ZupiChat
Product
Home Features Pricing
Solutions
Real Estate Healthcare Education E-commerce Agency Program
Resources
Blog Free Tools Case Studies Help Center Developer API Changelog
Compare
vs WATI vs AiSensy vs Interakt
Start Free Login to Dashboard Refer & Earn 20% Commission

WhatsApp OTP for Indian Apps: Setup and Costs

  • 04 Oct, 2026

WhatsApp OTP for Indian Apps and Websites: Setup, Templates and Costs

To send OTPs on WhatsApp in India, you need the WhatsApp Business Platform (the API, directly from Meta or through a provider) and an approved authentication template. Authentication templates use preset wording from Meta with your code as the variable, and come with a copy-code button or, on Android apps that implement it, a one-tap autofill button. Meta charges per authentication message delivered, at a rate that varies by country and changes from time to time. A reliable setup always keeps SMS as an automatic fallback for users who aren't on WhatsApp or whose message fails.

This guide is for product and engineering teams at Indian startups, fintechs, e-commerce apps and SaaS products deciding whether and how to add WhatsApp OTP.

Why teams add WhatsApp OTP

  • Delivery. SMS OTPs in India travel through DLT scrubbing and operator routes, and a slow code is a lost login. WhatsApp uses the data connection the user already has.
  • Brand trust. The message comes from your verified business name, not a six-letter sender ID many people can't recognise.
  • A known channel. Most Indian smartphone users open WhatsApp many times a day.
  • A second channel. Even if SMS stays primary, WhatsApp as a backup reduces failed logins during SMS outages.

It is not universally better. People without WhatsApp, feature-phone users and users with the app logged in on another phone still need SMS. Treat WhatsApp OTP as an addition, not a replacement.

How authentication templates work

PartWhat you controlWhat Meta controls
Body textOnly the code variablePreset wording, e.g. "[code] is your verification code."
Security lineWhether to show itWording: advises the user not to share the code
Expiry footerWhether to show it and the minutesWording of the footer
ButtonCopy-code, one-tap autofill or zero-tap (where supported)Button behaviour and fallback
LanguageWhich supported languages to createTranslated preset text

Because the wording is preset, authentication templates are simple to get approved. What you can't do is add a link, an offer or an image. Anything like that belongs in a separate utility or marketing template. Our template approval guide explains the three categories.

Copy-code vs one-tap autofill

Copy-code is a button that copies the code to the clipboard. The user switches back to your app or website and pastes it. It works everywhere: Android, iPhone and web.

One-tap autofill is for Android apps. When the user taps the button, WhatsApp hands the code directly to your app, which fills it in. It needs your app to initiate a handshake with WhatsApp before the OTP is requested, and your app's package name and signing key hash registered in the template. If the handshake isn't detected, the user sees copy-code instead, so nothing breaks.

Zero-tap, where supported, goes further and delivers the code to the app without a tap. It has extra requirements and user-experience rules, so check Meta's current documentation before relying on it.

For most Indian consumer apps, one-tap on Android with copy-code everywhere else covers nearly all users.

The login flow, step by step

  1. Let the user choose the channel. Show "Send code on WhatsApp" and "Send code by SMS". This doubles as consent.
  2. Generate the code on your server. Four to six digits from a secure random source, stored hashed with an expiry, typically five to ten minutes.
  3. Send the authentication template via the API to the number in international format (91 followed by the 10-digit mobile).
  4. Watch the delivery status. The API sends webhooks for sent, delivered and failed. If there's no "delivered" within a short window, say 10 to 20 seconds, or the send fails outright, trigger SMS fallback automatically.
  5. Verify on your server. Compare the hash, check expiry, count attempts, and invalidate the code after one successful use.
  6. Show a resend timer. Allow a resend after 30 seconds or so, and switch channel on the second attempt if the first one didn't arrive.

Security checklist

  • Rate-limit per number and per IP. OTP endpoints are a favourite target for "SMS pumping" style abuse, where attackers trigger thousands of paid messages. The same risk applies to WhatsApp OTP. Cap requests per number per hour and per IP per minute.
  • Limit verification attempts. Lock the code after five wrong tries.
  • Never log the plain code. Store a hash; mask numbers in logs.
  • Keep the security line on. It reminds users not to share the code, which matters for payment and account-change OTPs.
  • Bind the OTP to its purpose. A login code must not approve a payment or a phone-number change.
  • Protect your access token. The API token lives on your server only, never in app code or front-end JavaScript.

