You do not write this one
An authentication template is the one kind whose words are not yours. Meta writes them:394812 is your verification code. For your security, do not share this code. Expires in 10 minutes.You cannot change that wording, add your brand to it, or explain anything in it. That is a mercy rather than a restriction — OTP is the one message where wording is a liability, and Meta has already argued with every phishing pattern there is. What you choose is three things, and the preview beside them updates as you do.
1–90 minutes
Ten by default: long enough to find your phone, short enough that a screenshot
in a group chat is worthless by the time it matters. WhatsApp says this line
in the customer’s own language, so it costs you no words.
on / off
Appends “For your security, do not share this code.” On by default.
Copy code / One-tap
- Copy code — they tap, then paste. Works everywhere, needs no integration, and is the right answer for almost everyone.
- One-tap autofill — hands the code straight to your Android app. Needs your app’s package name and signing hash, which the form asks for. Meta refuses the template without them, so you would otherwise find out at review rather than at login.
Getting it approved
A new template is a draft — ours, not Meta’s, and it cannot send anything. Open it and press Submit for review. Authentication templates are usually approved within minutes, because Meta wrote the content and has little to argue with.Submit needs a connected number. Meta reviews a template against your
WhatsApp Business Account, so until one is connected there is nothing to
submit it to — the button says so on hover.