Autofill passes the code to an eligible Android app. Your backend still verifies it.
Prepare the Android integration
Your app team needs:
Use the identity of the build customers actually install. A debug build and a production build may use different signing keys, so a test that works locally does not prove that the store-distributed app works.
The current YCloud contract uses
supported_apps. The older top-level package_name and signature_hash fields are deprecated; do not use them for a new integration.
Create the template
- Select the WABA and Authentication category.
- Choose the one-tap/autofill option.
- Enter the supported Android app identity and required button settings.
- Configure the optional security and expiry notices.
- Submit and wait for approval.
- Connect the approved template to your application’s verification request.
otp_type: "ONE_TAP" and the supported-app configuration. Follow Manage templates for the complete contract.
Run the customer flow
When the customer requests WhatsApp verification, initiate the required app-side handshake, send the approved authentication template, receive the code through the supported interaction, and validate it against the active request. Supply the same code in the template body and OTP URL-button parameter. The send-time parameter pattern is shown in Copy-code authentication. Bind the code to the intended session and action. An autofilled value is input—not an authorization decision.Keep fallback usable
The customer can receive a copy-code experience when autofill eligibility is not met. Non-Android customers do not receive this Android app integration. Test:- A correctly signed production app.
- A debug or differently signed build.
- The target app not installed.
- A missing or unsuccessful handshake.
- An expired or already-used code.
- A non-Android device.
Plan the current SDK migration
Meta’s current notice extends deprecation of thePendingIntent handshake method to 15 October 2026 and recommends the OTP Android SDK migration path. Review existing integrations before that deadline; a previously approved template does not migrate app code.
For implementation, use Meta authentication guidance and its linked Android integration instructions.
Track message delivery, code capture, and successful verification separately. If messages arrive but only the copy action appears, inspect app identity and handshake eligibility before changing the message body.