What it costs

Meta charges per authentication template delivered, with the rate depending on the recipient's country. Authentication messages are priced separately from marketing and utility. Rates are revised periodically, and some countries have a distinct "authentication-international" rate for businesses based elsewhere. Your provider may also add a platform fee. Check the current figures in our WhatsApp Cloud API pricing guide and compare with your SMS gateway rate including DLT charges.

Three things usually matter more than the per-message price:

  • Failed logins. If WhatsApp delivers more codes on the first try, fewer users abandon sign-up.
  • Resends. Every resend is another paid message, on either channel.
  • Abuse. Without rate limits, fraud traffic can cost more than all your genuine OTPs combined.

SMS fallback done right

SMS OTP in India needs a DLT-registered sender ID (header) and content template. Keep those active even after WhatsApp goes live. Decide your fallback rule up front: automatic after a failed WhatsApp send, automatic after no delivery receipt in a set number of seconds, or user-triggered via "Didn't get it? Send by SMS". Most teams combine the first and third. Track which channel eventually verified each login; after a month you'll know your real WhatsApp delivery rate.

Where a WhatsApp CRM fits

For OTP alone, a direct integration with the Cloud API or a provider's API is enough. A WhatsApp CRM helps when the same number also handles support replies, order updates and opt-in campaigns, because customers who reply to anything land in one shared inbox. With ZupiChat, your backend sends approved templates through the developer API while your team handles conversations in the same account; see plans if that combination is what you need.

The short version

  • WhatsApp OTP needs the API and an authentication template with Meta's preset wording.
  • Use one-tap autofill on Android apps, copy-code everywhere else.
  • Let users pick the channel, and fall back to SMS automatically on failure.
  • Rate limits, attempt limits and hashed codes matter more than the channel you choose.

Frequently Asked Questions

Is WhatsApp OTP cheaper than SMS OTP in India?

It depends on your SMS contract and Meta's current authentication rate for India, so compare the two with your real numbers. Meta charges per authentication template delivered, and SMS gateways charge per SMS plus DLT costs. The bigger difference is often delivery: many teams find WhatsApp OTPs arrive more reliably than SMS on congested routes, while SMS still reaches people who are not on WhatsApp.

Can I write my own OTP message text?

Only partly. Authentication templates on WhatsApp use preset wording set by Meta, with the code as a variable. You choose options such as adding a security line telling people not to share the code, an expiry notice, and the button type. You cannot add links, promotional text or media to an authentication template.

What is one-tap autofill for WhatsApp OTP?

On Android, an authentication template can use a one-tap autofill button that passes the code straight to your app, provided your app implements the handshake Meta documents. If the handshake is not detected, the button falls back to copy-code. On iPhone and on websites, copy-code is what users see.

Do users need to opt in to receive WhatsApp OTPs?

Meta requires opt-in before you message people on WhatsApp. For OTP, the simplest approach is to let the user choose WhatsApp as the delivery channel on the login screen, which is both clear consent and a good user experience. Always offer SMS as an alternative.

What happens if the user's number is not on WhatsApp?

The send fails and the API reports it. Your system should then fall back to SMS automatically, ideally within a few seconds, so the user does not sit waiting for a code that will never arrive. Remember that the fallback SMS still needs DLT-registered templates in India.

ZupiChat is built and maintained by Codelith Lab, a software company in Pune building websites, mobile apps and AI automation for Indian businesses.

More Blogs

How WhatsApp CRM Lifts Customer Engagement

How WhatsApp CRM Lifts Customer Engagement In today’s fast-paced digital world, customer engagement...

  • 06 Feb, 2025
5 Ways to Automate Marketing with ZupiChat

5 Ways to Automate Marketing with ZupiChat In today’s fast-paced business world, efficiency is every...

  • 06 Feb, 2025
Why You Need a WhatsApp Campaign Manager

Why You Need a WhatsApp Campaign Manager In an era where instant messaging dominates communication,...

  • 08 Feb, 2025
WhatsApp Short Links and Chat Widgets

WhatsApp Short Links and Chat Widgets In the competitive world of digital marketing, even a small de...

  • 08 Feb, 2025
The WhatsApp Sales Funnel Explained

The WhatsApp Sales Funnel Explained WhatsApp is no longer just a messaging app — it’s a high-convers...

  • 01 Jun, 2025
ZupiChat for Agencies and Startups

ZupiChat for Agencies and Startups In today’s hyper-competitive market, agencies and startups need s...

  • 01 Jun, 2025

We may utilize cookies when you access our website, including any related media platforms or mobile applications. These technologies are employed to enhance site functionality and optimize your interactions with our services.