Yoola Verify

SMS & WhatsApp Verification, Built In

Send a one-time code. Check it when your customer types it back. Two simple API calls — expiry, retry limits, and rate limiting already handled for you.

See the Quick Start

Why not just send an SMS yourself?

You could — but you'd also need to generate a real, random code, store it safely, expire it after a few minutes, limit how many times someone can guess wrong, and stop the same number being spammed with codes. Yoola Verify already does all of that, so you don't have to build or maintain it yourself.

How It Works

1

Send a code

Call /verify-send with your customer's phone number. We generate a real code and deliver it — over SMS or WhatsApp.

2

They type it back

Your own app or website collects the code from the end user, exactly like any other verification screen.

3

We check it

Call /verify-check with what they typed. We tell you, plainly, whether it matched.

Quick Start

Two requests. That's the whole integration.

1. Send a code

curl --location 'https://yoolasms.com/api/v1/verify-send' \
  --header 'Content-Type: application/json' \
  --data '{
    "api_key": "YOUR_API_KEY_HERE",
    "phone": "256704487563",
    "brand_name": "YourApp"
  }'

Response

{
  "status": "success",
  "request_id": "vrf_8f2a1c...",
  "phone": "256704487563",
  "channel": "sms",
  "expires_in": 600
}

2. Check the code they typed back

curl --location 'https://yoolasms.com/api/v1/verify-check' \
  --header 'Content-Type: application/json' \
  --data '{
    "api_key": "YOUR_API_KEY_HERE",
    "request_id": "vrf_8f2a1c...",
    "code": "482913"
  }'

Response

{
  "status": "success",
  "verified": true,
  "request_id": "vrf_8f2a1c...",
  "phone": "256704487563"
}

Always confirm the returned phone is the number you meant to verify before you trust the result. A code works once — after it verifies, that request_id can't be used again.

Parameters

Field Endpoint Description
api_key both Required. Your account API key.
phone send Required. The number to verify, e.g. 256704487563.
sender send Optional. Your own approved sender ID. Defaults to YoolaSMS if you don't have one.
brand_name send Optional. The name used in the message text, e.g. “Your YourApp verification code is…”.
channel send Optional. sms (default) or whatsapp.
purpose send Optional. Your own label, e.g. login or password_reset — kept for your records.
request_id check Required. The request_id returned by /verify-send.
code check Required. The code your customer typed in.

What's Handled For You

Automatic Expiry

Every code expires after 10 minutes — no stale codes left valid indefinitely.

Retry Limits

Five wrong guesses and a code locks out, protecting against brute-force attempts.

Rate Limiting

Built-in limits per phone number and per account stop abuse before it starts.

SMS or WhatsApp

Send the code over whichever channel fits your customer best.

Your Own Sender ID

Pass your own approved sender ID, and a brand_name for the wording — codes arrive from your name, not ours.

No Extra Fee

Uses your existing balance. An SMS code costs one SMS at your normal rate — no Verify surcharge.

Included, Not an Add-On

Yoola Verify has no separate pricing. An SMS code costs exactly one SMS at your normal rate; a WhatsApp code costs the standard WhatsApp authentication rate. Both come out of the same balance you already use — there is no Verify fee on top.

View Full API Documentation