Passwordless login
Let existing WordPress or WooCommerce customers sign in using the mobile number linked to their account.
Official WordPress integration · Version 2.1.1
Add mobile OTP login, verified signup, protected pages, account recovery and billing-phone verification to WordPress. Classic Checkout and the WooCommerce Checkout Block are both supported.
[meraotp_login][meraotp_protected]…[/meraotp_protected]Useful from the first install
The plugin keeps credentials on the WordPress server and uses the same MeraOTP wallet, API key, rate and delivery records as your account.
Let existing WordPress or WooCommerce customers sign in using the mobile number linked to their account.
Create subscriber or WooCommerce customer accounts only after successful mobile OTP verification.
Wrap private page content in a shortcode backed by a signed, short-lived OTP verification session.
Enforce billing-phone OTP verification on Classic Checkout and the WooCommerce Checkout Block.
Add OTP login, signup and passwordless account recovery to WooCommerce My Account.
Use backend PHP helpers and authentication hooks without exposing the MeraOTP API key to the browser.
Step 1
Step 2
Step 3
Add a Shortcode block in Gutenberg or paste this shortcode into the classic editor:
[meraotp_verify]
Choose the purpose and change the visible heading when needed:
[meraotp_verify purpose="signup" title="Verify your phone" button_text="Send my code"]
Supported purposes are login, signup, password_reset, transaction, verification, and other.
Authentication
Add these shortcodes with a Gutenberg Shortcode block, the Classic Editor or an Elementor Shortcode widget.
[meraotp_login redirect="/my-account/"]
The mobile must already be stored as the user's verified MeraOTP mobile or WooCommerce billing phone. After verification, WordPress creates its normal authenticated session.
[meraotp_signup redirect="/welcome/"]
Enable OTP signup under Settings → MeraOTP first. WordPress creates the account only after the OTP succeeds.
[meraotp_recovery redirect="/my-account/"]
This securely signs an existing customer back in so they can update their account details without first remembering their password.
[meraotp_protected title="Verify to view this page"]
Private member content goes here.
[/meraotp_protected]
Protected content requires a logged-in WordPress user and a signed OTP verification session that is no more than 30 minutes old.
WooCommerce
Open Settings → MeraOTP and enable the integrations you need:
Custom WordPress/PHP
The plugin exposes small functions for a custom theme or plugin. Always send from backend PHP, never from browser JavaScript.
<?php
$sent = meraotp_send_otp(
'9876543210', // Indian mobile number
'signup', // Why the OTP is being sent
'wordpress_user_42',// Your optional reference
'', // Optional idempotency key
6 // OTP length: 4, 5 or 6
);
if (is_wp_error($sent)) {
error_log($sent->get_error_message());
return;
}
$message_id = $sent['data']['message_id'];
// Later, verify the code entered by the user.
$checked = meraotp_verify_otp($message_id, '123456');
$verified = !is_wp_error($checked)
&& !empty($checked['data']['verified']);
add_action('meraotp_phone_verified', function ($mobile, $purpose, $message_id) {
// Run your server-side action here.
}, 10, 3);
If another form submits the shortcode's meraotp_proof field, validate it on the server with meraotp_validate_proof($proof) before trusting it.
Outside WordPress, call the same API from backend PHP with cURL:
<?php
$payload = json_encode([
'mobile' => '9876543210',
'purpose' => 'signup',
'reference' => 'student_1001',
]);
$ch = curl_init('https://new.meraotp.in/api/v1/otp/send');
curl_setopt_array($ch, [
CURLOPT_POST => true,
CURLOPT_POSTFIELDS => $payload,
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'Authorization: Bearer ' . getenv('MERAOTP_API_KEY'),
'Content-Type: application/json',
'Idempotency-Key: signup_' . bin2hex(random_bytes(12)),
],
]);
$body = curl_exec($ch);
$status = curl_getinfo($ch, CURLINFO_HTTP_CODE);
if ($body === false) {
throw new RuntimeException(curl_error($ch));
}
curl_close($ch);
$result = json_decode($body, true, 512, JSON_THROW_ON_ERROR);
if ($status < 200 || $status >= 300 || empty($result['success'])) {
throw new RuntimeException($result['message'] ?? 'OTP could not be sent');
}
$messageId = $result['data']['message_id'];
When the user enters the code, post the returned message_id and OTP to the verify endpoint:
<?php
$ch = curl_init('https://new.meraotp.in/api/v1/otp/verify');
curl_setopt_array($ch, [
CURLOPT_POST => true,
CURLOPT_POSTFIELDS => json_encode([
'message_id' => $messageId,
'otp' => $userEnteredOtp,
]),
CURLOPT_RETURNTRANSFER => true,
CURLOPT_HTTPHEADER => [
'Authorization: Bearer ' . getenv('MERAOTP_API_KEY'),
'Content-Type: application/json',
],
]);
$result = json_decode(curl_exec($ch), true, 512, JSON_THROW_ON_ERROR);
curl_close($ch);
$verified = !empty($result['success']) && !empty($result['data']['verified']);
Direct API · Node.js
Node.js does not run the WordPress plugin. Use the same OTP API directly from your Node backend and keep the key in an environment variable.
// Node.js 18+
const response = await fetch('https://new.meraotp.in/api/v1/otp/send', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.MERAOTP_API_KEY}`,
'Content-Type': 'application/json',
'Idempotency-Key': `signup_${crypto.randomUUID()}`
},
body: JSON.stringify({
mobile: '9876543210',
purpose: 'signup',
reference: 'student_1001'
})
});
const result = await response.json();
if (!response.ok || !result.success) {
throw new Error(result.message || 'OTP could not be sent');
}
const messageId = result.data.message_id;
const response = await fetch('https://new.meraotp.in/api/v1/otp/verify', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.MERAOTP_API_KEY}`,
'Content-Type': 'application/json'
},
body: JSON.stringify({ message_id: messageId, otp: userEnteredOtp })
});
const result = await response.json();
const verified = response.ok && result.success && result.data.verified;
Quick fixes
new.meraotp.in:443, then run Test connection again.new.meraotp.in, TLS certificates are current, and no firewall blocks the connection.[meraotp_login], and verify an unclaimed number to link it.Ready for passwordless authentication?
The plugin is free. Login, signup, protected pages and WooCommerce verification use the prepaid OTP balance and current rate shown in your MeraOTP account.