Three ways to verify over WhatsApp
WhatsApp can now verify a user in one of three modes, and your account runs exactly
one of them. Code back is the default and is the flow that already existed: the
user opens a wa.me link, sends the prefilled message, and we reply with their code.
Inbound approve keeps the link but drops the code: the user’s message approves
the OTP by itself, and there is nothing to verify. Template drops the link: we
push the code straight to the user, so WhatsApp behaves exactly like SMS.
Your code never needs the mode’s name. A new completion field on the send, resend,
and status responses says how the OTP finishes: "code" means collect a code and
call POST /otp/verify; "inbound" means show the link, then poll
GET /otp/{otp_id} or take the otp.approved webhook, and never show a code input.
Read it together with action_url and the three modes fall out of two fields.
completion is frozen on the OTP when it is created, so switching your account’s
mode never re-points a verification already in flight.
The docs now say what resend actually does around WhatsApp. Under Template it is a
code channel like any other and a plain resend advances into and out of it. Under
the two link modes WhatsApp works as the first channel only: a plain resend skips it
anywhere else, and only an explicit resend {"channel":"whatsapp"} moves an OTP
onto it, with the response carrying the link for your app to show. An OTP already on
a link needs an explicit resend {"channel":"sms"} to move off it; a plain resend
there re-returns the same link.
Code back stays on by default. To switch, email info@otp.com. The full guide, with a screenshot of what the user sees in each mode, is at WhatsApp verification.