Verify a Phone Number in Python Without Touching SMS

A verification code should cost you one HTTP call, not a WhatsApp Business Platform project. This guide builds a working WhatsApp OTP API Python flow with requests: send the code, verify what the user typed, and handle the errors that show up in production.

This guide uses Replio’s WhatsApp OTP endpoint because it is a single JSON POST with no SDK to install. The shape of the flow is the same whichever provider you use, so the structure transfers.

WhatsApp OTP API Python flow from send through verify
The four steps of a WhatsApp OTP API Python integration.

Before you write any Python code

Three things need to exist first. A WhatsApp number connected to your provider account. At least one approved Authentication template on the WhatsApp Business Account. An API key.

Keep the key server-side. It sends from your verified business number, so a leaked key means someone else messaging your customers under your brand.

WhatsApp OTP API Python: sending the code

One POST sends the code. You can pass a code you generated yourself, or omit it and let the provider generate, hash and store one for you.

import os, requests

resp = requests.post(
    "https://engine-production-2647.up.railway.app/api/otp/send",
    headers={"Authorization": f"Bearer {os.environ['REPLIO_OTP_KEY']}"},
    json={
        "phone": "447911123456",
        "idempotency_key": f"signup-{signup_id}",
    },
    timeout=15,
)
resp.raise_for_status()
data = resp.json()
# data["verify_enabled"] is True

A success looks like this:

{
  "ok": true,
  "sent_to": "+447911123456",
  "template": "verify_code",
  "credits_charged": 1,
  "verify_enabled": false
}

Read verify_enabled carefully. It is true only when you omitted the code. That flag tells you whether the verify endpoint has anything to check.

Verifying what the user typed back

If you let the provider generate the code, check what the user typed with a second call.

resp = requests.post(
    "https://engine-production-2647.up.railway.app/api/otp/verify",
    headers={"Authorization": f"Bearer {os.environ['REPLIO_OTP_KEY']}"},
    json={"phone": "447911123456", "code": user_input},
    timeout=15,
)

if resp.ok and resp.json().get("verified"):
    return complete_signup()

err = resp.json()["detail"]["code"]
if err == "incorrect_code":
    return show("That code is not right.")
if err == "code_expired":
    return show("That code expired. Send a new one.")
if err == "too_many_attempts":
    return force_resend()
raise RuntimeError(err)

A correct code returns { "ok": true, "verified": true }. A wrong or expired one is a normal 400, not a 200 with a false flag. Handle it as an error branch.

Where this fits in your signup flow

Treat the send and the verify as two separate states in your own model, not one blocking call. Send the code, store the signup attempt, and return control to the user. Verify runs later, when they submit the form.

That separation matters when things go wrong. If the verify call fails, you still hold the signup attempt and can offer a resend without losing the user’s progress. If you couple the two, a network blip drops them back to the start.

Rate limits sit on the recipient as well as the account. Five codes to one number per hour, and ten verify attempts per number per ten minutes. Surface a clear message when you hit those rather than a generic failure, because a user who resends four times in a minute will hit them.

One detail trips people up on the first run. The phone number goes in international format as digits. A leading plus sign, spaces and dashes are accepted and stripped, but a local-format number without a country code is rejected as invalid_phone. Normalise before you send.

Only a delivered send costs a credit. Rejected requests, rate limits and test-mode calls are free, so strict validation on your side costs nothing.

Handling the errors that actually happen

Branch on the machine-readable code field, never on the human-readable message. The message wording can change at any time; the codes are the contract.

  • incorrect_code — wrong digits. Let the user retry.
  • code_expired — past its time to live. Offer a resend.
  • too_many_attempts — five wrong guesses burn the code. Force a new one.
  • recipient_rate_limited — five codes to one number in an hour. Back off.
  • upstream_error — WhatsApp was unreachable. Safe to retry.

Two habits that save you money and credits

Pass an idempotency key. Networks time out after a send has already happened, and a blind retry sends a second code and spends a second credit. With a key tied to the signup attempt, a retry returns the original result instead.

