Send and check a WhatsApp code from your website (API)

The two calls your server makes: send a code to a number, then check the code the person typed.

6 min read

Every request goes from your server to Chatmizer with your key in the header: Authorization: Bearer followed by your key. Keep the key in an environment variable; never put it in a web page or a mobile app, where anyone could read it.

1. Send a code

POST /api/v1/wa/verify with the number in international format, for example {"to": "+201005117920", "locale": "ar"}. You get back an id, the time the code expires and when another code may be sent. Keep the id with the person's sign-up.

2. Check the code

POST /api/v1/wa/verify/check with {"id": "…", "code": "482913"}. The answer has valid: true exactly once, when the right code is entered. A wrong code answers valid: false with the tries left; after too many, the verification fails and a new code is needed.

Answers to plan for

  • resend_too_soon (429): the person pressed Resend too quickly. Wait the seconds in Retry-After.
  • phone_limit_reached (429): this number had too many codes this hour.
  • invalid_to (422): the number has no country code. Ask for it with + and the country code.
  • country_not_allowed (422): the app only sends to the countries you allowed in Settings.
  • template_not_approved (409): Meta has not approved the code message yet.
  • send_failed (502): WhatsApp refused the message, with its reason. Offer another way to verify.

Did this answer your question?

Not quite — ask our team

Still stuck?

Our team answers real questions from real people. Customers open a ticket inside Chatmizer; everyone else can message us.