> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ycloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 零点击身份验证

> 通过所需的消息模板和验证流程使用零点击身份验证体验。

零点击身份验证允许受支持的 Android 应用通过所需的集成接收 WhatsApp 验证码，无需客户切换到 WhatsApp 或点击自动填充按钮。

<Frame caption="Explain automatic code capture in your app before requesting WhatsApp verification. These are Meta demonstration screens.">
  <img src="https://mintcdn.com/lchnan/gXEJIQXV2JH2VUQJ/product-assets/english-help-2026-09-22/meta-zero-tap-consent-annotated.svg?fit=max&auto=format&n=gXEJIQXV2JH2VUQJ&q=85&s=ff4fd40e522756aa41d457d45cccfd7c" alt="突出自动捕获 WhatsApp 验证码说明的两个 Meta Android 应用示例。" width={720} data-path="product-assets/english-help-2026-09-22/meta-zero-tap-consent-annotated.svg" />
</Frame>

来源：[Meta 官方示例](https://developers.facebook.com/documentation/business-messaging/whatsapp/templates/authentication-templates/zero-tap-authentication-templates)。

客户必须知晓并预期会自动捕获验证码，且您的后端必须验证该验证码和请求的操作。

## 确认零点击是否适用

当您拥有该 Android 应用、能够实现所需的集成，并能在客户选择 WhatsApp 验证时向其解释自动捕获验证码的流程时，可以使用此功能。

当您需要无需 Android 握手的更简单体验时，请使用 [复制代码身份验证](/zh/documentation/whatsapp-business-platform/messaging/message-templates/authentication-message-templates/copy-code-authentication)。当显式自动填充操作更契合流程时，请使用 [一键身份验证](/zh/documentation/whatsapp-business-platform/messaging/message-templates/authentication-message-templates/one-tap-authentication)。

## 准备应用和模板

1. 配置生产环境 Android 包名和签名密钥哈希。
2. 实现所需的握手和验证码接收流程。
3. 创建带有零点击选项的 **身份验证** 模板。
4. 配置受支持的应用标识和回退按钮标签。
5. 查看零点击条款以及面向客户的说明。
6. 提交审核，然后使用实际的应用构建版本测试已获批的消息模板。

在 YCloud API 中，OTP 按钮使用 `otp_type: "ZERO_TAP"`。应用标识应放在 `supported_apps` 中；旧的顶层包名和签名已弃用。

`zero_tap_terms_accepted` 字段记录了企业对预期自动体验的接受和责任。在未完成该项审查前，请勿将其设置为 `true` 作为排查问题的捷径。

回退设置属于受支持的 OTP 配置。请勿创建额外的任意按钮来模仿 Meta 的回退行为。

## 了解适用性结果

| 情况 | 预期路径 |
| - | - |
| 符合条件的 Android 应用且检查通过 | 应用可以自动捕获验证码。 |
| 不满足零点击适用条件 | WhatsApp 可根据适用情况显示自动填充或复制代码回退方案。 |
| 非 Android 设备 | 采用复制代码回退方案而非 Android 零点击。 |
| iOS 26 或更高版本 | 身份验证推送通知还可以提供原生键盘建议。 |

回退并不等同于送达失败。请将其视为受支持的客户路径，并确保验证码输入屏幕仍然可用。

<a id="limitations" />

## 捕获后安全验证

将每个验证码与请求的操作和客户会话绑定。在服务器上强制执行过期时间、单次使用和尝试次数限制。丢弃与活动请求不匹配的验证码。

在模板正文和 OTP URL 按钮参数中提供相同的验证码；请参阅[发送时组件示例](/zh/documentation/whatsapp-business-platform/messaging/message-templates/authentication-message-templates/copy-code-authentication#send-the-same-code-in-both-positions)。

不要在分析或崩溃报告中记录验证码内容。如果重试生成了较新的验证码，请确保对旧验证码的处理行为审慎且一致。

## 发布前测试

测试已安装的生产构建版本、签名标识不匹配、缺少握手、非 Android 回退、延迟送达、过期验证码、重复请求以及重复处理等情况。

Meta 当前的迁移通知将 **2026 年 10 月 15 日** 设定为 `PendingIntent` 握手的延期废弃日期，并推荐使用 OTP Android SDK。请更新应用集成，而不是仅假设修改消息模板就能完成迁移。

跟踪三个独立的结果：消息已送达、验证码已捕获以及验证已完成。自动捕获并不证明请求的操作已成功。

来源：[Meta 零点击身份验证](https://developers.facebook.com/docs/whatsapp/business-management-api/authentication-templates/zero-tap-authentication-templates/) 与 [YCloud 模板管理](/zh/api-reference/guides/whatsapp-platform/manage-whatsapp-templates)。


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.