Then build against a test key. A test credential validates the whole request and applies every rule, but sends nothing and bills nothing.

Hardening the flow before launch

Set a short time to live. Five minutes is the common default and it limits the window for a stolen code. Cap wrong guesses. Never log the code itself.

If you are weighing this against your current SMS provider, we compared the two channels in WhatsApp OTP vs SMS. The full parameter list and error table live in the Replio WhatsApp OTP API reference, and Meta documents the template rules in its message template guide. For context on running WhatsApp as a support channel too, see our piece on answering WhatsApp and Instagram without working nights.

Frequently asked questions

Do I need an SDK for Python?

No. It is one JSON POST with a bearer token, so your language’s standard HTTP client is enough.

Should I generate the code myself?

Either works. Pass your own code and the provider only delivers it. Omit it and the provider generates one, stores a hash, and gives you a verify endpoint.

How long does a code stay valid?

Five minutes by default, configurable between 60 and 1800 seconds when the provider generates the code.

What if the user never receives it?

Check the error code on the send. If the number has no WhatsApp account the send fails, which is your cue to fall back to SMS.

Is the code stored anywhere?

Replio stores only a sha256 hash of codes it generates, never the code itself. Codes you supply are not stored at all.

Related Guides

The Verification Flow You Can Ship in an Afternoon (Node.js)

Sending a verification code should be one HTTP call, not a week of WhatsApp Business Platform integration. This guide builds a working WhatsApp OTP API Node.js flow end to end: send the code, verify what the user typed, and handle the failures that actually occur in production.

This guide uses Replio’s WhatsApp OTP endpoint because it is a single JSON POST with no SDK to install. The shape of the flow is the same whichever provider you use, so the structure transfers.

WhatsApp OTP API Node.js flow from send through verify
The four steps of a WhatsApp OTP API Node.js integration.

Before you write any Node.js code

Three things need to exist first. A WhatsApp number connected to your provider account. At least one approved Authentication template on the WhatsApp Business Account. An API key.

Keep the key server-side. It sends from your verified business number, so a leaked key means someone else messaging your customers under your brand.

WhatsApp OTP API Node.js: sending the code

One POST sends the code. You can pass a code you generated yourself, or omit it and let the provider generate, hash and store one for you.

const res = await fetch("https://engine-production-2647.up.railway.app/api/otp/send", {
  method: "POST",
  headers: {
    "Authorization": `Bearer ${process.env.REPLIO_OTP_KEY}`,
    "Content-Type": "application/json"
  },
  body: JSON.stringify({
    phone: "447911123456",
    idempotency_key: `signup-${signupId}`
  })
});

const data = await res.json();
if (!res.ok) throw new Error(data.detail.code);
// data.verify_enabled === true

A success looks like this:

{
  "ok": true,
  "sent_to": "+447911123456",
  "template": "verify_code",
  "credits_charged": 1,
  "verify_enabled": false
}

Read verify_enabled carefully. It is true only when you omitted the code. That flag tells you whether the verify endpoint has anything to check.

Verifying what the user typed back

If you let the provider generate the code, check what the user typed with a second call.

const res = await fetch("https://engine-production-2647.up.railway.app/api/otp/verify", {
  method: "POST",
  headers: {
    "Authorization": `Bearer ${process.env.REPLIO_OTP_KEY}`,
    "Content-Type": "application/json"
  },
  body: JSON.stringify({ phone: "447911123456", code: userInput })
});

if (res.ok) {
  const { verified } = await res.json();
  if (verified) return completeSignup();
}

const { detail } = await res.json();
switch (detail.code) {
  case "incorrect_code":    return show("That code is not right.");
  case "code_expired":      return show("That code expired. Send a new one.");
  case "too_many_attempts": return forceResend();
  default:                  throw new Error(detail.code);
}

A correct code returns { "ok": true, "verified": true }. A wrong or expired one is a normal 400, not a 200 with a false flag. Handle it as an error branch.

One detail trips people up on the first run. The phone number goes in international format as digits. A leading plus sign, spaces and dashes are accepted and stripped, but a local-format number without a country code is rejected as invalid_phone. Normalise before you send, not after the first support ticket.

