Official WordPress integration · Version 2.1.1

Passwordless WordPress and WooCommerce authentication with OTP.

Add mobile OTP login, verified signup, protected pages, account recovery and billing-phone verification to WordPress. Classic Checkout and the WooCommerce Checkout Block are both supported.

ZIP package · WordPress 6.2+ · PHP 7.4+ · OTP only

Settings → MeraOTP
Account connectionConnected
mo_live_••••••••••••••••
Ready ✓
Passwordless login[meraotp_login]
Protected content[meraotp_protected]…[/meraotp_protected]

Useful from the first install

Authentication features people can use immediately.

The plugin keeps credentials on the WordPress server and uses the same MeraOTP wallet, API key, rate and delivery records as your account.

01

Passwordless login

Let existing WordPress or WooCommerce customers sign in using the mobile number linked to their account.

02

Verified signup

Create subscriber or WooCommerce customer accounts only after successful mobile OTP verification.

03

Protected pages

Wrap private page content in a shortcode backed by a signed, short-lived OTP verification session.

04

Both checkout types

Enforce billing-phone OTP verification on Classic Checkout and the WooCommerce Checkout Block.

05

My Account access

Add OTP login, signup and passwordless account recovery to WooCommerce My Account.

06

Developer functions

Use backend PHP helpers and authentication hooks without exposing the MeraOTP API key to the browser.

Step 1

Install the plugin

  1. Download meraotp-wordpress.zip using the button above.
  2. In WordPress open Plugins → Add New Plugin → Upload Plugin.
  3. Select the ZIP, choose Install Now, and then Activate.
  4. Open Settings → MeraOTP.
Do not unzip before uploading. WordPress expects the downloadable ZIP package.

Step 2

Connect your MeraOTP account

  1. Create a MeraOTP account, verify it, and add OTP credit.
  2. Open API key in the MeraOTP dashboard and copy your single account key.
  3. Paste it under Settings → MeraOTP and save.
  4. Select Test connection.
  5. Send a real test OTP, then enable the authentication or WooCommerce features you need.
Works on normal and cloud hosting: plugin version 2.3.1 keeps your account API key on the WordPress server and supports shared hosting, Kubernetes and serverless deployments.

Step 3

Add verification to a page

Add a Shortcode block in Gutenberg or paste this shortcode into the classic editor:

[meraotp_verify]

Choose the purpose and change the visible heading when needed:

[meraotp_verify purpose="signup" title="Verify your phone" button_text="Send my code"]

Supported purposes are login, signup, password_reset, transaction, verification, and other.

Authentication

Add login, signup and protected content

Add these shortcodes with a Gutenberg Shortcode block, the Classic Editor or an Elementor Shortcode widget.

Passwordless login

[meraotp_login redirect="/my-account/"]

The mobile must already be stored as the user's verified MeraOTP mobile or WooCommerce billing phone. After verification, WordPress creates its normal authenticated session.

Verified account signup

[meraotp_signup redirect="/welcome/"]

Enable OTP signup under Settings → MeraOTP first. WordPress creates the account only after the OTP succeeds.

Passwordless account recovery

[meraotp_recovery redirect="/my-account/"]

This securely signs an existing customer back in so they can update their account details without first remembering their password.

Protect part or all of a page

[meraotp_protected title="Verify to view this page"]
Private member content goes here.
[/meraotp_protected]

Protected content requires a logged-in WordPress user and a signed OTP verification session that is no more than 30 minutes old.

WooCommerce

Protect checkout and My Account

Open Settings → MeraOTP and enable the integrations you need:

  • Classic checkout: adds OTP controls after billing details and blocks order placement until the billing phone matches.
  • Checkout Block: mounts the same mobile-friendly OTP control and verifies the WooCommerce session again through the Store API before payment.
  • My Account authentication: adds passwordless OTP login and, when enabled, verified signup.
  • OTP signup: permits creation of customer accounts after successful OTP verification.
Changing the billing phone invalidates verification. Checkout verification remains valid for 30 minutes and is cleared after the order is created.

Custom WordPress/PHP

Use the plugin from PHP

The plugin exposes small functions for a custom theme or plugin. Always send from backend PHP, never from browser JavaScript.

