=== MeraOTP – OTP Verification for WordPress ===
Contributors: meraotp
Tags: otp, mobile verification, woocommerce, authentication, india
Requires at least: 6.2
Requires PHP: 7.4
Stable tag: 2.3.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Add Indian mobile OTP verification to WordPress and WooCommerce with your MeraOTP account.

== Description ==

MeraOTP connects WordPress to the MeraOTP OTP-only API. It keeps the account API key on your WordPress server and provides:

* A responsive verification form through the `[meraotp_verify]` shortcode.
* Passwordless WordPress login and verified account signup.
* OTP-protected page content with a short-lived signed verification session.
* Optional billing-phone verification on WooCommerce Classic Checkout and Checkout Block.
* Optional OTP login and signup on WooCommerce My Account.
* Simple server-side Bearer authentication with one account API key.
* A connection test that validates the API key and outbound HTTPS connection.
* A real test-OTP tool.
* Configurable 4, 5 or 6-digit OTPs.
* PHP functions for sending, verifying, and checking an OTP.
* A server-side action after successful verification.
* A signed, short-lived verification proof for custom form integrations.

The plugin does not send promotional or general SMS messages.

== External service ==

This plugin connects to MeraOTP at https://new.meraotp.in to send and verify OTPs. It sends the configured MeraOTP API key, the recipient's Indian mobile number, OTP purpose, an optional internal reference, request idempotency value, and normal HTTP connection metadata such as the hosting server IP. When verifying, it sends the MeraOTP message ID and the OTP entered by the visitor.

Data is sent only when an administrator runs a connection/test action, when a visitor requests or verifies an OTP through a MeraOTP form, when WooCommerce checkout verification is used, or when site code calls a MeraOTP PHP function.

Service terms: https://new.meraotp.in/terms-and-conditions
Privacy policy: https://new.meraotp.in/privacy-policy
Acceptable use: https://new.meraotp.in/acceptable-use
DLT guidance: https://new.meraotp.in/dlt-compliance

== Installation ==

1. Upload `meraotp-wordpress.zip` through Plugins → Add New Plugin → Upload Plugin.
2. Activate MeraOTP.
3. Open Settings → MeraOTP.
4. Paste the single API key shown in your MeraOTP account and save.
5. Choose Test connection. No IP or domain configuration is required.
6. Enable the required authentication and WooCommerce switches.
7. Add a MeraOTP shortcode to a page or use the automatic WooCommerce integrations.

Complete guide: https://new.meraotp.in/wordpress-plugin

== Shortcode ==

Basic:

`[meraotp_verify]`

Customized:

`[meraotp_verify purpose="signup" title="Verify your phone" button_text="Send my code"]`

Passwordless WordPress login:

`[meraotp_login redirect="/my-account/"]`

Verified account signup:

`[meraotp_signup redirect="/welcome/"]`

Passwordless account recovery:

`[meraotp_recovery redirect="/my-account/"]`

OTP-protected content:

`[meraotp_protected]Private member content[/meraotp_protected]`

Supported purposes: `login`, `signup`, `password_reset`, `transaction`, `verification`, and `other`.

== PHP API ==

Send:

`$result = meraotp_send_otp('9876543210', 'signup', 'user_42', '', 6);`

Verify:

`$result = meraotp_verify_otp($message_id, $otp_entered_by_user);`

Status:

`$result = meraotp_otp_status($message_id);`

All functions return a decoded MeraOTP response array on success or `WP_Error` on failure.

Successful shortcode verification fires:

`do_action('meraotp_phone_verified', $mobile, $purpose, $message_id);`

Successful passwordless login or signup also fires:

`do_action('meraotp_user_authenticated', $user_id, $mobile, $mode);`

Validate a proof posted from a custom form:

`$payload = meraotp_validate_proof($_POST['meraotp_proof']);`

== Frequently Asked Questions ==

= Does the plugin expose my API key? =

No. API calls are made by WordPress on the server. The key is not localized into frontend JavaScript or added to HTML.

= Does it require an OTP subscription? =

No. OTP uses your prepaid MeraOTP wallet and the current rate shown in your account.


= Does it support WooCommerce Checkout Blocks? =

Yes. Version 2.0 supports both Classic Checkout and the WooCommerce Checkout Block. Enable the matching integration under Settings → MeraOTP.

= Can I put my API key in JavaScript? =

No. Keep it in WordPress settings or server-side configuration only.

== Changelog ==

= 2.3.1 =

* Simplified authentication guidance across the plugin.

= 2.3.0 =
* Simplified connection testing and account setup.
* Uses the same Bearer API-key flow as the PHP and Node.js guides.
* Existing MeraOTP accounts, keys and OTP/WooCommerce features remain compatible.

= 2.1.1 =
* Added a 4, 5 or 6-digit OTP length setting used across WordPress and WooCommerce flows.
* Kept the SMS request compatible with the single-variable OTP template.

= 2.1.0 =

= 2.0.0 =
* Added passwordless WordPress login and verified account signup.
* Added signed 30-minute OTP sessions and protected-content shortcode.
* Added WooCommerce My Account OTP authentication.
* Added server-enforced OTP verification for WooCommerce Checkout Block.
* Retained Classic Checkout verification and standalone phone verification.

= 1.0.1 =
* Improved compatibility with shared-hosting HTTP proxies and UTF-8 response markers.
* Added actionable HTTP status and content-type diagnostics when a host returns HTML instead of API JSON.
* Safely follows HTTPS redirects during server-to-server API requests.

= 1.0.0 =
* Initial release.
