Insider OTP for WhatsApp API

The OTP for WhatsApp API from Insider — 3 operation(s) for otp for whatsapp.

Operations 4

POST /v1/generate Generate OTP codes #
POST /v1/template/create Create an OTP Template #
POST /v1/template/list Update OTP Templates #
GET /v1/template/list List OTP templates #

Documentation

📖
Documentation
https://academy.insiderone.com/docs/ucd-user-data-apis-overview
📖
APIReference
https://developers.insiderone.com/
📖
Authentication
https://raw.githubusercontent.com/api-evangelist/insider/refs/heads/main/authentication/insider-authentication.yml
📖
RateLimits
https://raw.githubusercontent.com/api-evangelist/insider/refs/heads/main/rate-limits/insider-rate-limits.yml
📖
Documentation
https://academy.insiderone.com/docs/data-collection-consent-apis
📖
Documentation
https://academy.insiderone.com/docs/email-apis-overview
📖
Documentation
https://academy.insiderone.com/docs/transactional-sms-overview
📖
Documentation
https://academy.insiderone.com/docs/whatsapp-transactional-api
📖
Documentation
https://academy.insiderone.com/docs/web-push-apis-overview
📖
Documentation
https://academy.insiderone.com/docs/app-push-apis-overview
📖
Documentation
https://academy.insiderone.com/docs/mobile-app-analytics-apis
📖
Documentation
https://academy.insiderone.com/docs/mobile-app-integration-guide-1
📖
Documentation
https://academy.insiderone.com/docs/otp-for-sms
📖
Documentation
https://academy.insiderone.com/docs/product-catalog-api-introduction
📖
Documentation
https://academy.insiderone.com/docs/recommendation-api
📖
Documentation
https://academy.insiderone.com/docs/eureka-search-api-overview
📖
Documentation
https://academy.insiderone.com/docs/eureka-event-collection-api-implementation
📖
Documentation
https://academy.insiderone.com/docs/email-analytics-api
📖
Documentation
https://academy.insiderone.com/docs/architect-analytics-api
📖
Documentation
https://academy.insiderone.com/docs/transactional-journeys-on-api-call-starter

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/insider-otp-for-whatsapp-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

insider-otp-for-whatsapp-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Insider One Verify (OTP) OTP for WhatsApp API
  version: 1.0.0
  description: 'OTP channels and templates for SMS and WhatsApp: create/update channels, manage templates, generate and verify OTP codes.'
  contact:
    name: Insider One Support
    email: support@useinsider.com
    url: https://academy.insiderone.com/docs/insider-one-apis-1
  termsOfService: https://insiderone.com/terms-of-use/
servers:
- url: https://verify.useinsider.com
tags:
- name: OTP for WhatsApp
paths:
  /v1/generate:
    post:
      operationId: generateOtpCodesWhatsapp
      summary: Generate OTP codes
      tags:
      - OTP for WhatsApp
      description: 'The Verify API enables you to generate, send, and verify OTP codes for the WhatsApp channel. You can utilize this API to generate OTP codes as defined in the payloads. Integrating it into your own websites or apps, you can trigger it on login pages, payment pages, and more.


        After you create your channel for your brand and update the templates, you need to perform the generate action for your OTP.


        This API key is sensitive and should never be used on the frontend or mobile SDK; it should only be implemented on the backend.


        Body Parameters


        Parameter

        Description

        Data Type

        Required

        Rules


        channel

        Channel that you will send the OTP code.

        String

        Yes

        oneof:whatsapp


        to

        Specifies the destination phone number in E.164 format to which the OTP code will be sent.

        String

        Yes

        e164


        locale

        Determines the language/locale in which the OTP code message will be sent.

        String

        No (Default: en)

        oneof:pt af sq ar az bn bg ca zh_CN zh_HK zh_TW hr cs da nl en en_GB en_US et fil fi fr ka de el gu ha he hi hu id ga it ja kn kk rw_RW ko ky_KG lo lv lt mk ms ml mr nb fa pl pt_BR pt_PT pa ro ru sr sk sl es es_AR es_ES es_MX sw sv ta te th tr uk ur uz vi zu


        ttl

        Specifies the Time-To-Live (TTL) duration for the OTP code, i.e., the time window within which the OTP code is valid. Measured in seconds.

        Integer

        No (Default: 180)

        min:60 max:600


        code-length

        Specifies the length of the OTP code to be generated. The code length must be between 4 and 8 digits.

        Integer

        No (Default: 4)

        min:4 max:8


        custom-code

        If provided, allows you to specify a custom OTP code instead of generating one.

        Integer

        No

        min:1000 max:99999999


        max-attempts

        Sets the maximum number of allowed OTP verification attempts. If the verification fails after reaching this limit, further attempts might be denied.

        Integer

        No (Default: 3)

        min:1 max:10


        Sample Example

        Sample Request

        Every request made to the request endpoint requires a request body formatted in JSON and containing your parameters.


