Miss OTP · missed-call verification

Miss OTP. India’s best alternative to SMS & WhatsApp OTP.
Ready in minutes. Not days.

Simply give a missed call and get your number verified. The network hands us the caller ID, and that is the proof — no SMS to be delayed, no DLT registration to sit through, no WhatsApp Business account to get approved. Two HTTP calls and you are done.

Try it on your own phone — sign up free and test it in two minutes

No DLT registrationVerified in ~3 secondsCharged only when a number verifies

What your user sees

1
You start a verification

One POST with the number your user typed. You get back a request id and the number to display.

2
They give a missed call

From the handset they are claiming. They can cut it the second it rings — we hang up anyway.

3
You get the verdict

Poll the status endpoint, or take our signed webhook. Typically two to four seconds after they press dial.

Nothing sent to the phone
Nothing for the user to type
Nothing for you to register

Lovable, Bolt, Cursor, Replit, v0, Claude Code

Built your app with an AI coding tool? Need to verify mobile numbers?

Sign up, get a key, paste one prompt into your AI tool — it writes the server calls, the screen and the voice fallback. Live in minutes: no DLT, no SMS templates, no approval wait.

Why teams switch

The paperwork is the product

Everyone’s OTP works once it is live. The difference is what stands between you and live — and what happens to the codes that never arrive.

 SMS OTPWhatsApp OTPMissed call
Time to first verificationDays — DLT cycleDays — BSP onboardingMinutes
DLT entity + header registrationRequired—Not required
Template approvalRequiredRequiredNot required
Works with zero balance / no dataYesNoYes
Can be delayed in a queueYesYesNo — it is a live call
Code the user can be tricked into reading outYesYesThere is no code
You pay for failed attemptsUsuallyUsuallyNever
Cost per attempt₹0.12–0.22~₹0.12₹0.10–0.20

One row goes against us, and we are leaving it in: per message, direct-route Indian SMS is cheaper than we are. It is also the row that matters least, because it prices the attempts that arrive — not the days you spend blocked on DLT, and not the users you lose to a code that never lands. Most teams put missed call first and keep SMS underneath as the fallback.

Ten seconds, start to finish

What your user actually does

  1. Your app asks for a missed callOne POST to start. Show the number we send back.
  2. The user rings, and we hang upWe reject the call before it connects, so it costs them nothing.
  3. The number is verifiedThe caller ID from the network matches your pending request.
  4. Your server finds outPoll the status endpoint, or get our signed webhook.

The whole integration

Two calls. No SDK to install.

One POST to start, one GET to check. Anything that speaks HTTP is supported, which is why there is no SDK — it would be longer than the integration.

Your number, or ours

Start on our shared verification line. Move to a number of your own when volume justifies it.

Poll, or don’t

Set an HTTPS callback and we POST the moment a number verifies, HMAC-signed so you can prove it came from us.

Scoped and rate-limited

Five-minute windows, one request per attempt, per-number throttling. A verification cannot be replayed or read across accounts.

A fallback for the rest

User can’t give a missed call? Voice OTP rings them and reads a code — same key, same webhook, billed only when they answer.

Node — the entire client
// 1 — start a verification
const start = await fetch("https://api.nacaller.com/api/verify/start", {
  method: "POST",
  headers: {
    "Authorization": "Bearer " + process.env.NACALLER_KEY,
    "Content-Type": "application/json",
  },
  body: JSON.stringify({ phone: "9876543210" }),
}).then(r => r.json());

// Show start.callNumber to the user: "Give a missed call to this number."

// 2 — poll until it flips (or receive our webhook instead)
const { verified } = await fetch(
  `https://api.nacaller.com/api/verify/status/${start.requestId}`,
  { headers: { "Authorization": "Bearer " + process.env.NACALLER_KEY } },
).then(r => r.json());

Full request/response reference in the developer docs; your API key and webhook secret live in your dashboard once you sign up.

Pricing

You pay for numbers that verify

A request nobody calls costs us no telephony, so it costs you nothing. Credits are prepaid, they never expire, and there is no monthly fee underneath them.

Also chasing leads by hand? NaCaller calls your Facebook and Instagram leads within seconds, in Telugu, and hands you the warm ones.

See NaCaller
Starter

₹199

1,000 verifications · ₹0.20 each

  • Credits never expire
  • Only verified numbers count
  • Failed attempts are free
  • Webhooks included
  • No DLT, no templates, no waiting
Start free
Most popular

₹749

5,000 verifications · ₹0.15 each

  • Credits never expire
  • Only verified numbers count
  • Failed attempts are free
  • Webhooks included
  • No DLT, no templates, no waiting
Start free
Business

₹2,999

25,000 verifications · ₹0.12 each

  • Credits never expire
  • Only verified numbers count
  • Failed attempts are free
  • Webhooks included
  • No DLT, no templates, no waiting
Start free
Scale

₹9,999

1,00,000 verifications · ₹0.10 each

  • Credits never expire
  • Only verified numbers count
  • Failed attempts are free
  • Webhooks included
  • No DLT, no templates, no waiting
Start free

25 free verifications and 5 voice calls per account, with your first key — real ones on the live line, no card.GST applicable as per Indian regulations. Higher volumes: tell us your number.

