Two MSG91 steps work together. MSG91 · Send an OTP — MSG91 sends a one-time code by SMS — has MSG91 make a code and text it to a mobile number. MSG91 · Verify an OTP — Checks a code someone typed against the one MSG91 sent — asks MSG91 whether the code someone gives back is right. MSG91 keeps the code; Bizomate never sees it.
A typical use: a form asks for a mobile number and starts one workflow that sends the code; a second form asks for the code and starts a workflow that verifies it, then carries on only when verified is true.
Who can do this
Workspace Admins and Editors, on every plan. Viewers see the steps' settings but cannot change them.
Before you start
- An MSG91 connection in this workspace — see Connect MSG91.
- An OTP template in MSG91. For Indian numbers it must come from a DLT-approved OTP template — see SMS to India: DLT templates in Connect MSG91.
Steps
Send the code:
- Select + where the code should be sent. In the step picker, open Apps, select MSG91, then Send an OTP. Or search OTP.
- In Connection, choose your MSG91 connection. If it is the only one, it is already chosen.
- In OTP template id, paste the template's id from MSG91 — A DLT-approved OTP template in MSG91.
- In Mobile, the number — With the country code. Spaces, hyphens and a
+are taken off, so +91 98765-43210 goes as 919876543210 (an example number). Usually a value from the trigger, such as a form's answer. - In Digits, how long the code is — 4 to 9. The default is 6.
- In Expires after (minutes), how long the code works. The default is 10.
- Select Run this step to send a test code to that number.
Check the code:
- Select + where the code should be checked. In the step picker, open Apps, select MSG91, then Verify an OTP.
- In Connection, choose the same MSG91 connection.
- In Mobile, the same number the code was sent to, written the same way.
- In OTP, the code they typed — The code they typed — from a form, say.
- Select Run this step to check it.
- Add an IF step after it on
{{ steps.verify_an_otp.verified }}to go one way for a right code and another for a wrong one.
Output
Send an OTP:
| Field | What it is |
|---|---|
sent |
True: MSG91 sent the code. When MSG91 refuses, the step fails with its words instead. |
requestId |
MSG91's id for the request. |
Verify an OTP:
| Field | What it is |
|---|---|
verified |
True when the code is right and still in time. |
message |
MSG91's own words about it. |
Good to know
- Check
verified. When MSG91 answers that the code does not match or has expired — however it says so — the step givesverifiedfalse, with MSG91's words inmessage. If MSG91 instead refuses the request outright, the step fails with MSG91's words — set If this step fails to Carry on and pass the error along if a wrong code should not stop the run. - Digits outside 4 to 9 are brought inside: 3 becomes 4, 12 becomes 9. Expires after is kept between 1 and 1,440 minutes (a day).
- Sending again sends a new code to the same number. MSG91 decides whether the earlier one still works.
- The number must match. Verify with the number written exactly as it was sent to — the same country code, no spaces.
- Each code is an SMS, billed by MSG91.
If something goes wrong
| What you see | Why | What to do |
|---|---|---|
sent is false |
MSG91 answered, but did not send. | Check the OTP template and the number in MSG91's reports. |
verified is false |
The code is wrong, has expired, or was checked for a different number. | Send a new code. |
| MSG91 refused: … | MSG91 turned the request away, in its own words — often a wrong template id or number. | Check OTP template id and Mobile. |
| Template is empty when the step ran — an earlier step may not have given the value it names. | OTP template id came out empty. | Fill it in. |
| Mobile is empty when the step ran — … / OTP is empty when the step ran — … | The value came out empty. | Check the values it reads. |
| MSG91 refused: … Check the connection's details on Connections. | The auth key was changed or deleted in MSG91. | Revoke the connection and reconnect it with the new key. |