Tawked Adds Workflow Controls to Saudi-Focused SMS OTP API
September 2 update adds verification tracking, controlled retries and configurable safeguards for application teams.
JEDDAH, Saudi Arabia, September 13, 2026 — Tawked announces the availability of updated workflow controls for its SMS one-time password (OTP) verification API. Documented in its September 2, 2026 changelog, the update supports developers and product teams building registration and login flows for Saudi mobile numbers.
The update addresses a practical distinction in mobile verification: requesting a text message is not the same as completing an application’s verification process. Teams also need to track request status, handle expired codes and manage retries without generating unintended duplicate messages.
The expanded API supports status retrieval, code resending and cancellation of pending verification requests. According to Tawked’s technical reference, an optional Idempotency-Key lets a repeated start request return its original response without another send or charge. This gives developers a defined way to handle request retries within their applications.
Daily spending caps and per-IP request limits provide additional operational controls, while API-key expiry, IP allowlists and check-only permissions can restrict how credentials are used. These options require configuration; per-IP limits depend on the application supplying the end user’s IP address.
These controls complement Tawked’s existing send-and-check workflow: one API request initiates delivery and another checks the submitted code. Application owners continue to manage their own sessions and access decisions. The service supports Saudi mobile-number formats and Arabic or English verification messages.
SMS OTP indicates access to a receiving number at the time of verification, not complete proof of identity. NIST’s digital identity guidance notes that out-of-band authentication is not phishing-resistant and highlights risks associated with SIM changes and number porting. Customers should assess whether additional, stronger authentication is needed for their use case.
Tawked’s terms require customers to protect API keys, obtain recipient opt-in and send verification codes requested by the recipient, rather than unsolicited marketing. Customers retain responsibility for application security and applicable compliance obligations. Delivery depends on telecommunications networks and service providers; neither delivery nor protection against every type of fraud is guaranteed.
Developers can register through Tawked’s website, access the API documentation and use test keys before production review. Sandbox sends are limited to verified destinations and remain subject to balance and usage limits. Production activation requires application review, and the service uses prepaid credit.
About Tawked
Tawked is a Jeddah-based platform providing API-based SMS OTP verification for Saudi mobile numbers. Its service combines code delivery and checking with a dashboard for application settings, API keys and verification records.
Disclaimer: This article is for informational purposes only and does not constitute technical, financial, legal, or business advice. Readers should independently verify the information and ensure that any SMS, OTP, or authentication services comply with applicable laws, regulations, and security requirements.