Your user taps a button, WhatsApp opens with the code already typed, and they press send. LoginWA matches the message and tells your app which number just signed in.
0 OTP messages sent. 0 ban risk from OTP.
WhatsApp acts on numbers whose messages get reported or blocked. Here your number only receives, so logins add zero outbound messages to it.
A sent OTP can stall when the sending device disconnects or the phone shows “Waiting for this message”. Here the user sends from their own phone, so that step does not exist.
One quota per successful login. Sessions that expire or are abandoned cost nothing.
POST https://api.loginwa.com/api/v1/auth/reverse/start
{}
200 OK
{
"session_id": "9b2f6c1e-…",
"mode": "any_sender",
"message": "LOGIN 48213907",
"wa_link": "https://wa.me/62811…?text=LOGIN%2048213907",
"expires_in": 300
}
# webhook
{ "event": "otp.verified",
"data": { "session_id": "9b2f6c1e-…", "phone": "6281234567890" } }
No phone field at all. The verified number comes from WhatsApp itself. 8-digit code.
Send the phone you already have. Only a message from that number completes the session. 6-digit code.
| WhatsApp OTP | Reverse OTP | |
|---|---|---|
| Who sends the message | WhatsApp OTP: Your number | Reverse OTP: Your user |
| Outbound messages per login | WhatsApp OTP: 1 or more | Reverse OTP: 0 |
| What the user types | WhatsApp OTP: Phone number and code | Reverse OTP: Nothing in Login with WhatsApp mode |
| Billed when | WhatsApp OTP: The OTP is sent | Reverse OTP: The login succeeds |
| Best for | WhatsApp OTP: Confirming transactions; numbers you must message first | Reverse OTP: Sign-in and sign-up |
100 logins a month, no card. Call one endpoint; connect your own number when you want your brand on it.
Start freeReverse OTP sends nothing, so logins add no ban risk of their own. WhatsApp's rules still apply to everything else the number does: other messages you send from it, reports from people you message, and WhatsApp's policies on automated use. Use a dedicated number for logins and keep broadcasts on another.
For almost all. A small share of accounts hide their number behind a WhatsApp privacy ID: 3 of 347 first-time senders to numbers on LoginWA between 7 Sep and 7 Oct 2026. Those sessions end as failed with reason sender_hidden, so you can offer standard OTP right away.
Render wa_link as a QR code. The user scans it with their phone camera and WhatsApp opens with the message ready to send.
One quota per successful login, on every plan including Free. Expired or abandoned sessions are not counted.
No. /api/v1/auth/start and /api/v1/auth/verify work as before. Use reverse OTP as the default and standard OTP as the fallback.
Your own WhatsApp number once one is connected to the app, so users message your business. Until then, LoginWA's verification number receives the code, so you can start without scanning a QR; the API response says which (receiver).