Authentication template
WhatsApp OTP template: the authentication format
The WhatsApp OTP template format Meta requires: the fixed wording, the optional security line and expiry, the copy code button, and what authentication templates cannot contain.
The short answer
A WhatsApp OTP is an authentication template, and Meta writes its wording. The body is fixed: the code, then “is your verification code.” You choose two options: a security line, “For your security, do not share this code.”, and an expiry footer between 1 and 90 minutes. The button copies the code, fills it into your app, or passes it on with no tap at all.
This code expires in 10 minutes.
10:24 am
Category: Authentication Name: otp_verification
{{1}} is your verification code. For your security, do not share this code.
This code expires in 10 minutes.Buttons: copy code
What each variable holds
- {{1}}
- The one-time code, up to 15 characters
Meta needs an example value for each variable when it reviews the template. The ones in the preview are examples.
A variant
This code expires in 5 minutes.
10:24 am
Without the security line
The shortest form Meta allows: the code line alone, with or without the expiry footer.
Category: Authentication Name: otp_short
{{1}} is your verification code.
This code expires in 5 minutes.Buttons: copy code
When to send it
- At sign-up, to recover an account, and at a sensitive step such as a payment, which are the uses Meta names. Many apps also use it at login.
- Immediately, while the person is waiting on the screen.
- With an expiry that matches your system's, so the message never promises a longer window than the code has.
What gets it rejected or re-categorised
- Custom wording. Meta does not allow custom text in authentication templates.
- Links, media or emoji, none of which are allowed in authentication templates.
- Codes longer than 15 characters.
Our public API sends authentication templates with their one-time password button like any other template, with scoped keys and idempotency keys so a retried request does not send a second code.
The developer platformQuestions
What is the WhatsApp OTP template format?
Meta fixes it: the code, then “is your verification code.” Optionally, “For your security, do not share this code.”, and a footer that says the code expires in a number of minutes between 1 and 90. The button is copy code, one-tap autofill or zero-tap.
Can I customise the WhatsApp OTP message?
No. Meta does not allow custom text, links, media or emoji in authentication templates. You choose only the security line, the expiry and the button type.
How long can a WhatsApp OTP stay valid?
The expiry line can say anything from 1 to 90 minutes. Match it to how long your system actually accepts the code.
Talk to us.
In a forty-minute call we go through what you send today, what it costs you, and what a flagged number would cost you. Then we set up a workspace on your own Meta app and build the first campaign with you.