بغداد سكربت للحلول البرمجية - خدمة OTP

OTP verification API documentation

A simple API for sending verification codes over WhatsApp and SMS inside Iraq. One HTTP request, no library to install, works with any language. Below: authentication, ready examples in PHP, Python, cURL and Node.js, error codes, and what your user actually receives.

Important: The message body and the code are generated on our side. You send only the phone number and channel; we generate a 6-digit code, send it using a fixed template, then you verify it through the verify endpoint.

Authentication

Send your key in the Authorization header with every request:

Authorization: Bearer bgs_live_xxxxxxxx

Choose your language

1) Send a verification code

POST https://otp.baghdadscript.online/api/send.php
curl -X POST https://otp.baghdadscript.online/api/send.php \ -H "Authorization: Bearer bgs_live_xxxxxxxx" \ -H "Content-Type: application/json" \ -d '{"phone":"07701234567","channel":"whatsapp"}'
<?php define('API_KEY', 'bgs_live_xxxxxxxx'); define('API_BASE', 'https://otp.baghdadscript.online/api'); function otp_call(string $endpoint, array $body): array { $ch = curl_init(API_BASE . $endpoint); curl_setopt_array($ch, [ CURLOPT_POST => true, CURLOPT_RETURNTRANSFER => true, CURLOPT_TIMEOUT => 20, CURLOPT_HTTPHEADER => [ 'Content-Type: application/json', 'Authorization: Bearer ' . API_KEY, ], CURLOPT_POSTFIELDS => json_encode($body), ]); $res = curl_exec($ch); $code = curl_getinfo($ch, CURLINFO_HTTP_CODE); curl_close($ch); return ['status' => $code, 'data' => json_decode($res, true)]; } // إرسال الرمز $r = otp_call('/send.php', [ 'phone' => '07701234567', 'channel' => 'whatsapp', ]); if (!empty($r['data']['success'])) { // احفظه بجلسة المستخدم: تحتاجه بخطوة التحقق $_SESSION['otp_request_id'] = $r['data']['request_id']; echo "تم إرسال الرمز"; } else { echo "فشل: " . ($r['data']['error'] ?? 'خطأ غير معروف'); }
import requests API_KEY = "bgs_live_xxxxxxxx" API_BASE = "https://otp.baghdadscript.online/api" def otp_call(endpoint: str, body: dict) -> dict: res = requests.post( f"{API_BASE}{endpoint}", json=body, headers={"Authorization": f"Bearer {API_KEY}"}, timeout=20, ) return res.json() # إرسال الرمز data = otp_call("/send.php", { "phone": "07701234567", "channel": "whatsapp", }) if data.get("success"): request_id = data["request_id"] # احفظه بجلسة المستخدم print("تم إرسال الرمز، ينتهي خلال", data["expires_in"], "ثانية") else: print("فشل:", data.get("error"))
const API_KEY = 'bgs_live_xxxxxxxx'; const API_BASE = 'https://otp.baghdadscript.online/api'; async function otpCall(endpoint, body) { const res = await fetch(`${API_BASE}${endpoint}`, { method: 'POST', headers: { 'Content-Type': 'application/json', 'Authorization': `Bearer ${API_KEY}`, }, body: JSON.stringify(body), }); return res.json(); } // إرسال الرمز const data = await otpCall('/send.php', { phone: '07701234567', channel: 'whatsapp', }); if (data.success) { req.session.otpRequestId = data.request_id; // احفظه بالجلسة console.log('تم إرسال الرمز'); } else { console.log('فشل:', data.error); }
Response
{ "success": true, "request_id": "req_9f3a2b8c1d4e5f60", "status": "pending", "channel": "whatsapp", "network": null, "charged": 13, "balance_remaining": 9987, "expires_in": 300}

Store request_id in your user session: you need it to verify. The code itself is never returned to you.

2) Verify the code

POST https://otp.baghdadscript.online/api/verify.php

When your user types the code, send it to us with the request_id and we confirm whether it matches.

curl -X POST https://otp.baghdadscript.online/api/verify.php \ -H "Authorization: Bearer bgs_live_xxxxxxxx" \ -H "Content-Type: application/json" \ -d '{"request_id":"req_9f3a2b8c1d4e5f60","code":"482913"}'
<?php // بعد ما المستخدم يكتب الرمز بالفورمة $v = otp_call('/verify.php', [ 'request_id' => $_SESSION['otp_request_id'], 'code' => $_POST['code'], ]); if (!empty($v['data']['verified'])) { unset($_SESSION['otp_request_id']); // ✅ تم التحقق: كمّل تسجيل المستخدم أو دخوله } else { $left = $v['data']['attempts_remaining'] ?? 0; echo "الرمز غير صحيح. متبقي {$left} محاولات."; }
# بعد ما المستخدم يكتب الرمز result = otp_call("/verify.php", { "request_id": request_id, "code": user_typed_code, }) if result.get("verified"): print("✅ تم التحقق") else: print("غير صحيح، متبقي", result.get("attempts_remaining", 0), "محاولات")
// بعد ما المستخدم يكتب الرمز const result = await otpCall('/verify.php', { request_id: req.session.otpRequestId, code: req.body.code, }); if (result.verified) { delete req.session.otpRequestId; // ✅ تم التحقق } else { console.log(`غير صحيح، متبقي ${result.attempts_remaining} محاولات`); }
Correct code
{ "success": true, "verified": true, "phone": "07701234567" }
Wrong code
{ "success": true, "verified": false, "error": "الرمز غير صحيح", "attempts_remaining": 4 }

Which number sends the message?

Every WhatsApp message is sent from your own WhatsApp number, linked from the Sender number page. Your users see your name, not ours.

If your number is unlinked or offline, the API returns 503 with no charge to your balance.

Monthly plan

If your account is on the monthly plan, charged returns 0 and the response adds:

{ "charged": 0, "plan": "monthly", "plan_expires_at": "2026-10-26 12:00:00", "daily_quota": 2000, "daily_used": 137 }

Hitting the daily cap returns 429 with no charge. Price: 10,000 IQD (≈ $7.58) per 30 days.

Channels and pricing

Value Description Price Status
whatsapp WhatsApp، Arabic message 13 Live
sms English SMS
No need to specify the network
65 Asiacell
77 Zain & Korek
Live

The send response returns the resolved channel (sms_asiacell or sms_other) and the detected network, so you know exactly what was charged and why.

Numbers whose network we cannot identify are rejected with 422 and no charge, use WhatsApp for those.

What your user receives

WhatsApp
SMS

You can add your app name from the Message settings page.

Error codes

CodeReason
401Invalid or revoked API key
402Insufficient balance
404Unknown request_id
410Code expired or already used
422Invalid phone or channel
429Rate limit, duplicate send, or too many verify attempts
503Your WhatsApp number is unlinked/offline, or the channel is not live

Notes