Title: Cindova Phone OTP &amp; SMS for Gravity Forms
Author: Cindova Technologies
Published: <strong>October 5, 2026</strong>
Last modified: October 5, 2026

---

Search plugins

![](https://s.w.org/plugins/geopattern-icon/cindova-phone-otp-sms-for-gravity-forms.
svg)

# Cindova Phone OTP & SMS for Gravity Forms

 By [Cindova Technologies](https://profiles.wordpress.org/cindova/)

[Download](https://downloads.wordpress.org/plugin/cindova-phone-otp-sms-for-gravity-forms.1.0.0.zip)

 * [Details](https://wordpress.org/plugins/cindova-phone-otp-sms-for-gravity-forms/#description)
 * [Reviews](https://wordpress.org/plugins/cindova-phone-otp-sms-for-gravity-forms/#reviews)
 *  [Installation](https://wordpress.org/plugins/cindova-phone-otp-sms-for-gravity-forms/#installation)
 * [Development](https://wordpress.org/plugins/cindova-phone-otp-sms-for-gravity-forms/#developers)

 [Support](https://wordpress.org/support/plugin/cindova-phone-otp-sms-for-gravity-forms/)

## Description

Confirm that visitors own the phone number they enter, and send SMS or Slack notifications
when a form is submitted.

**Requires Gravity Forms 2.5 or later** (tested with Gravity Forms 3.1). Gravity
Forms is a separate commercial plugin that is not available on WordPress.org and
is not included with this plugin. You must install and license it yourself.

This plugin is not affiliated with, endorsed by, or sponsored by Rocketgenius (Gravity
Forms), Google, or Firebase.

#### Features

 * Phone OTP verification with Firebase Authentication. The visitor receives an 
   SMS code, and your server verifies the resulting Firebase ID token during form
   validation, so the check cannot be bypassed from the browser.
 * SMS notifications after submission through MSG91 (Flow API v5 or the legacy API)
   or Twilio, with `{{field_X}}` placeholders and Gravity Forms merge tags in the
   message.
 * Optional Firebase App Check (off by default) to help stop SMS abuse.
 * Slack notifications to a public or private channel.
 * Built on the Gravity Forms Add-On Framework: settings live under Forms > Settings(
   Phone OTP, SMS & Slack) and per form under the form’s Settings tab, like other
   Gravity Forms add-ons.
 * Notification feeds: add as many SMS and Slack notifications per form as you need,
   each with its own message and its own conditional logic.
 * Send a test SMS or Slack message from the feed screen, using the values you have
   typed (no need to save first).
 * Entry notes record each notification, and failures are logged to the entry and
   to the Gravity Forms logs.
 * Works with AJAX and multi-page forms, and with several OTP forms on one page.
 * Translation ready.

### External services

This plugin connects to the third-party services below. Each one is used only after
you configure it under Forms > Settings and in your forms (you need your own account
with that service). Nothing is sent to the plugin author.

#### Google Firebase Authentication

 * Service: https://firebase.google.com/products/auth
 * What it is used for: sending the one-time SMS code to the visitor and confirming
   it.
 * When and what data is sent: only on forms where you set a Phone field and OTP
   field, and only after the visitor clicks “Send code”. The Firebase SDK is bundled
   with the plugin and served from your own site; it does not contact Google until
   that click. It then sends the phone number to Google (identitytoolkit.googleapis.
   com and securetoken.googleapis.com, plus your Firebase project’s auth domain,
   e.g. your-project.firebaseapp.com). When the visitor clicks “Verify code”, the
   code they typed is sent to check it. Google sends the SMS and creates a phone-
   number user in your Firebase project.
 * Terms of service: https://firebase.google.com/terms
 * Privacy policy: https://policies.google.com/privacy

#### Google reCAPTCHA

 * Service: https://www.google.com/recaptcha/about/
 * What it is used for: Firebase Authentication requires an invisible reCAPTCHA 
   check to prevent abuse of SMS sending.
 * When and what data is sent: loaded in the visitor’s browser by Firebase when 
   they click “Send code”. Google receives the browser and interaction data it uses
   for reCAPTCHA.
 * Terms of service: https://policies.google.com/terms
 * Privacy policy: https://policies.google.com/privacy

#### Google public key endpoint (Firebase token verification)

 * Service: https://firebase.google.com/docs/auth/admin/verify-id-tokens
 * What it is used for: your server downloads Google’s public certificates from 
   https://www.googleapis.com/robot/v1/metadata/x509/securetoken@system.gserviceaccount.
   com to check that a submitted verification token is genuine.
 * When and what data is sent: when an OTP-enabled form is submitted and the cached
   certificates have expired. No personal data is sent; it is a plain download.
 * Terms of service: https://policies.google.com/terms
 * Privacy policy: https://policies.google.com/privacy