        Make sure to replace the sample values in the request header(s) and body where required before sending your request.


        curl --location ''https://verify.useinsider.com/v1/generate'' \

        --header ''Content-Type: application/json'' \

        --header ''x-ins-auth-key: INS.************************'' \

        --data ''{

        "channel": "whatsapp",

        "locale": "tr",

        "to": "+905XXXXXXXXX",

        "ttl": 600

        }''


        Sample Responses

        202 Accepted

        This response indicates that your request was successfully completed.


        {

        "key": "whatsapp-12345",

        "channel": "whatsapp",

        "dateCreated": "2023-07-28T14:40:41Z",

        "dateUpdated": "2023-07-28T14:40:41Z",

        "locale": "en",

        "maxAttempts": 3,

        "ttl": 180

        }


        400 Bad Request

        {

        "errors": [

        {

        "message": "invalid request payload"

        }

        ]

        }


        400 Bad Request

        {

        "errors": [

        {

        "message": "this field is required",

        "field": "text"

        }

        ]

        }


        401 Unauthorized

        {

        "errors": [

        {

        "message": "unauthorized"

        }

        ]

        }


        429 Too Many Requests

        {

        "errors": [

        {

        "message": "rate limit exceeded"

        }

        ]

        }


        500 Internal Server Error

        {

        "errors": [

        {

        "message": "server error"

        }

        ]

        }


        Limitations


        All functions must be executed with a simple HTTPS POST request.


        The API Key should be provided as the authorization key in the request header. If the key is incorrect, the operation will not be executed and an authorization error will return in the response.


        The service is subject to a rate limit of 100 requests per second to ensure optimal system performance, and clients exceeding this limit will receive an HTTP 429 Too Many Requests response.'
      security:
      - InsAuthKey: []
      requestBody:
        content:
          application/json:
            example:
              channel: whatsapp
              locale: tr
              to: +905XXXXXXXXX
              ttl: 600
      responses:
        '429':
          $ref: '#/components/responses/TooManyRequests'
  /v1/template/create:
    post:
      operationId: createAnOtpTemplate
      summary: Create an OTP Template
      tags:
      - OTP for WhatsApp
      description: 'The Verify API enables you to generate, send, and verify OTP codes for the WhatsApp channel. Ensure that the provided template name exists and corresponds to the authentication template name you created through your WhatsApp Business Account.


        After you create a channel for your brand, you can create OTP templates.


        This API key is sensitive and should never be used on the frontend or mobile SDK; it should only be implemented on the backend.


        Body Parameters


        Parameter

        Description

        Data Type

        Required

        Rules


        channel

        Channel that you will send the OTP code. It will be WhatsApp.

        String

        Yes

        oneof:whatsapp


        locale

        Determines the language/locale in which the OTP code message will be sent.

        String

        Yes

        oneof:pt af sq ar az bn bg ca zh_CN zh_HK zh_TW hr cs da nl en en_GB en_US et fil fi fr ka de el gu ha he hi hu id ga it ja kn kk rw_RW ko ky_KG lo lv lt mk ms ml mr nb fa pl pt_BR pt_PT pa ro ru sr sk sl es es_AR es_ES es_MX sw sv ta te th tr uk ur uz vi zu


        templateName

        The template name that will be inserted

        String

        Yes

        The template has to exist already.


        Sample Example

        Sample Request

        Every request made to the request endpoint requires a request body formatted in JSON and containing your parameters.


        Make sure to replace the sample values in the request header(s) and body where required before sending your request.


        curl --location ''verify.useinsider.com/v1/template/create'' \

        --header ''Content-Type: application/json'' \

        --header ''x-ins-auth-key: INS.************************'' \

        --data ''{

        "channel": "whatsapp",

        "locale": "tr",

        "templateName": "otp_template"

        }''


        Sample Responses

        202 Accepted

        {

        "status": "success"

        }


        400 Bad Request

        {

        "errors": [

        {

        "message": "invalid request payload"

        }

        ]

        }


        400 Bad Request

        {

        "errors": [

        {

        "message": "this field must be one of these:whatsapp",

        "field": "text"

        }

        ]

        }


        401 Unauthorized

        {

        "errors": [

        {

        "message": "unauthorized"

        }

        ]

        }


        409 Conflict

        {

        "errors": [

        {

        "message": "no changes detected"

        }

        ]

        }


        429 Too Many Requests

        {

        "errors": [

        {

        "message": "rate limit exceeded"

        }

        ]

        }


        500 Internal Server Error

        {

        "errors": [

        {

        "message": "server error"

        }

        ]

        }


        Limitations


        All functions must be executed with a simple HTTPS POST request.


        The API Key should be provided as the authorization key in the request header. If the key is incorrect, the operation will not be executed and an authorization error will return in the response.


        For effective usage, create a dedicated template for each language.


