1. The user signs up
Your application collects the mobile number in the registration, log-in or purchase form. From there you can delegate the code to the platform with /verify or generate it yourself and send it as a normal message.
Verify user sign-ups, log-ins and sensitive operations with a verification code by SMS, WhatsApp or Telegram. OTP and 2FA with the /verify API: the platform generates the code, sends it through the channel you choose in the call and checks it, with signed status webhooks so you can react instantly if a code does not arrive.
Simple for the user, universal in coverage and with no apps to install: that is why the SMS verification code still protects sign-ups and log-ins all over the world.
An OTP (one-time password) is a single-use code — usually 4 to 8 digits — that you send to the user's mobile phone to prove that the number really belongs to them. It is the basis of 2FA by SMS (two-factor authentication), of sign-up verification in apps and ecommerce, of confirming sensitive operations and of signing consents.
Why SMS? Because it works on any mobile phone, with nothing to install and no data: coverage is universal. And when you want to reinforce it, WhatsApp brings its specific authentication category with an autofill button, and Telegram adds the cheapest channel, at €0.010 per message, for users who have already started the conversation with your bot — its API does not allow sending a code to the number of someone who has not, so Telegram works for re-verifying people you already have linked, not for the first sign-up. With SMSverifica the three channels live in the same REST API, with the same call: you choose the channel on each /verify/start and use SMS for everything else.
This is how an OTP flow works with the SMSverifica API, step by step.
Your application collects the mobile number in the registration, log-in or purchase form. From there you can delegate the code to the platform with /verify or generate it yourself and send it as a normal message.
One call to POST /api/v1/verify/start with the Idempotency-Key header — so a retry from your backend never duplicates the SMS or the charge — and the code reaches the phone within seconds.
The user types the code and your backend calls POST /api/v1/verify/check: a wrong code returns 200 with status: invalid and uses up one of the 5 attempts, not a network error in disguise. The signed webhooks confirm delivery to you.
curl -X POST https://app.smsverifica.com/api/v1/verify/start \
-H "X-Api-Key: sk_live_tu_api_key" \
-H "X-Api-Secret: tu_api_secret" \
-H "Idempotency-Key: otp-usuario-8842-intento-1" \
-H "Content-Type: application/json" \
-d '{
"channel": "sms",
"to": "+34612345678",
"length": 6,
"ttl_seconds": 300
}'
curl -X POST https://app.smsverifica.com/api/v1/verify/check \
-H "X-Api-Key: sk_live_tu_api_key" \
-H "X-Api-Secret: tu_api_secret" \
-H "Content-Type: application/json" \
-d '{
"id": 5512,
"code": "482913"
}'
// 200 { "data": { "id": 5512, "status": "verified", "attempts_remaining": 4 } }
The same JSON with "channel": "whatsapp" (and an authentication template with {code} in its variables) or "channel": "telegram": the channel is chosen on each call. The OTP by SMS to Spain costs €0.039, the verification code by WhatsApp (authentication category) €0.005 —plus whatever Meta bills you— and by Telegram €0.010, all excl. VAT — see all the SMS rates by country and WhatsApp rates by category. If you prefer to generate the code yourself, POST /api/v1/messages sends whatever text you want and leaves the expiry and attempts logic to you.
An OTP that does not arrive is a user who does not sign up, an abandoned cart or an employee who cannot clock in. Here, without embellishment, is who does what when that happens.
What the platform does today. Status webhooks signed with HMAC-SHA256 notify you within seconds of every transition: sent, delivered or failed. The amount of a send that fails permanently is automatically refunded to your balance. And the routing rules hold, per channel, your primary provider and —if you have a second one contracted— the backup one the platform retries with.
What you do. Switching channel is your backend's decision: you receive message.failed and make a second call to /verify/start with "channel": "whatsapp" or "telegram". It is five lines of code, but it is worth saying clearly: the platform does not switch from SMS to WhatsApp on its own.
Planned feature, not yet available: automatic channel switching (SMS → WhatsApp → Telegram), configurable per account, is being designed and does not exist yet. Do not count on it in your planning until we announce it.
Your verification code is 482913. It expires in 5 minutes.
✗ Failed: rejected by the provider — amount returned to the balance482913 is your verification code. Tap to autofill.
✓ Delivered in 2.1 sEvent access code: 482913. Valid once only.
