> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ycloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 一键认证

> 通过所需模板和验证流程使用一键认证体验。

一键认证允许受支持的 Android 客户点击自动填充操作，将验证码传递到您的应用中。这减少了手动复制，但仍需要应用集成和服务器端验证。

<Frame caption="Autofill passes the code to an eligible Android app. Your backend still verifies it.">
  <img src="https://mintcdn.com/lchnan/gXEJIQXV2JH2VUQJ/product-assets/english-help-2026-09-22/meta-authentication-autofill-annotated.svg?fit=max&auto=format&n=gXEJIQXV2JH2VUQJ&q=85&s=7a0bfcec572f7fdfe2cce0cf18f175d7" alt="带有自动填充按钮指示的 Meta 认证示例。" width={360} data-path="product-assets/english-help-2026-09-22/meta-authentication-autofill-annotated.svg" />
</Frame>

来源：[Meta 官方示例](https://developers.facebook.com/documentation/business-messaging/whatsapp/templates/authentication-templates/authentication-templates/)。

在 YCloud 中选择模板选项并不会在您的 Android 应用中安装该集成。

## 准备 Android 集成

您的应用团队需要：

| 项目 | 用途 |
| - | - |
| Android 包名 | 标识目标应用。 |
| 应用签名密钥哈希 | 标识允许接收验证码的已签名版本。 |
| 支持的应用配置 | 在模板中注册允许的包名和签名哈希对。 |
| 必要的握手 | 在发送验证码前确认应用的资格。 |
| 验证码接收器和后端验证 | 捕获结果并检查请求的操作。 |

请使用客户实际安装的构建版本的标识。调试版本与正式生产版本可能使用不同的签名密钥，因此在本地测试成功并不代表商店分发的应用可以正常工作。

当前 YCloud 规范使用 `supported_apps`。旧的顶层 `package_name` 和 `signature_hash` 字段已被弃用；新集成请勿使用它们。

## 创建模板

1. 选择 WABA 和 **身份验证** 类别。
2. 选择一键/自动填充选项。
3. 输入支持的 Android 应用标识和所需的按钮设置。
4. 配置可选的安全和过期提示。
5. 提交并等待审核批准。
6. 将审核通过的模板关联到应用程序的验证请求。

对于 API 创建，请使用带有 `otp_type: "ONE_TAP"` 的 OTP 按钮类型以及支持的应用配置。完整的规范要求请参见[管理模板](/zh/api-reference/guides/whatsapp-platform/manage-whatsapp-templates)。

## 运行客户流程

当客户请求 WhatsApp 验证时，发起所需的应用端握手，发送已批准的认证消息模板，通过支持的交互接收验证码，并针对当前请求进行验证。

在模板正文和 OTP URL 按钮参数中提供相同的验证码。发送时的参数模式请参见[复制验证码认证](/zh/documentation/whatsapp-business-platform/messaging/message-templates/authentication-message-templates/copy-code-authentication#send-the-same-code-in-both-positions)。

将验证码绑定到目标会话和操作。自动填充的值只是输入项，并不是授权决定。

<a id="limitations" />

## 保持备选方案可用

当不满足自动填充资格时，客户可以体验复制验证码。非 Android 客户不会获得此 Android 应用集成。

测试：

* 正确签名的生产应用。
* 调试版本或不同签名的版本。
* 未安装目标应用。
* 握手缺失或失败。
* 验证码过期或已被使用。
* 非 Android 设备。

在 iOS 26 及更高版本上，WhatsApp 认证推送通知可以提供原生键盘建议。该平台特性并不代表 Android 集成正在正常工作。

## 规划当前 SDK 迁移

Meta 的最新通知将 `PendingIntent` 握手方法的弃用时间延长至 **2026 年 10 月 15 日** ，并建议使用 OTP Android SDK 迁移路径。请在该截止日期前审查现有的集成；先前批准的模板不会自动迁移应用代码。

有关实现，请参阅 [Meta 认证指南](https://developers.facebook.com/docs/whatsapp/business-management-api/authentication-templates/) 及其链接的 Android 集成说明。

分别跟踪消息送达、验证码获取和成功验证。如果消息已送达但仅显示复制操作，请在修改消息正文之前检查应用标识和握手资格。


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.