Features API Demo Try it

Service activity

Counts, without personal data

We count requests, not people. Code requests include unsuccessful attempts that passed the rate limit.

35Code requests
13Successful verifications

The request counter includes the history that could be recovered; earlier requests may be missing. Successful verifications are counted from 02/10/2026.

Beta

Your code, already in the bot

Share your own contact once and enable automatic codes. On your next website request, the bot sends the code directly to your chat.

Integrating AuthPhone for the first time? Start with standard sign-in. Do not use the beta links (start=remember) as your standard sign-in buttons. First integrate and test code retrieval with start=start; add Remember me afterwards as an optional feature. Standard integration guide →

Try it in the demo

Optional. The usual contact-sharing flow stays available.

AuthPhone Illustration, not a real code
  1. 01
    Verify your own contact

    Open a private chat with the bot and use its Share contact button.

  2. 02
    Choose to remember the link

    Read the storage notice and tap “Enable automatic codes” in the bot.

  3. 03
    Request a code on the website

    Your connected bot sends it without asking for your contact again.

AuthPhone sign-in code482 916Valid for 3 minutes. Never share it with another person.

For this beta, we retain a keyed fingerprint of your phone number, an encrypted chat link, consent date and delivery counters until deletion. Phone numbers and codes are not written to disk. Send /forget to the bot to delete the link. About storage

A small API for a clear job

Request a code, let the user collect it in Telegram, then verify it from your backend.

Short-lived verification codes

Six-digit codes are checked with HMAC-SHA256. Verification records expire after three minutes and are removed after a successful check.

Telegram code delivery

Users open the Telegram bot and share their own contact to receive a code for the same phone number.

International phone numbers

Accept numbers with an international country code, such as +1 or +44. The number must match the contact shared in Telegram.

One active code per number

A number can have one active code for three minutes. A successful check consumes it; five incorrect attempts invalidate it.

RESTful API

Two JSON endpoints for requesting and verifying codes. Use them with Node.js, Python, PHP or any backend that supports HTTP.

API documentation

Start with two POST requests. No API key is needed. Call /auth from your backend before creating a user session.

POST /generate-code

Request a six-digit code. The response confirms the phone number; the code itself is delivered by the bot.

{
  "phoneNumber": "+12025550123"
}
Response:
{
  "status": "ok",
  "code": "12025550123"
}
POST /auth

Verify the code from your backend. Accept only status: ok and message: success.

{
  "phoneNumber": "12025550123",
  "code": "366275"
}
Response:
{
  "status": "ok",
  "message": "success"
}
GET /health

Check service availability

Response:
{
  "status": "ok",
  "message": "Server is running"
}

Where it fits

For apps whose users can receive a verification code in Telegram.

Websites

Add a phone verification step to your website with a small HTTP integration.

Mobile apps

Confirm a phone number during mobile onboarding through your own backend.

E-commerce

Verify a contact number before confirming an order or updating account details.

Internal tools

Add phone verification to tools used by teams already on Telegram.

How phone verification works

Try the demo first, then connect your backend. The user needs Telegram and a matching phone number.

1

Collect a phone number

Ask for the international country code and phone number.

2

Request and verify a code

Call /generate-code to issue a code and /auth to check the code entered by the user.

3

Let the user open Telegram

The user opens our Telegram bot, taps Share contact, and copies the code back to your app.

integration.js
// Request a verification code
const response = await fetch('https://authphone.su/generate-code', {
  method: 'POST',
  headers: {
    'Content-Type': 'application/json'
  },
  body: JSON.stringify({
    phoneNumber: '+12025550123'
  })
});

// Verify from your backend before creating a session
const verify = await fetch('https://authphone.su/auth', {
  method: 'POST',
  headers: {
    'Content-Type': 'application/json'
  },
  body: JSON.stringify({
    phoneNumber: '+12025550123',
    code: '366275'
  })
});

Standard sign-in: complete integration

Your website provides the form and bot link. AuthPhone creates and checks the code. Opening the bot does not create a code.

  1. Collect the phone number, including its country code, on your website.
  2. From your backend, send POST https://authphone.su/generate-code with JSON {"phoneNumber":"+12025550123"}. Check both the HTTP status and the JSON status: "ok" before proceeding. The response field "code" contains the submitted phone number, not the OTP.
  3. Show the Telegram button below and a field for the six-digit code on your website. The user opens the bot, presses Start if prompted, and shares their own contact using the bot button. The contact must match the requested phone number; forwarded contacts do not work.
  4. The user returns to your website and enters the code within three minutes of requesting it.
  5. From your backend, send POST https://authphone.su/auth with the same phoneNumber and the six-digit code as a string. Create your user session only if the HTTP request succeeds and JSON contains both status: "ok" and message: "success".

Bot button: copy this HTML

<a href="https://t.me/myauth_superbot?start=start"
   target="_blank" rel="noopener noreferrer">
  Get code in Telegram
</a>

These are fixed links to AuthPhone bots. Do not put a phone number, OTP or secret in the URL. AuthPhone does not add buttons to your website or redirect the user automatically.

Remember me is an optional beta

Use start=start for standard sign-in. Links with start=remember belong to the optional Remember me setup; do not use them as your standard integration example. Automatic delivery is available only after the user explicitly enables the beta inside the bot. Keep manual code retrieval available.

If no code arrives, check the /generate-code response first. code_pending means an earlier code is still active; retrieve it in the bot or wait until it expires. rate_limited means you must wait before requesting again. A successful request does not confirm that the bot has delivered the message.

What we store

No database of phone numbers or codes

We do not write phone numbers or verification codes to disk. For up to three minutes, memory holds HMAC-SHA256 values for the number and code, a random identifier and an expiry time. The record is deleted after successful verification or expiry.

For ordinary requests, only aggregate counters are retained. The optional automatic-code beta also keeps a keyed phone fingerprint, an encrypted chat link, consent date and delivery counters until you delete the link with /forget in the bot. This website has no analytics trackers.

The service temporarily processes your number and code to deliver and verify them. IP-based rate limiting keeps temporary state in memory for up to three minutes. Telegram manages chat messages and shared contacts under its own policies.

Before you integrate

Does this API send SMS?

No. The user receives the code from our Telegram bot after sharing their own contact. They need a Telegram account with the same phone number. This is not an SMS service.

What are the limits?

Up to five code requests per IP in three minutes. One active code per phone number, a three-minute lifetime, and up to five incorrect attempts. A successfully verified code cannot be reused.

How should I integrate it?

Request and verify codes from your backend. Create a session only after /auth returns status: ok and message: success. Handle expired codes and messaging service outages in your app.

Try phone verification with Telegram

Test the full flow before you integrate. Free to use, with request limits to reduce abuse.