- Sign-in. Use our Server SDKs to authenticate users with WhatsApp OTP as the 1st factor. This integration only requires a phone number to initiate.
- Adaptive MFA. Use Server SDKs together with Client SDKs to authenticate users with WhatsApp OTP as a secondary factor. This integration requires a user ID to initiate and assumes the user has already been authenticated with a primary factor.
Portal setup
- Navigate to Authenticators in the Authsignal Portal and click on WhatsApp.
- Choose and set up a WhatsApp Provider you want to use in the next screen. Then click Connect Account.

SDK setup
Server SDK
Initialize the SDK using your secret key from the API keys page and the API URL for your region.Client SDK
Initialize the Web SDK or Mobile SDK using your tenant ID from the API keys page and your API URL.Sign-in
Scenario - Let users sign-in with WhatsApp OTP as the 1st factor.
1. Initiate challenge
Call Initiate Challenge to send an OTP to a phone number.2. Verify challenge
Once the user inputs the OTP code, call Verify Challenge to verify it.3. Claim challenge
Now that the challenge has been verified, you can lookup the user in your IdP or DB based on their phone number. For passwordless flows with a combined sign-up and sign-in UX, you may need to create the user at this point if no account exists. Then claim the challenge once you know the primary user ID associated with the phone number.Adaptive MFA
Scenario - Challenge users with WhatsApp OTP as a 2nd factor and use rules to decide when
and where in your app to trigger the challenge.
1. Track action
Use a Server SDK to track an action in your backend. This step can apply rules to determine if a challenge is required.signIn or createPayment).
Each action can have its own set of rules.
To learn more about using rules and handling different action states refer to our documentation on actions and rules.
2. Present challenge
If the action state isCHALLENGE_REQUIRED then you can present a WhatsApp OTP challenge using the Web SDK or Mobile SDK.
- Custom UI
- Pre-built UI
3. Validate action
Use the new token obtained from the client SDK to validate the action on your backend.Enrollment
Scenario - Enroll users in WhatsApp OTP while they’re authenticated so it can be used later as
a method for adaptive MFA.
1. Initiate challenge
Call Initiate Challenge to send an OTP to a phone number.2. Verify challenge
Once the user inputs the OTP code, call Verify Challenge to verify it.Update phone number
Scenario - Let users update their phone number while they’re authenticated, completing an OTP
challenge to verify the new number.
1. Initiate challenge
Call Initiate Challenge to send an OTP to the user’s new phone number.2. Verify challenge
Once the user inputs the OTP code, call Verify Challenge to verify it.Verified phone numbers
Scenario - Enroll or update a WhatsApp authenticator for a user when you’ve already verified
their phone number in another system, so it can be used later as a method for adaptive MFA.
Next steps
- Pre-built UI - Rapidly deploy WhatsApp OTP challenges using our pre-built UI
- Web SDK - Implement WhatsApp OTP challenges while building your own UI
- Mobile SDK - Implement WhatsApp OTP challenges in native mobile apps
- Adaptive MFA - Set up smart rules to trigger authentication based on risk
- Passkeys - Offer the most secure and user-friendly passwordless authentication

