start, the person types (or autofills) the code, and your server calls check. This page covers the parts the quickstart leaves out.
1. Collect the number
Tawked sends to Saudi mobile numbers only, and accepts them in any of five forms (0551234567, 551234567, 966551234567, 00966551234567, +966551234567). Send what the person typed: you do not need to normalise it. The full list is on Numbers, language and the SMS.
Number field
422 invalid_destination. Show it under the field (“Enter a Saudi mobile number”) and let the person correct it.
2. Start the verification on your server
Callstart with four things beyond to:
Node.js (server)
An
Idempotency-Key that already started a verification replays that verification, whatever the new body says. Make a new key for every new attempt, and never reuse one for another number.3. Let the code fill itself in
Tawked can add lines to the SMS that phones read the code from. Switch them on under Verify → Settings, in Autofill:- Add the domain line to the message puts
@your-domain #123456last. iOS and Android browsers offer the code above the keyboard, and the WebOTP API can read it. The domain comes from your application’s reviewed website. - Android app hash adds your app’s 11-character SMS Retriever hash, so your Android app reads the code without the person typing it.
start, autofill (web, android or none) picks the lines for one send, for example android when the request comes from your Android app. Leave it out to send every line you switched on. Numbers, language and the SMS shows the message and its length limits.
The code field itself:
Code field
autocomplete="one-time-code" is what lets iOS and Android suggest the code. Set maxlength to your code length (6 by default). On the web, WebOTP can fill the field by itself when the SMS ends with the domain line:
Browser
4. Check the code and act on the outcome
Your server posts theid from the session and the code as typed. Every outcome is a 200 with verified and status:
An
id your key does not own answers 404 not_found. Treat it as a broken session and go back to the number screen.
Node.js (server)
check signs someone in. Never accept a “verified” flag from the browser.
5. Resend and start again
Give the person a “Send a new code” button behind a short countdown, so an impatient tap does not send two messages. Tawked does not enforce a wait between resends: the countdown is yours to choose.- Resend (
POST /v1/verify/{id}/resend) sends a new code on the sameid. The old code stops working, and the attempts and the lifetime start over. Each verification has 3 resends, then answers429 resend_limit_reached. - An expired or closed verification cannot be resent (
409 not_resendable). Callstartagain, with a newIdempotency-Key. - The number has an hourly cap. A start and each resend count toward the application’s “Codes per number per hour” (5 by default), across all your applications. Past it,
startandresendanswer429 rate_limited.
6. Errors the person can see
Most errors are for you, not for the person. Map the few they can act on, and log the rest with the response’sX-Request-Id header.
These are about your setup, so show a general “We could not send the code right now” and alert yourself:
insufficient_credits (top up), spend_cap_reached, application_paused, account_not_active, unauthorized, insufficient_scope. The Errors page lists every code, and Reliability and limits says which to retry.
Optional: hear about outcomes by webhook
If something else needs to know (an audit log, a fraud check), set a webhook under Application settings → Webhooks: it receivesverification.verified, verification.failed and verification.expired. Your sign-in itself should rely on the check answer, which is immediate. See Webhooks.