Download the PHP package otp-id/otp-id-php without Composer
On this page you can find all versions of the php package otp-id/otp-id-php. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download otp-id/otp-id-php
More information about otp-id/otp-id-php
Files in otp-id/otp-id-php
Package otp-id-php
Short Description Official PHP SDK for the OTP.ID V3 API — multi-channel OTP delivery and verification (WhatsApp, SMS, Voice, Email, Missed Call, and WhatsApp Inbound) with prepaid billing.
License MIT
Homepage https://otp.id
Informations about the package otp-id-php
otp-id-php
Official PHP SDK for the OTP.ID V3 API — multi-channel OTP delivery and verification (WhatsApp, SMS, Voice, Email, Missed Call, and WhatsApp Inbound) with prepaid billing.
- Zero runtime dependencies — no Composer packages required, only the
curlandjsonPHP extensions. - Faithful to the API: one method per endpoint, no hidden retries.
- PHP 7.4+ compatible — works on Indonesian shared hosting that has not moved to PHP 8 yet.
- Full API reference: https://docs.otp.id
Install
Requires PHP >= 7.4.
Quickstart
Error handling
Every non-success API response is an OtpId\Exception\ApiException:
Invalid SDK usage — an empty API key or an empty otp_id passed to
verifyOtp()/otpStatus() — throws a plain \InvalidArgumentException,
not OtpIdException. Treat it as a programming error to fix in your code,
not something to catch at runtime.
A wrong code on verifyOtp() is not an error: the server answers HTTP
200 with verified: false, and the SDK returns a VerifyResult with
reason: "mismatch". Expired, locked, or already-used transactions do
throw an ApiException (OTP_EXPIRED, TOO_MANY_ATTEMPTS,
ALREADY_USED).
Channels
| Constant | Value | Notes |
|---|---|---|
Channel::WHATSAPP |
whatsapp |
requestOtp() + sendOtp() |
Channel::SMS |
sms |
requestOtp() + sendOtp() |
Channel::VOICE |
voice |
requestOtp() only |
Channel::EMAIL |
email |
requestOtp() + sendOtp() |
Channel::MISSCALL |
misscall |
use requestOtp() for misscall; user completes the caller's number |
Channel::WHATSAPP_INBOUND |
whatsapp_inbound |
requestOtp() only; user messages OTP.ID |
Bring your own code
WhatsApp Inbound (user-initiated)
No code to type: show the user $res->verification->waLink and let
OTP.ID match their incoming message. Never call verifyOtp() for these
transactions — detect completion via the otp.verified webhook or by
polling otpStatus().
Missed Call
The last digits of the calling number are the code. Show
$res->verification->prefix and ask the user to complete the number,
then pass the completed digits to verifyOtp().
Account & top-up
Webhook: otp.verified
OTP.ID signs every webhook with HMAC-SHA256(secret, timestamp + "." + body).
Webhook::parseVerifiedEvent() checks the signature (constant-time),
rejects timestamps outside ±5 minutes by default (replay protection,
configurable via the $tolerance parameter), and decodes the payload:
Configuration
The SDK never retries a request. If you add retries, only retry
requestOtp()/sendOtp() calls that carry an external_id (the server
replays them idempotently) — retrying without one may deliver a second
OTP.
Examples
Runnable, per-channel examples live in examples/:
whatsapp.php, sms.php, voice.php, email.php, misscall.php,
whatsapp_inbound.php, send.php. Each reads OTPID_API_KEY and
OTPID_DESTINATION from the environment and is run with
php examples/<file>.php.
License
MIT — see LICENSE.
All versions of otp-id-php with dependencies
ext-curl Version *
ext-json Version *