Phone verification is an important, high-confidence step in a registration flow to verify that a user has the device they claim to have. Adding phone verification to your application will greatly reduce your number of fraudulent registrations and protect future application users from having their numbers registered by scammers.
This quickstart guides you through creating a Node.js, AngularJS, and MongoDB app that requires a phone verification step to create an account. Two channels of phone verification are demoed: SMS and voice.
Ready to add phone verification to a demo app and keep the bad actors away? Enter stage left!
Once logged in, visit the Authy Console. Click on the red 'Create New Aplication' (or big red plus ('+') if you already created one) to create a new Authy application then name it something memorable.
Twilio will redirect you to the Settings page next:
Click the eyeball icon to reveal your Production API Key, and copy it somewhere safe. You will use the API Key during the application setup step below.
While Twilio's Verify API doesn't return any user information you'll need to store, to continue working on the app after this Quickstart you'll want a database. For this demo, we built our user database on top of MongoDB.
Instructions for installing MongoDB vary depending on platform. Please follow the appropriate link for instructions on how to install MongoDB for your platform.
After you install MongoDB, launch it. On *NIX and OSX, this command may be as simple as:
Start by cloning our Node.js repository. Enter the directory and use npm to install all of our dependencies:
- Open the file
ACCOUNT_SECURITY_API_KEYto the API Key from the above step
- Now, save the file as
Depending on your system, you need to set the environmental variables before you continue. On *NIX, you can run:
On Windows, depending on your shell, you will have to use
Alternatively, you could use a package such as autoenv to load it at startup.
And then... actually, that's all the setup you'll need.
Now, launch Node with:
Assuming your API Key is correctly entered and MongoDB is running, you'll soon get a message that the app is up!
Keeping your phone at your side, vist the phone verification page of the demo at http://localhost:1337/verification/
Country Code and
Phone Number, then choose which channel to request verification over, 'SMS' or 'CALL' (Voice). Finally, hit the blue 'Request Verification' button and wait.
You won't be waiting long - you'll either receive a phone call or an SMS with the verification token. If you requested a phone call, as an additional security feature you may need to interact to proceed (by entering a number on the phone keypad).
Either way you requested the passcode, enter the token into the Verification entry form and click 'Verify Phone':
And with that, your demo app is protected with Twilio Verify! You can now log out to try the other channel.
Your demo app is now keeping hordes of fraudulent users from registering with your business and polluting the database. Next, you should check out all of the variables and options available to you in the Verify API Reference. Also, for protecting your customers in an ongoing manner (with this same codebase) try the Node.js Authy Two-Factor Authentication Quickstart.
After that, take a stroll through the Docs for more Account Security demos and tutorials - as well as sample web applications using all of Twilio's products. Encore!