Where it fits

Anywhere a number has to be real

Signup and login

Verify at the moment of account creation, before a fake number becomes a row in your users table.

High-drop-off forms

Loan applications, admissions, KYC starts. The wait for an SMS is where these forms are abandoned.

Delivery and service

Confirm the number a rider or technician will actually reach before the job is dispatched.

For the developer wiring this in

The questions you'd ask before your first commit

18questions, answered without a sales call. Where an answer is “that part is on you”, we say so.

How does missed-call OTP verification actually work?
You POST the number your user typed. We return a request id and a phone number. Your user gives a missed call to that number from the handset they are claiming — they can cut it the moment it rings. The network hands us their caller ID, we match it to your pending request, and your poll (or our webhook) flips to verified. Nothing is ever sent to the phone, which is why nothing can be delayed, filtered or undelivered.
Can I send OTP SMS in India without DLT registration?
Not legally, and not reliably — since 2021 TRAI requires every enterprise sending transactional or OTP SMS to register its entity, its sender header and its templates on a DLT platform, and unregistered traffic gets blocked at the operator gateway. That is the whole reason this product exists. A missed call is not an SMS: there is no header and no template, so there is nothing to register and nothing to get rejected. You can be verifying real numbers today.
How long does DLT registration actually take?
Entity registration is typically 1–3 working days, header approval 1–3 more, and each template 1–7 — so 3–7 working days when your paperwork is clean, and two to six weeks when it is not. Then every change to your message wording starts a fresh template approval. Teams find us on day two of that wait.
How does this compare to MSG91, 2Factor, SMSCountry or Twilio?
Honestly: on raw price per message, direct-route Indian SMS providers beat us — quality transactional SMS lands around ₹0.10–₹0.20, and Twilio around ₹1.50–₹2.00 once forex and markup are in. We do not claim to be the cheapest per unit and you should not believe anyone in this category who does. What we beat them on is the two things that actually cost you money: the days you spend blocked on DLT before you can ship, and the verifications that never complete because the SMS did not arrive. Use us to launch, and to catch the users SMS loses.
Are there other missed-call verification providers in India?
Yes — Cognalys is the best-known, and there are SMS providers that bolt a missed-call fallback onto their stack. We are not going to pretend we invented the mechanism. What we offer is a two-call API with no SDK, credits that are charged only on success and never expire, no monthly platform fee, and an account that also gives you AI voice calling if you ever need it. Compare us on those, not on novelty.
Why do OTP SMS messages fail to arrive in India?
Four common causes, all outside your code. A template that does not byte-match the registered DLT template gets rejected at the gateway. Carrier spam filters flag traffic from headers with poor reputation. Peak-hour routing bottlenecks on Jio, Airtel and Vi delay delivery during festive or UPI surges. And handset-level filtering and DND settings quietly bin the rest. None of these apply to a live inbound call.
Does it improve completion rate, or just cost?
Completion rate, in the places it matters most. In tier-2 and tier-3 markets — which is most of India — voice coverage is reliable where SMS delivery is not, and a user who has to wait 40 seconds for a code abandons the form. A missed call resolves in about three seconds and needs no data, no balance and nothing to read. That is where the number moves.
Is this secure enough for my app?
For signup, login and lead capture, yes — it is proof of possession at the same practical strength as an SMS OTP, and it removes the two ways SMS codes actually leak: a code readable on a lock screen, and a user reading a code aloud to someone impersonating support. There is no code to read. For authorising a payment, a device change or a regulated KYC step, use it as one factor, not the only one — those flows want an explicit confirmed code with an audit trail. We would rather tell you that than sell you a verification you will regret at audit.
What stops someone spoofing the caller ID?
Layered limits rather than a single claim. We only match 10-digit Indian mobile numbers, so the international routes where spoofing is practical do not resolve to a verifiable number. Each verification is bound to one request with a five-minute window, cannot be replayed, and cannot be read across accounts. Attempts are throttled per number and per key. The residual risk is comparable to SMS, which is spoofable at the SS7 layer in ways most teams never think about.
Do I have to poll, or can you send me a webhook?
Either. Polling the status endpoint is one line and fine for a signup screen the user is watching. If you would rather not poll, set an HTTPS callback URL and we POST the moment a number verifies, with an HMAC over the exact body bytes in the X-MissOTP-Signature header so you can prove the call came from us and detect a replay.
What does it cost, and what am I charged for?
Verified numbers only. A request that is started and never called costs you nothing, because an unanswered request costs us no telephony either. Credits are prepaid, they do not expire, and there is no monthly minimum, platform fee or per-seat charge underneath them. Your first 25 verifications and 5 voice calls are free, once per account, and run against the live line, not a sandbox that behaves differently.
Does my user pay for the missed call?
In practice, no. The call is hung up the instant it reaches us, so it stays a missed call. Your user needs no data, no balance, no WhatsApp and no app — it works on the cheapest feature phone in the market.
How do I integrate it with React Native, Flutter, Laravel or Django?
The same way in all four: two HTTP calls from your server. There is no SDK because an SDK would be longer than the integration, and no native module because nothing needs to touch the handset — you are not reading SMS, so you need no SMS-retriever permission, no Android autofill hash and no App Store justification for a permission you would rather not request. Keep the API key server-side and your client only ever sees a number to display and a request id to poll.
Can I keep my existing SMS provider?
You should. The pattern we recommend is missed call first, your existing SMS underneath as the fallback link — one branch in your code. The faster path takes most of the traffic, your SMS spend drops by that share, and users on whom the missed call fails still get verified. Nothing has to be ripped out to try this.
Is there a sandbox or a free trial?
Issuing your first API key includes free verifications with no card, against the live line. There is deliberately no sandbox: a sandbox that always succeeds teaches you nothing about the flow you are shipping, and every OTP integration that broke in production passed in one.
Does it work for landlines or international numbers?
Indian mobile numbers only, today. We reject anything that is not a valid 10-digit Indian mobile at the start call, rather than letting your user sit waiting for a verification that could never arrive. If you need other countries, tell us which and we will say plainly whether we can serve them.
What happens if the user calls from a different number?
Nothing verifies. The match is on caller ID, so a call from any other handset finds no pending request and is hung up. That is the security property rather than a limitation — it is exactly what proves the user holds the number they typed.
What are your uptime and support commitments?
The verification line runs on the same telephony that carries our AI calling product, so it is not a side project we forget to monitor. Support is WhatsApp and email to people who can read the logs, not a ticket queue. We are a small Indian team and we would rather tell you that than imply a 24/7 NOC we do not have.

