> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ycloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Zero-tap authentication

> Use the zero-tap authentication experience with the required template and verification flow.

Zero-tap authentication lets a supported Android app receive a WhatsApp verification code through the required integration without asking the customer to switch to WhatsApp or tap an autofill button.

<Frame caption="Explain automatic code capture in your app before requesting WhatsApp verification. These are Meta demonstration screens.">
  <img src="https://mintcdn.com/lchnan/gXEJIQXV2JH2VUQJ/product-assets/english-help-2026-09-22/meta-zero-tap-consent-annotated.svg?fit=max&auto=format&n=gXEJIQXV2JH2VUQJ&q=85&s=ff4fd40e522756aa41d457d45cccfd7c" alt="Two Meta Android app examples highlighting the explanation of automatic WhatsApp code capture." width={720} data-path="product-assets/english-help-2026-09-22/meta-zero-tap-consent-annotated.svg" />
</Frame>

Source: [Meta official example](https://developers.facebook.com/documentation/business-messaging/whatsapp/templates/authentication-templates/zero-tap-authentication-templates).

The customer must expect automatic code capture, and your backend must validate the code and requested action.

## Confirm that zero-tap fits

Use it when you own the Android app, can implement the required integration, and can explain the automatic code capture when the customer chooses WhatsApp verification.

Use [copy-code authentication](/en/documentation/whatsapp-business-platform/messaging/message-templates/authentication-message-templates/copy-code-authentication) when you need a simpler experience without an Android handshake. Use [one-tap authentication](/en/documentation/whatsapp-business-platform/messaging/message-templates/authentication-message-templates/one-tap-authentication) when an explicit autofill action better fits the flow.

## Prepare the app and template

1. Configure the production Android package and signing-key hash.
2. Implement the required handshake and code-receiving flow.
3. Create an **Authentication** template with the zero-tap option.
4. Configure the supported app identities and the fallback button labels.
5. Review the zero-tap terms and the customer-facing explanation.
6. Submit, then test the approved template with the actual app build.

In the YCloud API, the OTP button uses `otp_type: "ZERO_TAP"`. App identities belong in `supported_apps`; the older top-level package and signature fields are deprecated.

The `zero_tap_terms_accepted` field records the business's acceptance and responsibility for the expected automatic experience. Do not set it to `true` as a troubleshooting shortcut without that review.

Fallback settings belong to the supported OTP configuration. Do not create extra arbitrary buttons to imitate Meta's fallback behavior.

## Understand the eligibility outcomes

| Situation | Expected path |
| - | - |
| Eligible Android app and successful checks | The app can capture the code automatically. |
| Zero-tap eligibility is not met | WhatsApp can show an autofill or copy-code fallback, depending on eligibility. |
| Non-Android device | Copy-code fallback rather than Android zero-tap. |
| iOS 26 or later | The authentication push notification can also provide native keyboard suggestions. |

A fallback is not automatically a delivery failure. Treat it as a supported customer path and make sure the code-entry screen remains usable.

<a id="limitations" />

## Validate securely after capture

Bind each code to the requested action and customer session. Enforce expiry, single use, and attempt limits on your server. Discard codes that do not match the active request.

Supply the same code in the template body and OTP URL-button parameter; see the [send-time component example](/en/documentation/whatsapp-business-platform/messaging/message-templates/authentication-message-templates/copy-code-authentication#send-the-same-code-in-both-positions).

Do not log code contents in analytics or crash reports. If retries create a newer code, make the older-code behavior deliberate and consistent.

## Test before release

Test the installed production build, mismatched signing identity, missing handshake, non-Android fallback, delayed delivery, expired codes, repeated requests, and duplicate processing.

Meta's current migration notice sets **15 October 2026** as the extended deprecation date for the `PendingIntent` handshake and recommends the OTP Android SDK. Update the app integration rather than assuming a template edit alone resolves the migration.

Track three separate outcomes: message delivered, code captured, and verification completed. Automatic capture does not prove the requested action succeeded.

Sources: [Meta zero-tap authentication](https://developers.facebook.com/docs/whatsapp/business-management-api/authentication-templates/zero-tap-authentication-templates/) and [YCloud template management](/en/api-reference/guides/whatsapp-platform/manage-whatsapp-templates).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.