Explain automatic code capture in your app before requesting WhatsApp verification. These are Meta demonstration screens.
Confirm that zero-tap fits
Use it when you own the Android app, can implement the required integration, and can explain the automatic code capture when the customer chooses WhatsApp verification. Use copy-code authentication when you need a simpler experience without an Android handshake. Use one-tap authentication when an explicit autofill action better fits the flow.Prepare the app and template
- Configure the production Android package and signing-key hash.
- Implement the required handshake and code-receiving flow.
- Create an Authentication template with the zero-tap option.
- Configure the supported app identities and the fallback button labels.
- Review the zero-tap terms and the customer-facing explanation.
- Submit, then test the approved template with the actual app build.
otp_type: "ZERO_TAP". App identities belong in supported_apps; the older top-level package and signature fields are deprecated.
The zero_tap_terms_accepted field records the business’s acceptance and responsibility for the expected automatic experience. Do not set it to true as a troubleshooting shortcut without that review.
Fallback settings belong to the supported OTP configuration. Do not create extra arbitrary buttons to imitate Meta’s fallback behavior.
Understand the eligibility outcomes
A fallback is not automatically a delivery failure. Treat it as a supported customer path and make sure the code-entry screen remains usable.
Validate securely after capture
Bind each code to the requested action and customer session. Enforce expiry, single use, and attempt limits on your server. Discard codes that do not match the active request. Supply the same code in the template body and OTP URL-button parameter; see the send-time component example. Do not log code contents in analytics or crash reports. If retries create a newer code, make the older-code behavior deliberate and consistent.Test before release
Test the installed production build, mismatched signing identity, missing handshake, non-Android fallback, delayed delivery, expired codes, repeated requests, and duplicate processing. Meta’s current migration notice sets 15 October 2026 as the extended deprecation date for thePendingIntent handshake and recommends the OTP Android SDK. Update the app integration rather than assuming a template edit alone resolves the migration.
Track three separate outcomes: message delivered, code captured, and verification completed. Automatic capture does not prove the requested action succeeded.
Sources: Meta zero-tap authentication and YCloud template management.
