Verify API

Let good users in. Keep bad actors out with Verify API.

A fully managed turnkey API that verifies users over multiple channels at scale — handling 4.8B+ verifications each year.

Prices starting at $0.05 per successful verification
No credit card required
Screen showing authenticated status with a token input field for two-factor authentication.
Screen showing authenticated status with a token input field for two-factor authentication.

Verify API at a glance

Get a short-and-sweet summary of Verify capabilities, use cases, and pricing in our Twilio Verify fact sheet.

How the Verify API works

An illustration showing different user verification methods including Voice, SMS, WhatsApp, Email and more using Twilio.
An illustration showing different user verification methods including Voice, SMS, WhatsApp, Email and more using Twilio.

Verify is a turnkey API for user verification. Add two-factor authentication across channels like SMS, email, WhatsApp, and TOTP or implement frictionless verification with Silent Network Authentication (SNA). 

Quickly integrate a one-time password authentication (OTP) solution that handles your connectivity, channels, code generation, fraud monitoring, and prevention.

And now, you can add Stytch by Twilio Device Fingerprinting for device-level risk signals that inform when to step up verification.

Build verification steps that feel like a feature, not a frustration 

Trusted user verification with a downright delightful user experience.

Signup verification 

Prevent fake account creation and create a secure signup experience for new users with one-time passwords that can be delivered across channels.

Intuit set up one-time password (OTP) SMS messages to authenticate new customers across the globe while eliminating any friction along the way.

94%

deliverability across the globe

200+

countries deployed in 3 months

Smiling man talking on phone while using laptop, with Intuit logo in the corner.
Smiling man talking on phone while using laptop, with Intuit logo in the corner.

Verify API features

Global user verification is hard—Verify makes it easy.

Woman with glasses and a nose ring smiling at an event, with people in the background.
Woman with glasses and a nose ring smiling at an event, with people in the background.

100% Protection from SMS pumping fraud with Fraud Guard

Fraud Guard has already saved customers over $82 million by blocking 747 million fraud attempts1. With first-to-market innovation, Fraud Guard offers 100% protection against SMS pumping fraud.

  • Phone number management

    Verify procures and manages short codes, long codes, toll free, and global alpha-sender IDs to accelerate global expansion.
  • Carrier-approved templates

    Improve delivery rates with carrier-approved messages templates that automatically translate across 42 languages.
  • Actionable insight

    Dashboards provide conversion and success rates per region and channel, as well as SMS fraud trends to optimize against fraud.
  • Silent Network Authentication

    Secure authentication to protect end users, accounts, and transactions without requiring users to wait or leave your app.
  • PII-less, HIPAA-certified, SOC 2 Type 2

    Develop compliant healthcare and financial service applications that do not require users to provide personally identifiable information (PII).
  • Push authentication

    Embed push functionality in your apps easily.
  • Route optimization

    Verify uses premium telephony routes on Twilio's Super Network to prioritize deliverability and speed.
  • Rate limiting

    Verify's built-in platform protection for service rate limits give you turnkey protections with flexibility.
  • Multiple delivery channels

    OTP delivery via SMS, WhatsApp, voice, and email, all managed through a single API.
  • Global reach

    Verify manages the complexity of changing carrier and government regulations in 200+ regions and countries.

Less code, more security

Integrate Verify into your app in as little as one sprint with its developer-first APIs and client libraries for a quick and confident deployment.

# Download the helper library from https://www.twilio.com/docs/ruby/install
require 'rubygems'
require 'twilio-ruby'

# Find your Account SID and Auth Token at twilio.com/console
# and set the environment variables. See http://twil.io/secure
account_sid = ENV['TWILIO_ACCOUNT_SID']
auth_token = ENV['TWILIO_AUTH_TOKEN']
@client = Twilio::REST::Client.new(account_sid, auth_token)

verification = @client.verify
                      .v2
                      .services('VAXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX')
                      .verifications
                      .create(to: '+15017122661', channel: 'sms')

puts verification.sid

Need help setting up Verify?

Bring your ideal solution to life with technology partners and top-tier consulting partners like Deloitte Digital, Perficient, and more. View partners

Verify and Lookup save time and money. Sweat and tears too.

Get a comprehensive solution to cut costs, increase OTP conversions, and reduce fraud risk.

