=== Iraq Phone OTP Verification for WooCommerce ===
Contributors: baghdadscript
Tags: woocommerce, otp, phone verification, whatsapp, sms
Requires at least: 6.0
Tested up to: 6.7
Requires PHP: 7.4
Stable tag: 1.0.0
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Verify the customer phone number with a WhatsApp or SMS one time code before the order is placed. Built for Iraqi numbers.

== Description ==

Cash on delivery is how most orders are paid in Iraq, and a fake phone number means a delivery that costs you money and never arrives.

This plugin adds a verification box to the WooCommerce checkout. The customer enters a phone number, receives a one time code on WhatsApp or SMS, and the order cannot be placed until that exact number is confirmed.

**What it does**

* Adds a verify box under the billing fields on the classic checkout
* Sends a 6 digit code over WhatsApp or SMS
* Blocks the order on the server until the phone is verified
* Re-checks if the customer changes the number after verifying
* Limits how many codes one visitor can request per hour, so your balance is protected
* Marks every order with a verified badge in the orders list
* Arabic and English, right to left ready

**Security**

The verification state is stored in the WooCommerce session on the server, never in the browser. Editing the page in developer tools or posting the form directly does not get an order through. If the customer verifies one number and then types a different one, the order is refused.

**Account needed**

The plugin sends codes through the Baghdad Script OTP service, which is a paid service with a free trial and no card required. Create an account, copy your API key, and paste it into the plugin settings.

Service website: https://otp.baghdadscript.online/
API documentation: https://otp.baghdadscript.online/docs.php

== External services ==

This plugin connects to the Baghdad Script OTP API to send and verify one time codes.

When a customer asks for a code, the plugin sends the phone number they entered and the chosen channel (whatsapp or sms) to https://otp.baghdadscript.online/api/send.php. When the customer submits the code, the plugin sends the code and the request id to https://otp.baghdadscript.online/api/verify.php.

No data is sent until a customer asks for a code. Nothing is sent when the plugin is only installed or when the API key field is empty.

Terms of use: https://otp.baghdadscript.online/terms.php
Privacy policy: https://otp.baghdadscript.online/privacy.php

== Installation ==

1. Upload the plugin folder to /wp-content/plugins/ or install it from the Plugins screen.
2. Activate the plugin.
3. Go to Settings then Iraq Phone OTP.
4. Paste your API key and save.
5. Use the test button on the settings page to send a code to your own number.

The verification box is shown on the classic checkout. If your checkout page uses the newer checkout block, switch that page to the [woocommerce_checkout] shortcode so customers can see the box.

== Frequently Asked Questions ==

= Do I need an account? =

Yes. The plugin needs an API key from https://otp.baghdadscript.online/ to send codes. Signing up is free and gives you trial messages with no card.

= Which numbers are supported? =

Iraqi mobile numbers in the form 07xxxxxxxxx. The plugin also accepts +964 and 00964 and converts them.

= Can a customer skip the verification? =

No. The check runs on the server during checkout validation. Changing the page with developer tools or posting the form directly is refused.

= What happens if the code does not arrive? =

The customer can ask for a new code after 60 seconds. You can set how many codes one visitor may request per hour in the settings.

= Does it work with the checkout block? =

Orders are blocked on the server either way. The visible verification box currently renders on the classic checkout, so switch your checkout page to the shortcode to show it.

== Screenshots ==

1. The verification box on the checkout page
2. After the code is sent
3. A verified number
4. The plugin settings screen

== Changelog ==

= 1.0.0 =
* First release
