💬 WhatsApp API @ Best Rate | Zero Setup Fee → 99.9% Uptime OTP Delivery — Try FREE Demo! 🏆 10,000+ Registered Businesses — 2,000+ Enterprise Clients Served 🚀 API Integration in Under 5 Minutes 🏅 Verified Business Badge with RCS Messaging 💬 WhatsApp API @ Best Rate | Zero Setup Fee → 99.9% Uptime OTP Delivery — Try FREE Demo! 🏆 10,000+ Registered Businesses — 2,000+ Enterprise Clients Served 🚀 API Integration in Under 5 Minutes 🏅 Verified Business Badge with RCS Messaging
Talk to Sales: India 1800 102 1822

OneTap Verify: Passwordless Login with a Secure Link

Replace typed OTPs with a one-time link. Your user taps it on WhatsApp, SMS, RCS or email and is signed in - no code to copy, no password to remember, and automatic fallback when a channel cannot reach them.

No code to typeWhatsApp, SMS, RCS, EmailSingle use + expiryOne API key
1 tapInstead of typing a 6-digit code
4 channelsWhatsApp, SMS, RCS, Email
1 useEvery link works once
Since 2009Trusted messaging platform

Quick Answer

OneTap Verify is a passwordless login and verification API. Instead of sending a 6-digit OTP that the user must copy and type, your server asks our API to send a one-time secure link. The user taps the link on WhatsApp, SMS, RCS or email, confirms with one tap, and is sent back to your app with a single-use token that your server checks with one API call. Links expire in minutes, work only once and are delivered with automatic channel fallback.

How OneTap Verify works

Five steps, a few seconds for your user.

StepWhere it happensWhat happens
1. User enters a mobile or emailYour app or websiteLogin, sign-up, checkout or any step that needs verification.
2. Your server calls the APIOneTap Verify APIOne request with the number / email, channel order and your return URL.
3. Secure link deliveredWhatsApp, SMS, RCS or emailSent on the first channel; automatic fallback to the next one if it fails.
4. User taps and confirmsSecure confirm pageOne tap on "Confirm sign-in". Link previews and mail scanners cannot use the link up.
5. Your server verifiesOneTap Verify APIThe user returns to your app with a one-time token; one call confirms who it is.

OTP or OneTap Verify?

Use both: OneTap Verify where tapping is easiest, OTP where a code fits better.

Typed OTPOneTap Verify
User effortRead, remember and type a codeOne tap
Typing mistakes and drop-offsCommon on mobileNone - nothing to type
Works for email sign-inCode in email, switch appsTap the button in the email
ChannelsSMS, WhatsApp, voice, RCSWhatsApp, SMS, RCS, email with fallback
Phishing of the code by fake callersUsers can be tricked into reading it outNothing to read out; the link works once on a confirm page

Sample request

Same CPaaS API key as the unified messaging API. {{link}} is replaced with the one-time link in every channel.

Create and send a link
curl -X POST "https://www.smsgatewayhub.com/cpaas/v1/verify-link.ashx" \
  -H "Authorization: Bearer YOUR_CPAAS_API_KEY" -H "Content-Type: application/json" \
  -d '{"to":"9198XXXXXXXX","toEmail":"user@example.com",
       "channels":["whatsapp","sms","email"],"fallbackAfter":60,
       "redirectUrl":"https://yourapp.com/auth/callback","state":"session-123",
       "appName":"Your App","expiry":600,
       "sms":{"text":"Tap to sign in to Your App: {{link}} - valid 10 min","templateId":"YOUR_DLT_TEMPLATE_ID"},
       "whatsapp":{"template":"login_link","language":"en","variables":["{{link}}"]}}'
Verify the token on your server
curl -X POST "https://www.smsgatewayhub.com/cpaas/v1/verify-link.ashx?action=verify" \
  -H "Authorization: Bearer YOUR_CPAAS_API_KEY" -H "Content-Type: application/json" \
  -d '{"token":"VALUE_OF_vl_token"}'
# -> {"verified":true,"to":"9198XXXXXXXX","state":"session-123", ...}

No redirect URL? Poll GET ?id=vl_... - status becomes confirmed when the user taps, which suits "approve the login on your phone" flows for desktop sign-in.

Why OneTap Verify

Faster sign-ins, fewer drop-offs

One tap, no typing

No code to copy between apps - the biggest reason users abandon an OTP screen.

Automatic fallback

WhatsApp first, then SMS or email - every user is reached on a channel that works.

Secure by design

Random single-use links with short expiry, a confirm step and a one-time server token.

Great for email login

A branded email with a "Sign in now" button is created for you automatically.

Full visibility

Sent, opened, confirmed and verified status for every link, plus delivery reports per channel.

One key, one API

Works with the same CPaaS key and billing as your WhatsApp, SMS, RCS and email messages.

Where to use it

App and website login

Passwordless sign-in for customers, partners and staff.

Checkout and COD

Confirm the buyer's number before dispatch with one tap.

Sign-up verification

Verify a new user's mobile or email without an OTP screen.

Desktop login approval

User approves a desktop sign-in from the phone in their pocket.

Document and consent links

Confirm identity before opening a statement, policy or e-sign step.

Account recovery

Safer password reset links with single use and short expiry.

Good to know

  • SMS in India: register the message as a DLT template and whitelist the link domain as a CTA, or operators block it.
  • WhatsApp: send the link in an approved utility template (WhatsApp authentication templates carry codes, not links).
  • Links expire in 1-60 minutes (10 by default) and work once; at most 5 links per recipient every 10 minutes.
  • Keep your API key on the server; verify the token server-side before you sign the user in.
  • Short links for SMS: send "shortLink": true and the message carries a 19-character link like sg0.co/v-Ab3dE7xQ2m - it fits in one SMS and is one domain to whitelist for DLT.

Frequently Asked Questions

OneTap Verify is a passwordless login and verification API. It sends a one-time secure link over WhatsApp, SMS, RCS or email; the user taps it and confirms, and your server verifies a single-use token instead of checking a typed OTP.

Yes. Each link is a long random value that works once and expires in minutes. The tap lands on a confirm page, so link previews and mail scanners cannot use it, and your server must verify a separate one-time token before signing the user in.

WhatsApp, SMS, RCS and email, in the order you choose, with automatic fallback to the next channel when one fails or is not delivered in time.

Yes. In India the SMS must use an approved DLT template and the link domain must be whitelisted as a CTA for your header; our team helps with both.

Yes. Many apps offer both: a one-tap link as the default and a typed OTP as an alternative. Both run on the same account and API key.

Each link is billed as the message that delivered it (WhatsApp, SMS, RCS or email) at your normal rates. Contact sales for volume pricing.

Give your users one-tap sign-in this week

Get your CPaaS API key, DLT and WhatsApp template help and sample code from our team.