Quick Answer
OneTap Verify is a passwordless login and verification API. Instead of sending a 6-digit OTP that the user must copy and type, your server asks our API to send a one-time secure link. The user taps the link on WhatsApp, SMS, RCS or email, confirms with one tap, and is sent back to your app with a single-use token that your server checks with one API call. Links expire in minutes, work only once and are delivered with automatic channel fallback.
Sample request
Same CPaaS API key as the unified messaging API. {{link}} is replaced with the one-time link in every channel.
Create and send a link
curl -X POST "https://www.smsgatewayhub.com/cpaas/v1/verify-link.ashx" \
-H "Authorization: Bearer YOUR_CPAAS_API_KEY" -H "Content-Type: application/json" \
-d '{"to":"9198XXXXXXXX","toEmail":"user@example.com",
"channels":["whatsapp","sms","email"],"fallbackAfter":60,
"redirectUrl":"https://yourapp.com/auth/callback","state":"session-123",
"appName":"Your App","expiry":600,
"sms":{"text":"Tap to sign in to Your App: {{link}} - valid 10 min","templateId":"YOUR_DLT_TEMPLATE_ID"},
"whatsapp":{"template":"login_link","language":"en","variables":["{{link}}"]}}'
Verify the token on your server
curl -X POST "https://www.smsgatewayhub.com/cpaas/v1/verify-link.ashx?action=verify" \
-H "Authorization: Bearer YOUR_CPAAS_API_KEY" -H "Content-Type: application/json" \
-d '{"token":"VALUE_OF_vl_token"}'
# -> {"verified":true,"to":"9198XXXXXXXX","state":"session-123", ...}
No redirect URL? Poll GET ?id=vl_... - status becomes confirmed when the user taps, which suits "approve the login on your phone" flows for desktop sign-in.