FastAPI Python GatewayGitHub StarsStar

send otp on telegram & whatsapp with two api calls.

Lightning-fast open-source OTP gateway built with FastAPI Python. Telegram OTP is 100% live, unmetered and free. WhatsApp Cloud API is fully implemented and ready to self-host or plug in with your Meta Business account.

No install and no signup to look: the playground runs the real send and verify rules in your browser and sends nothing anywhere.

code lifetime, in seconds

0 s150 s300 s
  • ttl300 s
  • attempts3
  • throttle5 / phone · hour

02 · how it works

one endpoint sends a code. one endpoint checks it.

both accept json and return json. your api key travels in the X-Api-Key header, never in query parameters, so it remains private and out of logs.

post /v1/otp/send

expires_in 300 s

curl -X POST "$WOTP_API/v1/otp/send" \
  -H "X-Api-Key: $WOTP_KEY" \
  -H "Content-Type: application/json" \
  -d '{"to": "919876543210", "channel": "whatsapp"}'

post /v1/otp/verify

verified true

curl -X POST "$WOTP_API/v1/otp/verify" \
  -H "X-Api-Key: $WOTP_KEY" \
  -H "Content-Type: application/json" \
  -d '{"to": "919876543210", "code": "123456"}'

03 · channel status & engineering reality

the code is complete. telegram is live. here is the meta status.

we believe in total open-source honesty. the backend and frontend are 100% built, tested, and ready. here is where both channels stand right now:

telegram channel · 100% live

unmetered & free

telegram otp works right now with zero corporate friction. no business verification, no credit cards, and no per-message fees. users link our bot with one click and receive instant codes. Explore Telegram OTP landing page →

whatsapp cloud api · code ready

ready for self-host

our meta cloud api engine (graph v25.0) is 100% written, tested with live deliveries, and supports both sandbox and production templates. self-hosters and businesses with a verified meta account can plug credentials in and go live immediately.

04 · meta kyc requirements

why indie developers hit the meta business wall.

to operate a public shared whatsapp line, meta imposes enterprise hurdles documented in facebook help doc 159334372093366. here is what makes a community-wide whatsapp number challenging without corporate sponsorship:

01 · official business verification
meta requires certified government documents (gst registration or certificate of incorporation) matching the legal business entity name to approve a production business manager.
02 · international credit card
meta billing demands an international credit card supporting recurring auto-debit. indian domestic debit cards and rupay cards fail due to rbi e-mandate rules.
03 · dedicated phone number
the production whatsapp number must be a clean sim completely unattached from personal or business whatsapp mobile apps.
04 · authentication template review
custom one-time password templates with copy-code buttons are locked behind full corporate kyc before public delivery is unlocked.

05 · numbers & limits

unmetered telegram, configurable quotas, audited storage.

limits are data, not code. quotas, expiry, attempt thresholds and throttles live in a single database row you can tweak without redeploying.

153

automated tests, all passing

2

http calls in the whole integration

0

per-message cost on telegram

06 · cryptographic security

codes and api keys are hashed. the phone number is not.

one-time codes and api keys are stored only as sha256 digests. an operator inspecting pocketbase sees hashes, never plaintext secrets. meta and telegram tokens are fernet-encrypted at rest. phone numbers remain raw so delivery and verification can be matched.

07 · self-host & contribute

100% open source. run it yourself, on your own credentials.

The whole repository is open source under the AGPL-3.0. Run it on a $4 VPS, plug in your own Meta and Telegram credentials, and you owe this project nothing. The copyleft is deliberate: fork it, modify it, even sell hosting on it, but a modified version offered to users over a network has to publish its source.

stack
lightning-fast fastapi (python 3.12) asynchronous backend and pocketbase database and auth engine, running in a lightweight container.
telegram is live
telegram otp is 100% active, fast and unmetered. zero corporate hurdles, zero kyc, zero credit cards needed. start building today.
plug your meta account
if your company already has an approved meta business account, add META_PHONE_NUMBER_ID and META_ACCESS_TOKEN and whatsapp works instantly.
calling contributors & sponsors
we are looking for open-source contributors or companies willing to sponsor a verified meta business line for the community.

08 · documentation

start with the page that matches your problem.

Two calls to integrate, but the work around them is real. These are the six pages the docs are made of, and the short version of what each one settles.

Quickstart

send an OTP from my backend

Two HTTP calls, from a fresh install to a verified code. Copy-paste, no framework.

WhatsApp OTP

whatsapp cloud api authentication template for OTP

The Meta Cloud API path: business verification, the authentication template, and the four things that stop a launch.

Telegram OTP

send OTP through a telegram bot

The channel with no business verification, no card and no per-message fee. Bot setup and the linking flow.

Self-hosting

self host an OTP gateway / docker compose

Docker Compose, TLS, backups and upgrades. What production refuses to boot without, and why.

API reference

OTP API reference and error codes

Every endpoint, every field, every error code and the retry decision for each.

FAQ

is there a free / open source OTP service

The questions that decide whether this fits your project, answered without hedging.

open source community

built in the open with our community.

WOTP is 100% free and open source. From core FastAPI Python architecture to the responsive Next.js dashboard, we welcome developers worldwide to inspect the code, file bug reports, and submit contributions.

see it work, then clone it.

The playground needs no install and no account, and it sends nothing. When you have seen the wire format, the compose file is the next step.