        The service is subject to a rate limit of 100 requests per second to ensure optimal system performance, and clients exceeding this limit will receive an HTTP 429 Too Many Requests response.'
      security:
      - InsAuthKey: []
      requestBody:
        content:
          application/json:
            example:
              channel: whatsapp
              locale: tr
              templateName: otp_template
      responses:
        '429':
          $ref: '#/components/responses/TooManyRequests'
  /v1/template/list:
    post:
      operationId: updateOtpTemplates
      summary: Update OTP Templates
      tags:
      - OTP for WhatsApp
      description: 'The Verify API enables you to generate, send, and verify OTP codes for the WhatsApp channel.


        After you create a channel for your brand, you can list its templates later.


        This API key is sensitive and should never be used on the frontend or mobile SDK; it should only be implemented on the backend.


        Sample Example

        Sample Request

        Every request made to the request endpoint requires a request body formatted in JSON and containing your parameters.


        Make sure to replace the sample values in the request header(s) and body where required before sending your request.


        curl --location ''verify.useinsider.com/v1/template/list'' \

        --header ''Content-Type: application/json'' \

        --header ''x-ins-auth-key: INS.************************''


        Sample Responses

        200 OK

        This response indicates that your request was successfully completed.


        {

        "templates": {

        "whatsapp": [

        {

        "locale": "en",

        "text": "",

        "templateName": "sample_otp_template_1"

        },

        {

        "locale": "tr",

        "text": "",

        "templateName": "sample_otp_template_2"

        }

        ]

        }

        }


        401 Unauthorized

        {

        "errors": [

        {

        "message": "unauthorized"

        }

        ]

        }


        429 Too Many Requests

        {

        "errors": [

        {

        "message": "rate limit exceeded"

        }

        ]

        }


        Limitations


        All functions must be executed with a simple HTTPS GET request.


        The API Key should be provided as the authorization key in the request header. If the key is incorrect, the operation will not be executed and an authorization error will return in the response.


        The service is subject to a rate limit of 100 requests per second to ensure optimal system performance, and clients exceeding this limit will receive an HTTP 429 Too Many Requests response.'
      security:
      - InsAuthKey: []
      responses:
        '429':
          $ref: '#/components/responses/TooManyRequests'
      x-source-note: The published collection maps the "Update OTP Templates" request to POST /v1/template/list; Insider One's own rate-limit table lists Update OTP Templates as /v1/template/update. Recorded as published — not silently corrected.
    get:
      operationId: listOtpTemplatesWhatsapp
      summary: List OTP templates
      tags:
      - OTP for WhatsApp
      description: 'The Verify API enables you to generate, send, and verify OTP codes for the WhatsApp channel.


        After you create a channel for your brand, you can list its templates later.


        This API key is sensitive and should never be used on the frontend or mobile SDK; it should only be implemented on the backend.


        Sample Example

        Sample Request

        Every request made to the request endpoint requires a request body formatted in JSON and containing your parameters.


        Make sure to replace the sample values in the request header(s) and body where required before sending your request.


        curl --location ''verify.useinsider.com/v1/template/list'' \

        --header ''Content-Type: application/json'' \

        --header ''x-ins-auth-key: INS.************************''


        Sample Responses

        200 OK

        This response indicates that your request was successfully completed.


        {

        "templates": {

        "whatsapp": [

        {

        "locale": "en",

        "text": "",

        "templateName": "sample_otp_template_1"

        },

        {

        "locale": "tr",

        "text": "",

        "templateName": "sample_otp_template_2"

        }

        ]

        }

        }


        401 Unauthorized

        {

        "errors": [

        {

        "message": "unauthorized"

        }

        ]

        }


        429 Too Many Requests

        {

        "errors": [

        {

        "message": "rate limit exceeded"

        }

        ]

        }


        Limitations


        All functions must be executed with a simple HTTPS GET request.


        The API Key should be provided as the authorization key in the request header. If the key is incorrect, the operation will not be executed and an authorization error will return in the response.


        The service is subject to a rate limit of 100 requests per second to ensure optimal system performance, and clients exceeding this limit will receive an HTTP 429 Too Many Requests response.'
      security:
      - InsAuthKey: []
      responses:
        '429':
          $ref: '#/components/responses/TooManyRequests'
components:
  responses:
    TooManyRequests:
      description: Too Many Requests. The published per-endpoint rate limit was exceeded; back off and retry, honouring Retry-After when present.
      content:
        application/json:
          example:
            message: Too Many Requests
            status: 429
  securitySchemes:
    InsAuthKey:
      type: apiKey
      in: header
      name: X-INS-AUTH-KEY
      description: Insider One authorization key for this API, generated in the InOne panel.
externalDocs:
  description: Insider One API reference
  url: https://academy.insiderone.com/docs/api-reference-welcome
x-provenance:
  generated: '2026-08-13'
  method: derived
  source: postman/insider-one-apis.postman_collection.json
  source_url: https://documenter.gw.postman.com/api/collections/24851117/2sB3dSR9bM
  publisher_page: https://developers.insiderone.com/
  note: Insider One publishes a single public Postman collection covering every REST API. This document is the subset of that collection served from verify.useinsider.com.