Skip to main content
Verification and 2FA

SMS verification API: one-time OTP codes

Verify user sign-ups, log-ins and sensitive operations with a verification code by SMS, WhatsApp or Telegram. OTP and 2FA with the /verify API: the platform generates the code, sends it through the channel you choose in the call and checks it, with signed status webhooks so you can react instantly if a code does not arrive.

  • OTP by SMS from €0.039
  • One channel per call: SMS, WhatsApp or Telegram
  • One-time codes with expiry
  • GDPR · EU servers

What an SMS OTP is and why it is still the verification standard

Simple for the user, universal in coverage and with no apps to install: that is why the SMS verification code still protects sign-ups and log-ins all over the world.

An OTP (one-time password) is a single-use code — usually 4 to 8 digits — that you send to the user's mobile phone to prove that the number really belongs to them. It is the basis of 2FA by SMS (two-factor authentication), of sign-up verification in apps and ecommerce, of confirming sensitive operations and of signing consents.

Why SMS? Because it works on any mobile phone, with nothing to install and no data: coverage is universal. And when you want to reinforce it, WhatsApp brings its specific authentication category with an autofill button, and Telegram adds the cheapest channel, at €0.010 per message, for users who have already started the conversation with your bot — its API does not allow sending a code to the number of someone who has not, so Telegram works for re-verifying people you already have linked, not for the first sign-up. With SMSverifica the three channels live in the same REST API, with the same call: you choose the channel on each /verify/start and use SMS for everything else.

Where SMS verification is used

  • User sign-ups and registration with a verified number
  • 2FA at log-in and on password changes
  • Confirmation of orders, payments and sensitive operations
  • Single-use access codes for doors, events and restricted areas
  • Identity verification for remote clock-ins and teleworking
  • Account recovery and validation of numbers in databases

A three-step verification flow: sign-up, sending the code and validation

This is how an OTP flow works with the SMSverifica API, step by step.

1. The user signs up

Your application collects the mobile number in the registration, log-in or purchase form. From there you can delegate the code to the platform with /verify or generate it yourself and send it as a normal message.

2. You send the OTP code

One call to POST /api/v1/verify/start with the Idempotency-Key header — so a retry from your backend never duplicates the SMS or the charge — and the code reaches the phone within seconds.

3. You validate and grant access

The user types the code and your backend calls POST /api/v1/verify/check: a wrong code returns 200 with status: invalid and uses up one of the 5 attempts, not a network error in disguise. The signed webhooks confirm delivery to you.

terminal — generate and send the OTP by SMS
curl -X POST https://app.smsverifica.com/api/v1/verify/start \
  -H "X-Api-Key: sk_live_tu_api_key" \
  -H "X-Api-Secret: tu_api_secret" \
  -H "Idempotency-Key: otp-usuario-8842-intento-1" \
  -H "Content-Type: application/json" \
  -d '{
    "channel": "sms",
    "to": "+34612345678",
    "length": 6,
    "ttl_seconds": 300
  }'
terminal — check the code the user types
curl -X POST https://app.smsverifica.com/api/v1/verify/check \
  -H "X-Api-Key: sk_live_tu_api_key" \
  -H "X-Api-Secret: tu_api_secret" \
  -H "Content-Type: application/json" \
  -d '{
    "id": 5512,
    "code": "482913"
  }'

// 200 { "data": { "id": 5512, "status": "verified", "attempts_remaining": 4 } }

The same JSON with "channel": "whatsapp" (and an authentication template with {code} in its variables) or "channel": "telegram": the channel is chosen on each call. The OTP by SMS to Spain costs €0.039, the verification code by WhatsApp (authentication category) €0.005 —plus whatever Meta bills you— and by Telegram €0.010, all excl. VAT — see all the SMS rates by country and WhatsApp rates by category. If you prefer to generate the code yourself, POST /api/v1/messages sends whatever text you want and leaves the expiry and attempts logic to you.

If the SMS does not arrive: retry through another channel from your backend

An OTP that does not arrive is a user who does not sign up, an abandoned cart or an employee who cannot clock in. Here, without embellishment, is who does what when that happens.

What the platform does today. Status webhooks signed with HMAC-SHA256 notify you within seconds of every transition: sent, delivered or failed. The amount of a send that fails permanently is automatically refunded to your balance. And the routing rules hold, per channel, your primary provider and —if you have a second one contracted— the backup one the platform retries with.

What you do. Switching channel is your backend's decision: you receive message.failed and make a second call to /verify/start with "channel": "whatsapp" or "telegram". It is five lines of code, but it is worth saying clearly: the platform does not switch from SMS to WhatsApp on its own.

Planned feature, not yet available: automatic channel switching (SMS → WhatsApp → Telegram), configurable per account, is being designed and does not exist yet. Do not count on it in your planning until we announce it.

Single-use codes for access control: the perfect match for QRACCESO

Our sister platform QRACCESO handles QR access control for events, offices and venues. Together with SMSverifica, physical access gains a second factor.

Open a door with a code by SMS

Send a single-use access code by SMS or WhatsApp to open a door, a car park or a restricted area: the visitor receives it on their phone, types it in or shows it, and the access is recorded with time and person. No keys, no cards that get lost.

Verified tickets and credentials

Combine the event's QR ticket with a verification OTP when the attendee registers: a mobile number verified from sign-up, fewer duplicate tickets and capacity under control. The ticket travels by SMS, WhatsApp or Telegram; the event reminder, through the channel the attendee prefers.

