Skip to main content
Copy-code authentication lets the customer copy a verification code from WhatsApp and enter it into your application.
Meta authentication example with the Copy code button indicated.

The customer copies the code, then enters it in your application. The code and expiry shown are demonstration values.

Source: Meta official example. WhatsApp delivers the code. Your backend creates it, checks it, expires it, and decides whether the requested action is authorized.

Create the authentication template

  1. Open Templates, select the WABA, and create an Authentication template.
  2. Choose the copy-code option.
  3. Decide whether to include the security recommendation and expiry notice.
  4. Set an expiry notice that matches your intended verification policy.
  5. Submit the template and confirm approval for the intended language.
Authentication uses prescribed message content. Do not add a promotion, media header, or arbitrary website button to turn it into a general-purpose message. For API creation, use the OTP button with otp_type: "COPY_CODE". This is different from the COPY_CODE promotional button used in a coupon template.

Design the request-to-verification flow

  1. The customer requests a code for a specific action in your application.
  2. Your backend generates a short-lived, single-use code and binds it to that request.
  3. Your system sends the approved template to the confirmed destination.
  4. The customer copies or enters the code.
  5. Your backend validates the request, code, expiry, and attempt limit.
  6. Only a successful backend check completes authentication.
Make the code-entry screen explain where the code was sent. Provide a controlled resend option and a way to correct the number. Do not expose whether an unrelated person’s account exists through overly specific error messages.

Send the same code in both positions

Authentication sending uses the code in the message body and in the OTP button’s URL parameter. These values must agree. Example of the template components only, with a fictional code:
Do not replace this OTP URL parameter with the marketing coupon_code parameter. Use Send WhatsApp messages for the full request and keep real codes out of logs.

Align the three expiry controls

The backend code expiry, the template’s visible expiry notice, and the message delivery time-to-live are separate controls. Setting the notice does not configure your backend. For a five-minute verification flow, enforce five minutes on the server, display the matching notice, and choose a delivery validity that does not allow an already-useless code to arrive much later. See Authentication templates for the current TTL range and defaults.

Test the failure paths

Test a valid code, wrong code, expired code, reuse after success, repeated resend, changed phone number, and delayed delivery. Decide whether a new request invalidates older codes and make that behavior clear to the customer. On iOS 26 and later, Meta documents native keyboard suggestions from the WhatsApp push notification, effective 15 June 2026. This is separate from Android one-tap integration and does not replace backend verification. A delivered or read message is not proof of authentication. Sources: Meta authentication templates and YCloud template management.