Miss OTP for developers

Phone verification questions developers ask

12questions, answered without a sales call. Where an answer is “that part is on you”, we say so.

How do I add phone number verification to a Lovable, Bolt, v0 or Replit app?
Use Miss OTP by NaCaller, which takes two HTTP calls and needs no SDK. Your user types their number, and your server sends POST https://api.nacaller.com/api/verify/start with { "phone": "<10-digit mobile>" } and your API key as a Bearer token. The response has a requestId and a callNumber. Your screen then says "Give a missed call to <callNumber>". Your server polls GET https://api.nacaller.com/api/verify/status/<requestId> until verified is true, or waits for our webhook. Keep the key out of browser code. Put both calls in a server-side function, such as a Supabase Edge Function in a Lovable or Bolt project, an API route in a v0 or Next.js app, or the backend of a Replit project.
How do I add phone OTP verification to a Next.js app?
With Miss OTP by NaCaller, add two route handlers and store your key in an environment variable such as NACALLER_KEY. The first, app/api/verify/start/route.ts, forwards the phone number to POST https://api.nacaller.com/api/verify/start and returns requestId and callNumber to the page. The second, app/api/verify/status/[id]/route.ts, calls GET https://api.nacaller.com/api/verify/status/<id>. The page shows the number to ring and checks the status route every two seconds. When it gets verified: true, it marks the number verified in your own users table. The same two server calls work from React Native, Flutter or any mobile app's backend. Nothing runs on the handset, so you need no SMS permissions.
What should I tell Cursor, Claude Code or Copilot to add missed call verification?
You can paste a prompt like this one: "Add phone verification with Miss OTP by NaCaller. Server side only, with the key in NACALLER_KEY. POST https://api.nacaller.com/api/verify/start with JSON { phone } and header Authorization: Bearer <key>. It returns requestId, callNumber, expiresIn and an instruction string. Show the user callNumber and ask them to give a missed call from the number they entered. Poll GET https://api.nacaller.com/api/verify/status/{requestId} every 2 seconds until status is 'verified' or 'expired'. Handle HTTP 400 (not a valid Indian mobile), 402 (out of credits) and 429 (too many attempts)." A pending request lasts five minutes, so show a retry button once status comes back as expired.
How do I verify phone numbers in India without DLT registration?
Don't send an SMS. Verify with a call the user places. Miss OTP by NaCaller asks your user to give a missed call to a number the API returns, then matches the caller ID the telephone network passes to us against your pending request. No message is sent, so there is no sender header, SMS template or DLT entity to register, and you can verify real numbers as soon as you have an API key. DLT rules still apply to any SMS you also send, so you can add SMS later as a fallback once your registration comes through.
Is there an alternative to Firebase phone auth for Indian numbers?
Miss OTP by NaCaller verifies an Indian mobile number with a missed call instead of an SMS code. The user rings the number your app shows, and the API reports the number as verified. It is a verification step, not a full auth system. It tells your server "this user holds this number", and then you create the session or set the flag in your own database, or in the auth system you already use. Because nothing is sent to the phone, there is no SMS to be delayed or filtered, and your app needs no SMS-reading permission. It works only for Indian mobile numbers, so it suits apps whose users are in India.
Is there an alternative to Twilio Verify or MSG91 for OTP in India?
For Indian mobile numbers, Miss OTP by NaCaller verifies with a missed call instead of an SMS code, so you have no DLT registration or template approval to finish before launch. It is a plain REST API: POST /start, then GET /status or a signed webhook. Existing code that sends a number and waits for a verdict maps across in one small change. If some of your users can't place a call, NaCaller Voice OTP uses the same API and key to ring the user and read out a code. You can also keep your current SMS provider as a fallback rather than removing it.