Note also that only a delivered send costs a credit. Rejected requests, rate limits and test-mode calls are free, so aggressive validation on your side costs you nothing.

Where this fits in your signup flow

Treat the send and the verify as two separate states in your own model, not one blocking call. Send the code, store the signup attempt, and return control to the user. Verify runs later, when they submit the form.

That separation matters when things go wrong. If the verify call fails, you still hold the signup attempt and can offer a resend without losing the user’s progress. If you couple the two, a network blip drops them back to the start.

Rate limits sit on the recipient as well as the account. Five codes to one number per hour, and ten verify attempts per number per ten minutes. Surface a clear message when you hit those rather than a generic failure, because a user who resends four times in a minute will hit them.

Handling the errors that actually happen

Branch on the machine-readable code field, never on the human-readable message. The message wording can change at any time; the codes are the contract.

  • incorrect_code — wrong digits. Let the user retry.
  • code_expired — past its time to live. Offer a resend.
  • too_many_attempts — five wrong guesses burn the code. Force a new one.
  • recipient_rate_limited — five codes to one number in an hour. Back off.
  • upstream_error — WhatsApp was unreachable. Safe to retry.

Two habits that save you money and credits

Pass an idempotency key. Networks time out after a send has already happened, and a blind retry sends a second code and spends a second credit. With a key tied to the signup attempt, a retry returns the original result instead.

Then build against a test key. A test credential validates the whole request and applies every rule, but sends nothing and bills nothing.

Hardening the flow before launch

Set a short time to live. Five minutes is the common default and it limits the window for a stolen code. Cap wrong guesses. Never log the code itself.

If you are weighing this against your current SMS provider, we compared the two channels in WhatsApp OTP vs SMS. The full parameter list and error table live in the Replio WhatsApp OTP API reference, and Meta documents the template rules in its message template guide. For context on running WhatsApp as a support channel too, see our piece on answering WhatsApp and Instagram without working nights.

Frequently asked questions

Do I need an SDK for Node.js?

No. It is one JSON POST with a bearer token, so your language’s standard HTTP client is enough.

Should I generate the code myself?

Either works. Pass your own code and the provider only delivers it. Omit it and the provider generates one, stores a hash, and gives you a verify endpoint.

How long does a code stay valid?

Five minutes by default, configurable between 60 and 1800 seconds when the provider generates the code.

What if the user never receives it?

Check the error code on the send. If the number has no WhatsApp account the send fails, which is your cue to fall back to SMS.

Is the code stored anywhere?

Replio stores only a sha256 hash of codes it generates, never the code itself. Codes you supply are not stored at all.

Related Guides

Apple Just Admitted Vision Pro Isn’t Working — 200 Jobs Are Gone

The Apple Vision Pro layoffs cut roughly 200 jobs in August 2026. The cuts split about evenly between the company’s Vision Pro division and its Siri and broader software teams. The move counts as one of Apple’s most visible workforce reductions in years. It lands just over a year after Vision Pro launched to heavy hype, followed by much quieter sales.

Around 100 of the cuts hit Vision Pro staff, concentrated in gaming and immersive video teams. The other 100 came from Siri and software groups. Apple has not issued a detailed public breakdown of the reasoning team by team. But the pattern of cuts points toward a deliberate pivot in where the company plans to put its engineering resources next.

What the Apple Vision Pro layoffs actually cut

The Vision Pro-side reductions concentrate on teams building games and immersive video content for the headset, not the core hardware or operating system group. That distinction matters. It suggests Apple isn’t necessarily halting Vision Pro development outright. Instead, the company appears to be scaling back investment in the content categories meant to make the headset a mainstream entertainment device.

Virtual reality headset similar to Apple Vision Pro, subject of the layoffs

Why Siri’s old team is also affected

The Siri-side cuts target employees who worked on the assistant’s older architecture. Apple has been rebuilding Siri around newer generative AI models. That overhaul reportedly calls for different technical skills than the legacy voice-assistant codebase required. Workers on the older system, rather than the new AI-driven rebuild, appear to have borne the brunt of this round of cuts.