<?php
$sent = meraotp_send_otp(
    '9876543210',       // Indian mobile number
    'signup',          // Why the OTP is being sent
    'wordpress_user_42',// Your optional reference
    '',                 // Optional idempotency key
    6                   // OTP length: 4, 5 or 6
);

if (is_wp_error($sent)) {
    error_log($sent->get_error_message());
    return;
}

$message_id = $sent['data']['message_id'];

// Later, verify the code entered by the user.
$checked = meraotp_verify_otp($message_id, '123456');
$verified = !is_wp_error($checked)
    && !empty($checked['data']['verified']);

React after the shortcode verifies a number

add_action('meraotp_phone_verified', function ($mobile, $purpose, $message_id) {
    // Run your server-side action here.
}, 10, 3);

If another form submits the shortcode's meraotp_proof field, validate it on the server with meraotp_validate_proof($proof) before trusting it.

Standalone PHP application

Outside WordPress, call the same API from backend PHP with cURL:

<?php
$payload = json_encode([
    'mobile' => '9876543210',
    'purpose' => 'signup',
    'reference' => 'student_1001',
]);

$ch = curl_init('https://new.meraotp.in/api/v1/otp/send');
curl_setopt_array($ch, [
    CURLOPT_POST => true,
    CURLOPT_POSTFIELDS => $payload,
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_HTTPHEADER => [
        'Authorization: Bearer ' . getenv('MERAOTP_API_KEY'),
        'Content-Type: application/json',
        'Idempotency-Key: signup_' . bin2hex(random_bytes(12)),
    ],
]);
$body = curl_exec($ch);
$status = curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($body === false) {
    throw new RuntimeException(curl_error($ch));
}
curl_close($ch);

$result = json_decode($body, true, 512, JSON_THROW_ON_ERROR);
if ($status < 200 || $status >= 300 || empty($result['success'])) {
    throw new RuntimeException($result['message'] ?? 'OTP could not be sent');
}
$messageId = $result['data']['message_id'];

When the user enters the code, post the returned message_id and OTP to the verify endpoint:

<?php
$ch = curl_init('https://new.meraotp.in/api/v1/otp/verify');
curl_setopt_array($ch, [
    CURLOPT_POST => true,
    CURLOPT_POSTFIELDS => json_encode([
        'message_id' => $messageId,
        'otp' => $userEnteredOtp,
    ]),
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_HTTPHEADER => [
        'Authorization: Bearer ' . getenv('MERAOTP_API_KEY'),
        'Content-Type: application/json',
    ],
]);
$result = json_decode(curl_exec($ch), true, 512, JSON_THROW_ON_ERROR);
curl_close($ch);
$verified = !empty($result['success']) && !empty($result['data']['verified']);

Direct API · Node.js

Use MeraOTP without WordPress

Node.js does not run the WordPress plugin. Use the same OTP API directly from your Node backend and keep the key in an environment variable.

// Node.js 18+
const response = await fetch('https://new.meraotp.in/api/v1/otp/send', {
  method: 'POST',
  headers: {
    Authorization: `Bearer ${process.env.MERAOTP_API_KEY}`,
    'Content-Type': 'application/json',
    'Idempotency-Key': `signup_${crypto.randomUUID()}`
  },
  body: JSON.stringify({
    mobile: '9876543210',
    purpose: 'signup',
    reference: 'student_1001'
  })
});

const result = await response.json();
if (!response.ok || !result.success) {
  throw new Error(result.message || 'OTP could not be sent');
}
const messageId = result.data.message_id;

Verify the code

const response = await fetch('https://new.meraotp.in/api/v1/otp/verify', {
  method: 'POST',
  headers: {
    Authorization: `Bearer ${process.env.MERAOTP_API_KEY}`,
    'Content-Type': 'application/json'
  },
  body: JSON.stringify({ message_id: messageId, otp: userEnteredOtp })
});
const result = await response.json();
const verified = response.ok && result.success && result.data.verified;

Quick fixes

Common setup problems

NETWORK_ERROR
Confirm your WordPress hosting allows outbound HTTPS requests to new.meraotp.in:443, then run Test connection again.
INSUFFICIENT_BALANCE
Add OTP credit to your MeraOTP wallet. The plugin has no separate plan or subscription.
PROVIDER_NOT_CONFIGURED
This is a MeraOTP service configuration problem, not a WordPress setting. Contact MeraOTP support with the request ID.
NETWORK_ERROR
Confirm your host allows outbound HTTPS requests to new.meraotp.in, TLS certificates are current, and no firewall blocks the connection.
No account is linked to that mobile
WooCommerce customers can use the billing phone saved on their account. Other WordPress users can log in normally once, open a page containing [meraotp_login], and verify an unclaimed number to link it.

Ready for passwordless authentication?

Download, connect and choose the features you need.

The plugin is free. Login, signup, protected pages and WooCommerce verification use the prepaid OTP balance and current rate shown in your MeraOTP account.