✓ DeliveredOur sister platform QRACCESO handles QR access control for events, offices and venues. Together with SMSverifica, physical access gains a second factor.
Send a single-use access code by SMS or WhatsApp to open a door, a car park or a restricted area: the visitor receives it on their phone, types it in or shows it, and the access is recorded with time and person. No keys, no cards that get lost.
Combine the event's QR ticket with a verification OTP when the attendee registers: a mobile number verified from sign-up, fewer duplicate tickets and capacity under control. The ticket travels by SMS, WhatsApp or Telegram; the event reminder, through the channel the attendee prefers.
When a visitor arrives, the host receives the notice instantly — visitor notification by Telegram at €0.010 or by SMS/WhatsApp — and can authorise access by replying or generating a temporary code. Reception without calls or waiting.
Discover more messaging integrations with access control in the QRACCESO use cases.
Recording working hours has been mandatory in Spain since 2019 and is moving towards digital clock-ins. With ACCESSTIME, our time-tracking platform, SMS verification settles the last doubt: who is really clocking in?
In working-hours recording with teleworking or with mobile teams, remote clock-ins need a guarantee of identity. An OTP by SMS or WhatsApp at the moment of clocking in links the clock-in to the employee's personal mobile phone: a single-use code, validation in seconds and full traceability for inspections.
The same messaging solves HR's day-to-day: clock-in notices to employees who forgot to clock in, start- and end-of-day reminders, shift and holiday communications, or alerts to the manager when a record is missing. By Telegram, all those internal notices cost €0.010 per message; by SMS, €0.039 with practically immediate delivery.
Messaging for time tracking and HR →The rules our own verification API applies, in case you prefer to build the flow yourself.
Idempotency-Key on every send: a network retry will never duplicate the SMS or the charge.message.failed so that you can launch the retry by WhatsApp or Telegram yourself straight away.Two calls and not a single code table in your database: POST /api/v1/verify/start sends the OTP through the channel you specify and POST /api/v1/verify/check validates it. The platform handles expiry and the attempts limit.
Idempotency-Key, the same authentication and the same signed webhooks as the rest of the APIWhat this API does not do yet: it does not switch channel on its own. Each verify/start sends through the channel you ask for; if you want to retry through another, you ask for it. Automatic switching between channels is a planned feature, with no date.
/verify and /messages/verify if you want to delegate the code, its expiry and its attempts./messages if you already have your own OTP logic and only need the sending, with the text and sender you decide.Both charge the same: the price of the channel and the destination, with no surcharge for using /verify. All the details, parameters and error codes are in the REST API documentation.
An OTP (one-time password) is a single-use verification code, usually 4 to 8 digits, sent to the user's mobile phone by SMS to confirm their identity at sign-up, log-in or in a sensitive operation. It expires within a few minutes and can only be used once.
2FA by SMS adds a real barrier to a password on its own and stands out for its universal coverage: it works on any mobile phone with nothing to install. For critical operations you can combine it with attempt limits, a short code expiry and verification through a second channel such as WhatsApp or Telegram.
With SMSverifica, an OTP by SMS to Spain costs €0.039, a verification code by WhatsApp (authentication category) €0.005 —Meta's conversation fees are separate— and by Telegram €0.010. Prepaid in euros, no fees and a balance that never expires.
Yes. The WhatsApp Business API has a specific template category for verification codes (authentication), with an autofill button on the phone. With our API you send the same OTP by SMS or by WhatsApp by changing a single field in the JSON.
The status webhooks notify you within seconds if the SMS fails, and your backend can make a second call to /verify/start with another channel. Put plainly: you decide and trigger the channel switch, the platform does not switch on its own. What you can configure is a backup provider within the same channel, if you have a second one contracted: the platform retries through it.
Yes. POST /api/v1/verify/start generates the code, sends it through the channel you specify and returns the pending verification; POST /api/v1/verify/check checks it (a wrong code is a 200 with status: invalid, not a 4xx). Expiry configurable from 60 to 900 seconds, a length of 4 to 8 digits and 5 attempts per code. Automatic switching between channels is still a planned feature, with no date.
Creating the account is free and needs no card. When you verify your email the account opens on its own in sandbox mode so you can integrate without spending, while we review every sign-up by hand before enabling real sending and payments. A balance that never expires and published prices, excl. VAT.