$103M

saved by Verify Fraud Guard1

5.1B

validations per year2

40%

increase in conversion rates with SNA and Push3

68%+

global conversion rate with Verify2

Build first, buy later. Start your free trial today.

There’s no credit card required to sign up. And when you're ready to scale, you only pay for successful verifications. Simple, fair, and completely transparent.

Man with curly hair in a yellow plaid shirt smiling next to a brick wall
Man with curly hair in a yellow plaid shirt smiling next to a brick wall

Verify FAQs

Twilio Verify is an API for user verification and authentication flows, including one-time passcodes, two-factor authentication, account recovery, and step-up verification. It gives you a managed way to send and validate verification challenges across multiple channels without building the full workflow yourself.

Unlike standard SMS messaging APIs, Verify handles code generation, expiration, rate limiting, and fraud prevention out of the box. The Twilio Authy app is a two-factor authentication (2FA) app that generates secure tokens to protect your accounts from unauthorized access. It's a free mobile app that adds an extra layer of security beyond passwords, requiring a code generated on your device to log in to various online accounts. 

Check out the Verify docs to learn more.

 

Twilio Verify reduces engineering overhead by eliminating the need to build custom code generation, retry logic, carrier routing, or localized template management. Compared to building in-house or using single-channel CPaaS vendors, Verify automatically mitigates SMS toll fraud via integrated Fraud Guard, while maintaining a 94%+ global delivery rate across 180+ countries. It offers turnkey multi-channel fallback and a pay-per-success pricing model, whereas custom builds incur fixed infrastructure costs and messaging charges for unverified attempts.

A general SMS API can send a code. Verify handles the rest of the verification flow.

That includes code generation, expiration, retry logic, rate limits, localized templates, and fraud controls designed for authentication use cases. If you want to ship verification quickly and avoid maintaining that logic yourself, Verify is usually the better fit.

 

Verify automates the common moving parts behind authentication flows: generating passcodes, validating them, managing verification windows, limiting repeat attempts, and supporting multiple verification channels.

It also helps with operational tasks like template localization and protections against SMS pumping fraud. Your team can focus on the user flow and business logic instead of rebuilding verification infrastructure.

 

Verify supports multiple channels, including: SMS, Passkeys, Silent Network Auth, Voice, WhatsApp, Email, TOTP (authenticator apps like Authy and Google Authenticator), Push, and Silent Device Approval. 

Channel availability, pricing, and launch requirements can vary by country, carrier, and configuration. Check the docs and pricing pages for the channels you plan to use before launch.

 

Verify pricing is based on successful verifications, with additional channel fees depending on how the verification is delivered. The exact total cost depends on the channel, destination, and any related messaging or carrier fees. If you are comparing Verify to a DIY SMS build, look at total verification cost, including retries, fraud controls, and operational overhead — not just the cost of sending a message.

You are not billed the verification fee for failed, expired, or uncompleted authorization attempts. A successful verification for an OTP-based authentication channel is one where the user inputs the correct OTP and it is confirmed on the Verify API. If you create your own custom code, you will be charged per created verification. A verification session lasts 10 minutes by default and can contain up to 5 send message attempts.

You can find more detailed rates, international pricing, and links to channel-specific rates on the Verify pricing page.

 

Verify is not the right tool for general transactional messaging, promotional messaging, or ongoing conversations with users.

If you only need to send notifications, use a messaging product like the Twilio Programmable Messaging API instead. If you only need identity or phone number intelligence without sending a verification challenge, use a lookup product like Twilio Lookup API instead.

 

Twilio Verify delivers global reach across 180+ countries and territories, automatically managing carrier sender IDs, short codes, and localized templates. Verify is SOC 2 Type 2 certified, ISO 27001 compliant, GDPR compliant, HIPAA-eligible, and supports PII-less verification architectures. All data is encrypted in transit and at rest. For full details on our overall platform compliance, read our security documentation.

Verify has a rate limit of five verification attempts to the same entity within 10 minutes. If you send more than this, you’ll get an error message that you’ve reached the limit for maximum attempts. These limits are in place to prevent fraud and abuse. 

You can set your own limits, too. Our docs explain how to protect your Verify application with service rate limits, and we also outline rate limits and timeout considerations for your app.

 

1 From Sept '23 up to 31 Dec ‘25

2 Twilio 2024 internal data, based on those customers who provide conversion data

3 Curve results with Twilio

Let's find the right products for you

Generating your product picks...

See your product picks