The bigger pivot: from headsets to AI glasses

Both sets of cuts point to the same underlying story. Apple is shifting resources away from Vision Pro’s original pitch as an immersive entertainment headset. Instead, the company is leaning toward lightweight, AI-powered smart glasses, alongside the generative AI rebuild of Siri. Vision Pro launched in 2025 amid enormous anticipation, but adoption has lagged well behind the hype. Apple has faced months of speculation about how committed it remains to mixed reality as a category.

How this fits Apple’s wider 2026 layoff wave

Apple’s cuts landed in the middle of a broader wave of technology-sector layoffs in August 2026. Reports of workforce reductions also hit TikTok, LinkedIn and Netflix during the same stretch. Apple rarely announces large layoffs. Cutting 200 positions across two flagship, forward-looking teams stands out even against that backdrop.

What happens next for Apple’s mixed reality bets

Apple has given no public timeline for a next-generation headset or its rumored AI glasses. The company has not said whether further Vision Pro-related cuts are coming. One thing is clear: near-term product priorities are shifting. Teams tied to Vision Pro’s original entertainment-first pitch now face a smaller role in that future than they did a year ago.

Apple is offering some affected employees internal transfers to teams working on the new Siri AI system and other active product lines, according to reporting on the cuts. Not every displaced worker is expected to find a matching role inside the company. Analysts covering Apple expect smaller, less publicized rounds of reshuffling to continue as the smart-glasses project moves from early development toward an actual product timeline.

Apple layoffs: what employees and buyers want to know

How many jobs were cut? Roughly 200, split about evenly between Vision Pro and Siri/software teams.

Which Vision Pro teams were hit? Mostly gaming and immersive video teams within the division.

Why cut Siri staff too? The cuts targeted the older Siri architecture, since the newer AI-driven Siri needs different expertise.

Is Apple discontinuing Vision Pro? No official discontinuation has been announced, but resources appear to be shifting toward AI glasses.

Is this part of a wider layoff trend? Yes, it coincided with layoffs at TikTok, LinkedIn and Netflix in the same period.

When did this happen? Reports surfaced in mid-to-late August 2026.

For related coverage, see our reporting on AI infrastructure debt and chipmakers and Nvidia’s H200 chip export rules.

Sources: TechCrunch, 9to5Mac.

Meta Agreed to Pay $17 Billion — Here’s What Teens Get

The Meta teen safety settlement closes out one of the largest legal fights the company has faced over how Facebook and Instagram treat young users. Meta agreed on August 26, 2026, to pay $17 billion. The company also agreed to a specific list of safety features. Those changes end a landmark trial brought by 47 states over teen social media addiction.

The case traces back to 2023, when 33 states sued Meta. The list included California, Virginia, Indiana, Kentucky and New Jersey. States accused Meta of knowingly building addictive features into its platforms. They said Meta kept internal research about the harm to minors out of public view. That case grew into a 47-state settlement. It covers some of the most sweeping product changes Meta has ever agreed to for teenage users.

Inside the Meta teen safety settlement

The $17 billion figure ranks among the largest settlements ever reached in a case tied to platform design. Most such cases involve a single product defect instead. Court filings describe the payment as covering direct compensation tied to the states’ claims. Some funding is earmarked for youth mental health programs. The exact allocation was still being finalized when the settlement was announced.

Courthouse steps representing the Meta teen safety settlement legal case

What 47 states accused Meta of doing

The states argued that Meta built features to maximize time spent on the platform by minors. Those features included infinite scroll, algorithmic recommendation feeds and visible engagement metrics such as like counts. The states said Meta knew about links to anxiety, poor sleep and body-image harm. Meta had previously pointed to its existing parental controls and argued that families bear responsibility for screen time. The company did not admit wrongdoing as part of the settlement.