How much does missed call OTP verification cost per number?
Miss OTP by NaCaller costs between ₹0.10 and ₹0.20 per verified number, depending on the prepaid pack. The Starter pack is ₹199 for 1,000 verifications (₹0.20 each), and the Scale pack is ₹9,999 for 1,00,000 (₹0.10 each). You are charged one credit only when a number actually verifies. A request nobody rings, or one that expires, costs nothing. Credits do not expire, there is no monthly fee, and GST is added.
Can a user be tricked into sharing a missed call verification like an OTP code?
Not in the same way. With Miss OTP by NaCaller there is no code, so there is nothing for a scammer to ask the user to read out, forward or type into a fake page. Proof comes from the call itself: the caller ID the telephone network passes to us has to match the number your user entered, within a five-minute window. It is not stronger than every attack. Caller ID can be spoofed on some routes, which is why only 10-digit Indian mobile numbers are accepted, and a SIM-swapped number would pass, just as it passes an SMS OTP. Use it for signup, login and lead checks, and add a second factor for payments or account recovery.
How do I verify the Miss OTP webhook signature?
When a number verifies, Miss OTP by NaCaller sends a POST to the callback URL you set in your dashboard. The JSON body contains event "verification.verified", requestId, phone, reference, verifiedAt and a millisecond timestamp. The X-MissOTP-Signature header is a hex HMAC-SHA256 of the raw request body, keyed with your webhook secret. Compute it over the exact bytes you received, before any JSON parsing, and compare the two with a constant-time function such as crypto.timingSafeEqual in Node. The timestamp is inside the signed body, so you can reject stale deliveries to block replays. Poll the status endpoint if you would rather not expose a webhook URL.
What if my user can't give a missed call?
Offer "Get a call instead". NaCaller Voice OTP uses the same API and key as Miss OTP by NaCaller. Start the verification with method "voice" and we ring the user and read a 6-digit code aloud, twice. The user types it into your app. This covers users who can't place outgoing calls, for example with no outgoing balance, and anyone uncomfortable dialling an unknown number. A good pattern is missed call as the default and the voice call behind a small link, so most verifications take the cheaper, code-free path.
Is there a free phone number verification API I can test in India?
Yes. Miss OTP by NaCaller gives you 25 free verifications and 5 free voice calls per account, with your first API key and no card required. They run on the live verification line with real calls from real phones, so what you test is what ships. There is no sandbox mode. After the free verifications, prepaid packs start at ₹199.
What does the Miss OTP start endpoint return, and what errors can it send?
POST https://api.nacaller.com/api/verify/start to Miss OTP by NaCaller returns requestId, phone (normalised to 10 digits), callNumber, status "pending", expiresAt, expiresIn (seconds) and a ready-made instruction sentence you can show the user. It accepts an optional reference string, up to 120 characters, that comes back in status responses and webhooks. Errors: 401 for a missing or invalid key, 400 for anything other than a 10-digit Indian mobile starting 6–9, 402 when your credits have run out, and 429 when one number has been started too often (five attempts in ten minutes) or your key sends too many requests. GET /status/{requestId} returns status as "pending", "verified" or "expired", plus verified, verifiedAt and expiresAt.

Live today

Your first verification is about ten minutes away.

Sign up, issue a key, paste two fetch calls. 25 verifications on us while you wire it in.

Call meStart free