Skip to content
Tawked Verify

Verify Saudi users by SMS code, in two API calls.

One request sends a code by SMS or WhatsApp to a Saudi mobile number. One request checks it.

Two calls, and the lifecycle around them

start and check

POST /v1/verify/start sends the code and returns an id. POST /v1/verify/check verifies what the user typed.

Two endpoints

Status, resend, cancel

Read a verification without spending an attempt, send a fresh code on the same id, or cancel it. Resends are capped per verification.

Max resends: 3

Idempotency and request ids

Send an Idempotency-Key and a retried request returns the original response without sending or charging again. Every response carries an X-Request-Id for support.

Replay-safe

Your reference

Attach an order id or session id to each verification. It comes back on every read and is searchable in the dashboard.

Up to 64 characters

Channels

SMS that names your app

Codes go out from Tawked's sender ID through a licensed Saudi gateway, and the text names your reviewed app.

STC, Mobily, Zain and MVNOs

WhatsApp verification

A Meta-approved authentication template with a one-tap copy-code button, from a verified business number. Enabled per account on request.

Same two calls

Any Saudi number format

Send 05..., 5..., 9665..., +9665... or 009665...; every form is normalized to E.164 before sending.

Five accepted formats

Arabic or English message

Pick the message language per request. The code itself is digits; the text around it matches the user.

lang field

WhatsApp Business API for your notifications

Your app's name in every code

Reviewed before go-live

A person reviews your service name and website during business hours, before any live message carries them.

Manual review

No sender ID to register

Codes go out from Tawked's sender ID, so there is no application or fee for one on your side. Renaming your app sends it back to review.

Nothing to register

Stamped trial messages

Before approval, sandbox messages carry a visible test stamp, so nobody can use the trial to impersonate anyone.

Sandbox only

A sandbox that sends real messages

A test key on day one

A tk_test_ key is issued the moment onboarding completes, before your application is approved. Same endpoints, same shapes as production.

Issued at signup

To your own phone

Sandbox sends deliver real SMS to the phone you signed up with, and only to it, so you test the end-to-end flow, not a mock.

Sandbox cap per application: 10

Going live is a key swap

Replace tk_test_ with tk_live_ once approved. Nothing else changes.

Zero code changes

Bounded by default

Code shape and expiry

Choose the code length and how long it stays valid, per application, within safe bounds. Codes are stored hashed and cannot be read back.

Length: 6, 4 to 8. Expiry in minutes: 5, 1 to 15

Attempts

After the last wrong guess the verification fails, and the result is reported once.

Attempts: 3, 1 to 5

Per destination

One number cannot be flooded with codes, across all your applications and channels.

Per hour: 5, 1 to 10

Per key and per IP

A fixed per-key request limit, and when you pass the end user's IP, a per-IP send limit too.

Per key a minute: 120. Per IP an hour: 20

Auto-pause on abuse

A burst of sends to new numbers pauses the application and notifies you, so a leaked form cannot drain your balance overnight.

New numbers an hour: 300

Daily spend cap

An optional ceiling on what one application can spend in a day.

Off by default

Keys you can constrain

Expiry and IP allowlist

Give a key an end date, or restrict it to your servers' addresses. Anything else is refused with a clear error.

Per key

Check-only scope

A key for the code-entry path. It can verify but never send.

scope: check

Hashed at rest

Keys are shown once and stored as a hash; revoke and reissue from the dashboard at any time.

SHA-256

Webhooks and delivery

Signed webhooks

verification.verified, verification.failed and verification.expired reach your URL with a timestamp and an HMAC signature, and are retried on failure.

Per application

Autofill-ready messages

The last line of the SMS carries the @domain #code form iOS AutoFill and the WebOTP API read, and the Android app-hash line when you set it.

iOS, Android, web

Delivery receipts

Every send, delivery and failure is logged with its provider status. Failed sends are refunded on the spot.

In the dashboard

Billing you can predict

One price per delivered code

0.09 SAR per SMS code that is delivered. Not per attempt, not per segment.

0.09 SAR

Failed sends cost nothing

If the network does not deliver, the charge is reversed in the same ledger.

Refunded

Prepaid, no contract

Top up by card from 25 to 50,000 SAR, at the same rate per code, with no subscription. New accounts start with 10 SAR free.

10 SAR on signup

For platforms and the people who run them

Partner API

Marketplaces and platforms provision an application per merchant, send on their behalf with one key, and read usage per merchant.

/v1/partner

Docs in both languages

The full reference in Arabic and English, an OpenAPI 3.1 description at /openapi.json, and a Markdown version for tools.

OpenAPI 3.1

Engineers answer

Support by email and WhatsApp, answered by the people who built the platform, in Arabic or English.

support@tawked.com

Why not a plain SMS gateway?

A gateway sells messages. Tawked sells the verification.

Public prices from each provider's pricing page on 2026-09-09. Global providers list USD before tax; Saudi gateways include VAT.

TawkedGlobal CPaaS: Twilio, PlivoSaudi bulk SMS gateway
Built forOTP verification, end to endAny messaging; you build OTP on topCampaigns; you build OTP on top
Public price per Saudi SMS0.09 SAR per delivered codeAbout 0.73 SAR per segment, 0.1949 USD to STC0.069 to 0.13 SAR per sent message, by volume
Charged whenDeliveredSentSent
Sender nameTawked's, nothing to registerRegister through a local partnerAbout 230 SAR per year
Code generation, expiry, attemptsBuilt in and boundedBuild it yourselfBuild it yourself
Real messages before approvalSandbox to your own phoneTrial to verified numbersVaries
WhatsApp verificationSame API, on requestSeparate productSeparate product or none
Docs and support in ArabicYes, by engineersEnglishArabic
The full comparison with sources
FAQ

Questions people ask before switching

How is Tawked Verify different from an SMS gateway?

A gateway sells messages; you build code generation, expiry, attempt counting and abuse limits on top. Tawked Verify sells the verification itself: one call sends the code, one checks it, and everything in between is built, bounded and billed only on delivery.

What does it really cost?

0.09 SAR per delivered SMS code, from prepaid credit. Failed sends are not charged, and there is no contract. New accounts get 10 SAR of free credit.

Can I test before my app name is approved?

Yes. A tk_test_ key is issued the moment onboarding completes. It sends real, stamped messages to the phone you signed up with, and only to it, with the same requests and responses, up to 10 sends per application.

Is WhatsApp available?

Yes, for verification codes, through a Meta-approved authentication template with a copy-code button, enabled per account on request. The channel is a field on verify/start, so you choose SMS or WhatsApp per user. WhatsApp notifications to your customers are a different product: Tawked Notifications.

What if an API key leaks?

Revoke it from the dashboard at once. Before that, constrain it: an expiry date, an IP allowlist, or a check-only scope for a key that never sends. The per-destination, per-IP and daily spend limits bound the damage even while it is in use.

Verify your first user today.

10 SAR free credit. No card required.

Chat on WhatsApp