New limits on Instagram and Facebook for under-18 users

Meta agreed to a defined package of safety measures under the deal. Users under 18 will face a default two-hour daily time limit on Instagram and Facebook. An overnight block will run from midnight to 6 a.m. Push notifications will switch off during weekday school hours. Meta also agreed to strengthen age-assurance technology to identify underage users more reliably. The company will add age-appropriate content controls for bullying and self-harm material. It will build more usable parental controls too. And it will limit features tied to social comparison, including visible like counts.

How this settlement compares to past tech accountability fights

Tech platforms have faced fines before over data privacy and antitrust issues. Design-focused cases like this one are harder to win. They hinge on proving intent behind product features, not a single rule violation. This settlement is unusually large. It also forces specific, measurable product changes rather than just a payment. Together, those two facts mark a shift in how these design-liability cases get resolved. The case follows a broader wave of litigation this year accusing major platforms of building addictive features for minors.

What happens next for enforcement

The settlement puts the burden on Meta to implement the agreed changes. State attorneys general involved in the case plan to monitor compliance. The case ended in settlement rather than a final court judgment. That means some granular technical requirements, including exact age-verification methods, will likely get worked out in follow-up filings over the coming months.

Meta settlement: the details parents are asking about

How much is Meta paying? $17 billion, to resolve claims brought by 47 states.

Which states sued Meta? The case began with 33 states in 2023, including California, Virginia, Indiana, Kentucky and New Jersey, and grew to 47 states in the final settlement.

What changes are coming to Instagram and Facebook? A default two-hour daily limit and overnight block for under-18 users, no school-hours notifications, stronger age checks, and limits on features like visible like counts.

When do these changes start? Meta is expected to roll them out on a defined schedule following the settlement; exact dates for each feature were still being finalized in late August.

Does this end all lawsuits against Meta? It resolves the state-led case that went to trial, but separate private lawsuits and claims elsewhere may continue.

Did Meta admit wrongdoing? No. The company agreed to the payment and the product changes without admitting the states’ claims.

For related coverage, see our earlier reporting on social media addiction lawsuits against Meta and Google and our piece on how small businesses use WhatsApp and Instagram.

Sources: MPR News, US News.

NoOnes Took 2.5 Million Traders Offline. CoinCola Wants Them Back

When NoOnes switched off its peer-to-peer marketplace on 21 August 2026, it did not just close a website. It stranded vendors who had spent years building reputation scores that existed nowhere else. The CoinCola migration program, announced this week, is an attempt to catch some of them before they drift to WhatsApp groups and Telegram channels where nobody holds the escrow.

NoOnes had passed 2.5 million users earlier in 2026. The wind-down began on 17 August. The P2P marketplace closed at 23:59 UTC on 21 August, and the platform told users to pull their assets by 23 August. Withdrawals now run only over the Bitcoin network and Tether on TRON.

The cause was not a hack or a bank run. The EU added NoOnes to its Russia-related sanctions list. Partners cut ties, blockchain monitoring firms flagged the platform as high risk, and normal operations became impossible. We covered that collapse and what it meant for user funds in our earlier report on the NoOnes shutdown.

Timeline of the NoOnes shutdown leading to the CoinCola migration program, from 17 to 23 August 2026
The NoOnes wind-down ran over six days in August 2026.

What the CoinCola migration program actually offers

CoinCola describes the package as a transition pathway for three groups: P2P vendors, gift card traders, and ordinary users who held balances. According to the company, it covers five areas.

  • Fast-track vendor migration. Former NoOnes vendors can submit verifiable trading history. CoinCola says it will recognise eligible vendor reputation status and cut P2P fees for those who qualify.
  • VIP onboarding. The company promises a dedicated account team, 24/7 priority dispute handling, and guidance on moving assets across.
  • Mobile money payouts in Kenya and Ghana. CoinCola cites direct withdrawal integration with M-Pesa in Kenya, and MTN Mobile Money and Vodafone Cash in Ghana, with no extra deposit requirement.
  • Gift card escrow. Multi-layer escrow, anti-fraud screening, and dedicated dispute handling on eligible gift card trades.
  • Transition incentives. Fee discount vouchers and signup rewards aimed at traders working in Kenyan shillings and Ghanaian cedis.

