Authyo OTP for Elementor Form

Description

Authyo OTP for Elementor Form adds OTP (One-Time Password) verification to your Elementor forms. Protect your forms with multi-channel verification – Email, SMS, WhatsApp, and Voice Call – powered by the Authyo API.

Features:

  • 11 field types: First Name, Last Name, Email, Phone, Message, Dropdown, Checkbox, Radio Button, File Upload, Hidden Field, Multi-Step Form
  • Enable OTP toggle on Email and Phone fields individually
  • Multi-channel OTP delivery: Email, SMS, WhatsApp, Voice Call
  • Configurable OTP length (4–8 digits), expiry (1–60 minutes), resend cooldown, and max resend limit
  • Failsafe protection: allow forms to submit even if OTP delivery fails (e.g. low balance)
  • Built-in country code selector with 250+ countries via the Authyo API, with a bundled static fallback
  • Clean, modern settings panel with vertical tab layout
  • Rate limiting on send and verify endpoints to prevent abuse
  • Full WordPress REST API integration with nonce verification

Third-Party Disclaimer:

This plugin is NOT affiliated with, endorsed by, or officially supported by Elementor Ltd. It is an independent third-party integration that works alongside Elementor to provide OTP verification functionality using Authyo’s API services.

External Services

This plugin connects to the Authyo API (https://app.authyo.io) for the following purposes:

  • Send OTPPOST https://app.authyo.io/api/v1/auth/sendotp
    Sends a one-time password to the user’s phone number or email address via the selected channel (SMS, WhatsApp, Voice Call, or Email). The user’s contact target, OTP length, expiry, and delivery channel are transmitted.

  • Verify OTPPOST https://app.authyo.io/api/v1/auth/verifyotp
    Verifies the OTP entered by the user against a temporary maskId issued during the send step. No contact information is sent during verification.

  • Country listGET https://app.authyo.io/api/v1/user/getcountrylist
    Fetches the list of supported countries for the phone number field dropdown. This is called once and cached; no user data is transmitted.

  • Support requestPOST https://app.authyo.io/api/v1/user/WordpressWebhook
    Sent only when a site administrator submits the form on the Support tab, and never as a result of visitor activity. Transmits the message and reply-to address entered on that form, together with your Authyo Client ID, site URL, plugin version, WordPress version and PHP version, so the support team can identify the account and environment. The form states this before it is submitted.

These requests are made from your WordPress server (server-side), not from the user’s browser. Use of these services is subject to the Authyo Terms of Service and Privacy Policy.

Privacy Policy

This plugin transmits personal data to the Authyo API (https://app.authyo.io) in order to deliver and verify one-time passwords. The following data may be sent:

  • Phone number or email address – transmitted when a user requests an OTP, to identify the delivery target.
  • OTP session token (maskId) – a temporary, opaque identifier returned by the Authyo API and used only to verify the code the user enters. No contact information is included in the verify request.
  • Country list requests – no personal data is transmitted; only a request for supported country codes is made.
  • Support requests – when an administrator uses the Support tab, the message and reply-to address they type, plus the site URL, Authyo Client ID and version details, are sent to Authyo. This is an explicit administrator action; no visitor data is involved and nothing is sent otherwise.

No personal data collected through this plugin is stored on the Authyo servers beyond what is necessary to deliver and verify a single OTP session.

Site administrators are responsible for informing their users about this data transmission in their own site privacy policy.

For full details, refer to the Authyo Privacy Policy and Terms of Service.

About

Konceptwise Digital Media Pvt. Ltd. is the parent company that officially develops and maintains this plugin.

Authyo is a product line developed and owned by Konceptwise Digital Media Pvt. Ltd., providing multi-channel OTP verification services (Email, SMS, WhatsApp, and Voice Call) for web applications.

This plugin is NOT affiliated with, endorsed by, or officially supported by Elementor Ltd. It is an independent third-party integration.

Installation

Automatic Installation

  1. Log in to your WordPress admin panel.
  2. Go to Plugins Add New Upload Plugin.
  3. Choose the plugin ZIP file and click Install Now.
  4. Click Activate Plugin.

Manual Installation

  1. Upload the authyo-otp-for-elementor-form folder to /wp-content/plugins/.
  2. Activate the plugin through the Plugins menu in WordPress.

After Activation

  1. Navigate to Authyo OTP for Elementor Form General Settings.
  2. Enter your Client ID and Client Secret from your Authyo dashboard.
  3. Enable the OTP channels you want to use under the OTP Channel tab.
  4. In the Elementor editor, add the Authyo Form widget to any page.
  5. In the widget’s repeater fields, enable OTP on any Email or Phone field.

FAQ

Do I need an Authyo account?

Yes. You need a free or paid Authyo account to obtain your API credentials (Client ID and Client Secret). Sign up at https://app.authyo.io.

Which OTP channels are supported?

Email, SMS, WhatsApp, and Voice Call. Each channel can be enabled or disabled individually under Authyo OTP for Elementor Form General Settings OTP Channel.

Does it work without Elementor Pro?

Yes. The plugin works with both the free Elementor plugin and Elementor Pro.

What happens if the Authyo API is unreachable?

If the Failsafe Protection option is enabled (under General Settings), forms will still submit even if the OTP cannot be delivered. Your site administration email is alerted when this happens.

What data is sent to Authyo?

When sending an OTP, the user’s phone number or email address, the selected OTP channel, and OTP length/expiry settings are sent to the Authyo API. When verifying, the maskId (a temporary session token returned by Authyo) and the OTP entered by the user are sent. No personally identifiable information is stored by this plugin beyond standard WordPress transients used for session management.

Is the country list cached?

Yes. The country list is fetched from the Authyo API once and cached as a WordPress option. You can refresh it manually from the Country tab in the settings panel.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“Authyo OTP for Elementor Form” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.0.2

  • Added: one-click setup wizard – a “Setup Authyo” modal that walks through credentials, channels, countries and OTP behaviour, and saves everything in one step.
  • Added: a Support tab with the support address and a help-request form that sends your message to the Authyo team.

1.0.1

  • Compatibility: the REST nonce and OTP session tokens are now fetched at runtime instead of being embedded in the page, so forms work correctly behind server-level and CDN page caches (Varnish, Nginx FastCGI, Cloudflare) that cannot honour DONOTCACHEPAGE.
  • Reliability: a request rejected because a cached page supplied an expired nonce is now retried automatically with a fresh one.
  • Maintenance: page caches are purged automatically after a plugin update.
  • Added the authyo_ef_disable_page_cache filter for site owners who prefer to keep form pages cached.

1.0.0

  • Initial release.
  • Supports Email, SMS, WhatsApp, and Voice Call OTP channels.
  • 11 field types in the Elementor widget.
  • Rate limiting, failsafe protection, and country dropdown with cache.