New · Reverse OTP · Login with WhatsApp

WhatsApp login without sending a single OTP

Your user taps a button, WhatsApp opens with the code already typed, and they press send. LoginWA matches the message and tells your app which number just signed in.

0 OTP messages sent. 0 ban risk from OTP.

Start free Read the docs
Why let the user send the code

Nothing to report as spam

WhatsApp acts on numbers whose messages get reported or blocked. Here your number only receives, so logins add zero outbound messages to it.

No delivery step to fail

A sent OTP can stall when the sending device disconnects or the phone shows “Waiting for this message”. Here the user sends from their own phone, so that step does not exist.

Pay for logins, not attempts

One quota per successful login. Sessions that expire or are abandoned cost nothing.

How it works
  1. Your server calls POST /api/v1/auth/reverse/start and gets a code plus a WhatsApp link to your connected number, or to LoginWA's verification number if you have not connected one.
  2. Show the link as a button on mobile or a QR code on desktop. The user sends the pre-filled message, for example LOGIN 48213907.
  3. LoginWA checks the sender and sends otp.verified to your webhook with their number. You create the session.
POST https://api.loginwa.com/api/v1/auth/reverse/start
{}

200 OK
{
  "session_id": "9b2f6c1e-…",
  "mode": "any_sender",
  "message": "LOGIN 48213907",
  "wa_link": "https://wa.me/62811…?text=LOGIN%2048213907",
  "expires_in": 300
}

# webhook
{ "event": "otp.verified",
  "data": { "session_id": "9b2f6c1e-…", "phone": "6281234567890" } }
Two ways to use it

Login with WhatsApp

No phone field at all. The verified number comes from WhatsApp itself. 8-digit code.

Verify a known number

Send the phone you already have. Only a message from that number completes the session. 6-digit code.

Reverse OTP vs WhatsApp OTP
WhatsApp OTPReverse OTP
Who sends the message WhatsApp OTP: Your number Reverse OTP: Your user
Outbound messages per login WhatsApp OTP: 1 or more Reverse OTP: 0
What the user types WhatsApp OTP: Phone number and code Reverse OTP: Nothing in Login with WhatsApp mode
Billed when WhatsApp OTP: The OTP is sent Reverse OTP: The login succeeds
Best for WhatsApp OTP: Confirming transactions; numbers you must message first Reverse OTP: Sign-in and sign-up
Try it on the Free plan

100 logins a month, no card. Call one endpoint; connect your own number when you want your brand on it.

Start free
Reverse OTP FAQ

Does this mean my number can't be banned?

Reverse OTP sends nothing, so logins add no ban risk of their own. WhatsApp's rules still apply to everything else the number does: other messages you send from it, reports from people you message, and WhatsApp's policies on automated use. Use a dedicated number for logins and keep broadcasts on another.

Does it work for every WhatsApp user?

For almost all. A small share of accounts hide their number behind a WhatsApp privacy ID: 3 of 347 first-time senders to numbers on LoginWA between 7 Sep and 7 Oct 2026. Those sessions end as failed with reason sender_hidden, so you can offer standard OTP right away.

How does it work on desktop?

Render wa_link as a QR code. The user scans it with their phone camera and WhatsApp opens with the message ready to send.

How is it billed?

One quota per successful login, on every plan including Free. Expired or abandoned sessions are not counted.

Is standard WhatsApp OTP going away?

No. /api/v1/auth/start and /api/v1/auth/verify work as before. Use reverse OTP as the default and standard OTP as the fallback.

Which number receives the messages?

Your own WhatsApp number once one is connected to the app, so users message your business. Until then, LoginWA's verification number receives the code, so you can start without scanning a QR; the API response says which (receiver).