Every one of those points comes from CoinCola. None has been independently verified, and the company has not published the eligibility thresholds, the size of the fee reduction, or how it will validate a trading history from a platform that no longer serves data.

Why reputation, not money, is the real loss

A P2P vendor’s balance is portable. Their reputation is not. Trade counts, completion rates, and dispute records sit inside one platform’s database. When that platform closes, a vendor with four years of history restarts at zero somewhere else.

That matters because reputation sets pricing power. Established vendors quote tighter spreads and attract larger orders precisely because buyers trust the badge. Strip it away and the vendor competes on price alone against strangers.

CoinCola says it identified three pressures on affected traders: keeping cash flow moving, preserving that track record, and avoiding unverified trades arranged over social channels. The third is the dangerous one. When a marketplace disappears, deals migrate to group chats, and group chats have no escrow.

“When a major marketplace halts trading, vendors risk losing both their working capital and the trading history they built over years,” said January, Content Manager at CoinCola.

The gift card corridor few outsiders track

Gift cards function as a remittance rail in several markets. A relative abroad buys a retail or digital card. The recipient sells it on a P2P marketplace and receives local currency. The money covers school fees, rent, or stock for a small business.

This corridor rarely appears in remittance statistics, because a gift card is not a wire transfer. It still moves real household income. NoOnes carried a meaningful share of that flow, which is why its closure reached further than its user count suggests.

What traders should check before migrating

An offer of continuity is appealing when your income has just stopped. It still deserves the same scrutiny you would apply to any platform holding your funds.

  • Get the fee terms in writing. “Reduced P2P fees” is not a number. Ask what the rate becomes, and how long the reduction lasts.
  • Test a small withdrawal first. Move a minor amount out before you move a large one. Confirm it lands, and note how long it takes.
  • Check the licensing position. CoinCola does not hold a licence from a major financial regulator. Weigh that against platforms that do.
  • Read the reviews yourself. CoinCola’s public review pages include complaints about frozen accounts and delayed withdrawals. Read them before you commit working capital.
  • Keep your own records. Export whatever NoOnes history you still have. It is the only proof of your track record that you control.

Traders comparing options may also want to look at how signup incentives stack up, including CoinCola’s first naira trade bonus, before choosing where to rebuild.

What happens next

NoOnes has not said when withdrawal-only access ends. Anyone still holding a balance should move it now rather than wait for a deadline that may never be announced.

For CoinCola, the opportunity is obvious. A rival with millions of users has exited, and the vendors who supplied that liquidity are looking for somewhere to trade. Whether the promises in this programme survive contact with real volume is the part worth watching, and the part no press release can settle.

Eligible traders can review the terms on CoinCola’s NoOnes transition page. Reporting on the sanctions that forced the closure is available via CryptoSlate and BeInCrypto.

Frequently asked questions

When exactly did NoOnes shut down?

The wind-down started on 17 August 2026. The P2P marketplace closed at 23:59 UTC on 21 August 2026. NoOnes advised users to withdraw assets by 23 August 2026.

Why did NoOnes close?

The EU added the platform to its Russia-related sanctions list. Partners withdrew, monitoring firms classified it as high risk, and continued operation became unworkable.

Can I still withdraw funds from NoOnes?

Withdrawals run only over the Bitcoin network and Tether on TRON. NoOnes has not announced when that access ends, so move balances promptly.

Who qualifies for the CoinCola migration program?

CoinCola says former NoOnes vendors, gift card traders and P2P users qualify. Applicants with verified records of prior NoOnes volume go to a VIP queue. The company has not published exact thresholds.

Is CoinCola regulated?

CoinCola launched in 2017 and operates across Asia, Africa and Latin America. It does not hold a licence from a major financial regulator such as the SEC or FCA. Factor that into any decision.

Which mobile money services does the programme cover?

CoinCola lists M-Pesa in Kenya, plus MTN Mobile Money and Vodafone Cash in Ghana, with direct withdrawal and no additional deposit requirement.

Related Guides