the customer shares a code with the delivery partner on arrival.

    Sensitive account changes , such as updating a phone number or address.

    For an order-focused set of messages, see our guide to order confirmation and delivery update templates.

    Why Use WhatsApp Instead of SMS

    There are real reasons, and a few honest caveats.

    Familiar app: customers check WhatsApp constantly, so the code is seen quickly.

    Easy copy: the copy-code button saves typing and typing errors.

    One thread: the code arrives where you may also send order updates and support replies.

    The caveats: the customer must have WhatsApp on that number, and you need a WhatsApp Business API account. Many businesses therefore keep SMS as a fallback for users who are not on WhatsApp. Compare channels in our guide to WhatsApp vs SMS vs email.

    What It Costs

    Meta charges per template message by category and country, and it revises its rates from time to time. We do not quote figures here because they change, so check Meta's current published rate card for India or our guide to WhatsApp Business API pricing in 2026. You can also estimate your own bill with the free cost calculator.

    How the Flow Works Technically

    Your website or app generates the one-time code and stores it with a short expiry. It then calls the WhatsApp API with the approved template and the code as the variable. The customer receives the message, copies or autofills the code, and your system checks it. WhatsApp only delivers the message. **Generating, storing, validating and expiring the code is your responsibility.**

    That means you need an API connection from your site or app. VedLink AI offers API integrations for this kind of event-based sending, so a login or checkout event can trigger the right template without manual work.

    Security Practices to Follow

    Keep codes short-lived. A few minutes is common. Reject expired codes.

    Limit retries. Cap how many times a code can be entered and how often a new one can be requested from one number.

    Use each code once. Invalidate a code as soon as it has been used.

    Never send codes on request from your own staff. Customers should only ever receive a code after they start an action themselves.

    Watch for abuse. Bots can request codes in bulk to your customers' numbers. Rate limits and a simple challenge on your form reduce this.

    A Practical Setup Checklist

    Before you go live, run through these steps with your developer or your provider's support team.

    1. Confirm API access. You need an approved WhatsApp Business API number. If you are still choosing one, read our guide to phone number requirements for India.

    2. Create the template. Choose the authentication category, switch on the security and expiry lines if you want them, and pick copy code or one-tap autofill.

    3. Wait for approval. Authentication templates are reviewed like others, so submit early.

    4. Test on your own number. Check the code arrives quickly and the button works on both Android and iPhone.

    5. Add a fallback. Show an SMS or email option if the WhatsApp message does not arrive.

    Common Mistakes

    Using a utility template for OTPs. Codes belong in the authentication category. Using the wrong one risks rejection.

    Adding a link or a discount line. This is the most common reason for rejection.

    No fallback. Some customers will not be on WhatsApp. Offer SMS or email as an alternative.

    Sending without a clear user action. Only send a code after the customer asks for it. Unwanted codes feel like spam and can hurt your sending quality. See quality rating and messaging limits.

    Frequently Asked Questions

    Can I send an OTP from the free WhatsApp Business app? No. Authentication templates are part of the WhatsApp Business API. See API vs app.

    Does the customer need to have messaged me first? No. A template can be sent without a prior conversation, provided the customer has agreed to receive messages from you.

    Can I customise the OTP wording? Only within the options Meta allows. The core text is preset.

    Is it suitable for payments? WhatsApp can carry a verification code, but payment authorisation should follow your payment provider's own rules and RBI requirements. Do not replace those with a WhatsApp code.

    The Bottom Line

    Authentication templates give you a faster, cleaner way to verify customers than a delayed SMS, as long as you respect Meta's strict format and handle the code logic securely on your side. If you already plan to send order updates and reminders on WhatsApp, adding verification keeps everything in one thread. To set it up, see our plans or book a demo.