Visitor notifications at reception

When a visitor arrives, the host receives the notice instantly — visitor notification by Telegram at €0.010 or by SMS/WhatsApp — and can authorise access by replying or generating a temporary code. Reception without calls or waiting.

Discover more messaging integrations with access control in the QRACCESO use cases.

Identity verification for remote clock-ins: OTP for HR and ACCESSTIME

Recording working hours has been mandatory in Spain since 2019 and is moving towards digital clock-ins. With ACCESSTIME, our time-tracking platform, SMS verification settles the last doubt: who is really clocking in?

In working-hours recording with teleworking or with mobile teams, remote clock-ins need a guarantee of identity. An OTP by SMS or WhatsApp at the moment of clocking in links the clock-in to the employee's personal mobile phone: a single-use code, validation in seconds and full traceability for inspections.

The same messaging solves HR's day-to-day: clock-in notices to employees who forgot to clock in, start- and end-of-day reminders, shift and holiday communications, or alerts to the manager when a record is missing. By Telegram, all those internal notices cost €0.010 per message; by SMS, €0.039 with practically immediate delivery.

Messaging for time tracking and HR →
  • Identity verification for remote clock-ins with a single-use code
  • Automatic clock-in notices to employees by SMS, WhatsApp or Telegram
  • HR reminders: shifts, holidays, pending documents
  • Alerts to the manager if a working-hours record is missing
  • Full traceability: delivery statuses with signed webhooks
  • GDPR compliance with servers in the EU

Best practices for implementing OTP and 2FA by SMS

The rules our own verification API applies, in case you prefer to build the flow yourself.

  • 6-digit codes generated with cryptographic randomness, never sequential.
  • Short expiry: 5 minutes is the balance between security and usability.
  • Limit the attempts at validation (3-5) and the resends per hour to stop brute-force attacks and SMS pumping.
  • Truly single use: invalidate the code as soon as it is validated or expires.
  • Use Idempotency-Key on every send: a network retry will never duplicate the SMS or the charge.
  • Listen to the webhooks message.failed so that you can launch the retry by WhatsApp or Telegram yourself straight away.
  • State the sender and the context in the text (“Your code for MYAPP…”) and ask users not to share it.
  • Start with sandbox mode —it opens on its own when you verify your email— and test the statuses: delivered, failed, read, before going into production.
Available in API v1

The /verify API: the platform generates, sends and checks the code

Two calls and not a single code table in your database: POST /api/v1/verify/start sends the OTP through the channel you specify and POST /api/v1/verify/check validates it. The platform handles expiry and the attempts limit.

  • A 4 to 8-digit code generated with cryptographic randomness (6 by default)
  • Configurable expiry between 60 and 900 seconds; 300 if you say nothing
  • 5 attempts per code and, against SMS pumping, a limit per destination: 1 start every 30 seconds and at most 3 every 10 minutes
  • The code never appears in the API responses or in the history: only in the message to the user
  • Idempotency-Key, the same authentication and the same signed webhooks as the rest of the API

What this API does not do yet: it does not switch channel on its own. Each verify/start sends through the channel you ask for; if you want to retry through another, you ask for it. Automatic switching between channels is a planned feature, with no date.

Choosing between /verify and /messages

  • /verify if you want to delegate the code, its expiry and its attempts.
  • /messages if you already have your own OTP logic and only need the sending, with the text and sender you decide.

Both charge the same: the price of the channel and the destination, with no surcharge for using /verify. All the details, parameters and error codes are in the REST API documentation.

Frequently asked questions about SMS verification and OTP codes

What is an SMS OTP code?

An OTP (one-time password) is a single-use verification code, usually 4 to 8 digits, sent to the user's mobile phone by SMS to confirm their identity at sign-up, log-in or in a sensitive operation. It expires within a few minutes and can only be used once.

Is 2FA by SMS secure?

2FA by SMS adds a real barrier to a password on its own and stands out for its universal coverage: it works on any mobile phone with nothing to install. For critical operations you can combine it with attempt limits, a short code expiry and verification through a second channel such as WhatsApp or Telegram.

How much does it cost to send a verification code?

With SMSverifica, an OTP by SMS to Spain costs €0.039, a verification code by WhatsApp (authentication category) €0.005 —Meta's conversation fees are separate— and by Telegram €0.010. Prepaid in euros, no fees and a balance that never expires.

Can I send the verification code by WhatsApp?

Yes. The WhatsApp Business API has a specific template category for verification codes (authentication), with an autofill button on the phone. With our API you send the same OTP by SMS or by WhatsApp by changing a single field in the JSON.

What happens if the SMS with the code does not arrive?

The status webhooks notify you within seconds if the SMS fails, and your backend can make a second call to /verify/start with another channel. Put plainly: you decide and trigger the channel switch, the platform does not switch on its own. What you can configure is a backup provider within the same channel, if you have a second one contracted: the platform retries through it.

Is the /verify API available?

Yes. POST /api/v1/verify/start generates the code, sends it through the channel you specify and returns the pending verification; POST /api/v1/verify/check checks it (a wrong code is a 200 with status: invalid, not a 4xx). Expiry configurable from 60 to 900 seconds, a length of 4 to 8 digits and 5 attempts per code. Automatic switching between channels is still a planned feature, with no date.

Set up your OTP verification by SMS, WhatsApp or Telegram today

Creating the account is free and needs no card. When you verify your email the account opens on its own in sandbox mode so you can integrate without spending, while we review every sign-up by hand before enabling real sending and payments. A balance that never expires and published prices, excl. VAT.