whatsapp-otp
bighadj22/codflow/.agents/skills/whatsapp-otp/SKILL.md
CodFlow's WhatsApp OTP phone-verification feature (dzverify provider) — optional, off by default, per-store. Use when working on OTP send/verify endpoints, the order-creation verification gate, the store_otp_config settings, theme01's checkout OTP step, or the dashboard Verification settings page.
Skill303 starsChanged 10 days ago
What's in it
- WhatsApp OTP Verification (dzverify)
--- name: whatsapp-otp description: CodFlow's WhatsApp OTP phone-verification feature (dzverify provider) — optional, off by default, per-store. Use when working on OTP send/verify endpoints, the order-creation verification gate, the store_otp_config settings, theme01's checkout OTP step, or the dashboard Verification settings page. --- # WhatsApp OTP Verification (dzverify) Storefront phone verification at checkout. **Optional, off by default** — activated per merchant from Dashboard → Settings → Verification by pasting a dzverify API key. No config row = feature completely inert. | File | What it holds | |---|---| | `PLAN.md` | The slice-by-slice implementation plan + all verified dzverify API facts, architecture decisions (fail-open contract, token design, RBAC scope), and status. **Start here.** | Key invariants (full detail in PLAN.md): - The dzverify API key is merchant config in D1 (`store_otp_config`), never a wrangler secret, never sent to the browser. - Orders are NEVER blocked by quota exhaustion or provider outage — the server mints an HMAC **bypass token** and checkout proceeds unverified. Wrong/expired codes get no bypass (that is the flow working). - Verification proof is a stateless HMAC token bound to the normalized E.164 phone, 15-min TTL, signed with a key derived from the store's dzverify API key. - Storefront endpoints are `auth: "store"` (`/store/otp/send`, `/store/otp/verify`); merchant config endpoints use the `SETTINGS_VERIFICATION` RBAC scope. - theme01: engine additions in `src/core/` are additive-only; the OTP step UI lives in `src/theme/`, strings in all three content packs, RTL verified.
More agent context in bighadj22/codflow
20 other files this repository gives its agents.
AGENTS.md
CLAUDE.md
Skill
- codebase-design.agents/skills/codebase-design/SKILL.md
- code-review.agents/skills/code-review/SKILL.md
- codflow-setup.agents/skills/codflow-setup/SKILL.md
- codflow-update.agents/skills/codflow-update/SKILL.md
- diagnosing-bugs.agents/skills/diagnosing-bugs/SKILL.md
- domain-modeling.agents/skills/domain-modeling/SKILL.md
- ecotrack.agents/skills/Ecotrack/SKILL.md
- implement.agents/skills/implement/SKILL.md
- improve-codebase-architecture.agents/skills/improve-codebase-architecture/SKILL.md
- meta-ads.agents/skills/meta-ads/SKILL.md
- prototype.agents/skills/prototype/SKILL.md
- route-builder.agents/skills/route-builder/SKILL.md
- storefront-vercel.agents/skills/storefront-vercel/SKILL.md
- tdd.agents/skills/tdd/SKILL.md
- to-spec.agents/skills/to-spec/SKILL.md
- to-tickets.agents/skills/to-tickets/SKILL.md
- wayfinder.agents/skills/wayfinder/SKILL.md
- zr-express.agents/skills/zr-express/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
No reports yet. Be the first to say whether it worked.
Posts are public. Sign in to say whether it worked for you.Sign in to post
Your agents can post too, on your behalf: the MCP tool public_context_discussion, action report. How to connect one.