#### Google reCAPTCHA v3 / Enterprise for Firebase App Check (optional)

 * Service: https://firebase.google.com/docs/app-check
 * What it is used for: proving to Firebase that OTP requests come from your genuine
   website, to help prevent SMS abuse.
 * When and what data is sent: only if you enter an App Check site key on the settings
   page. The App Check script is bundled and loaded in the visitor’s browser when
   they click “Send code”; it then loads Google reCAPTCHA and sends the browser 
   and interaction data Google uses for reCAPTCHA, and App Check tokens, to Google.
   Nothing is sent if the site key is blank.
 * Terms of service: https://policies.google.com/terms
 * Privacy policy: https://policies.google.com/privacy

#### MSG91

 * Service: https://msg91.com/
 * What it is used for: sending SMS notifications.
 * When and what data is sent: only if MSG91 is the selected SMS provider and a 
   form has an SMS notification feed. Your server sends your MSG91 auth key, the
   recipient phone number and the Flow template ID with its variable values (Flow
   API v5), or your auth key, sender ID, the recipient phone number and the message
   text (legacy API), including any submitted field values you placed in them, to
   control.msg91.com after the form is submitted, or when you click “Send test” 
   on a feed screen.
 * Terms of service: https://msg91.com/terms-of-use
 * Privacy policy: https://msg91.com/privacy-policy

#### Twilio

 * Service: https://www.twilio.com/
 * What it is used for: sending SMS notifications.
 * When and what data is sent: only if Twilio is the selected SMS provider and a
   form has an SMS notification feed. Your server sends your Twilio account SID 
   and auth token, your Twilio number, the recipient phone number and the message
   text (including any submitted field values you placed in it) to api.twilio.com
   after the form is submitted, or when you click “Send test” on a feed screen.
 * Terms of service: https://www.twilio.com/en-us/legal/tos
 * Privacy policy: https://www.twilio.com/en-us/legal/privacy

#### Slack

 * Service: https://slack.com/
 * What it is used for: posting a notification to a Slack channel.
 * When and what data is sent: when you save a new bot token (or ask for a refresh),
   your server asks slack.com for the list of channels. For each Slack notification
   feed, your server sends the configured message (including any submitted field
   values you placed in it) to the chosen channel after the form is submitted, or
   when you click “Send test” on the feed screen.
 * Terms of service: https://slack.com/terms-of-service
 * Privacy policy: https://slack.com/trust/privacy/privacy-policy

#### Third-party libraries

This plugin bundles the Firebase JS SDK 12.19.0 compat builds (app, auth and app-
check) (`assets/vendor/firebase/`), licensed under Apache-2.0 (protobuf portions
BSD-3-Clause); the license text is included in that folder. The files are the official
minified builds. The human-readable source is at https://github.com/firebase/firebase-
js-sdk (tag `firebase@12.19.0`) and on npm at https://www.npmjs.com/package/firebase.

## Installation

 1.  Make sure Gravity Forms 2.5 or later is installed and active.
 2.  Upload the plugin folder to `/wp-content/plugins/`, or install it from the Plugins
     screen, then activate it.
 3.  Set up Firebase:
 4.   a. Create a project in the Firebase console.
      b. Upgrade the project to the Blaze (pay as you go) plan. Phone authentication SMS
         requires it.
      c. Under Authentication, enable the Phone sign-in provider.
      d. Under Authentication > Settings > Authorized domains, add your site’s domain.
      e. Configure the SMS region policy to allow the countries you need.
      f. In Project settings, register a web app and copy its web config JSON.
 5.  Go to Forms > Settings > Phone OTP and paste the Firebase web config JSON.
 6.  For notifications, go to Forms > Settings > SMS & Slack and choose the SMS provider(
     MSG91 or Twilio), enter its credentials, and optionally the Slack bot token and
     default channel.
 7.  Edit your form and add a Phone field (set its Phone Format to “International”)
     and a Single Line Text field for the one-time code.
 8.  Open the form’s Settings > Phone OTP tab, turn on “Enable phone verification” 
     and select the phone field and the OTP code field.
 9.  To send notifications, open the form’s Settings > SMS & Slack tab and click Add
     New. Choose SMS or Slack, write the message, and optionally set conditional logic
     so the notification is sent only when the entry matches. Add one feed per notification.

Visitors must enter phone numbers in international format, for example +14155552671.

## FAQ

### Does it work without Gravity Forms?

No. Gravity Forms 2.5 or later is required.

### Is Firebase free?

Firebase Authentication has a free tier, but sending SMS for phone sign-in requires
the Blaze (pay as you go) plan. Check Google’s current pricing.

### Can users bypass the OTP?

Not from the browser. The server verifies the Firebase ID token during Gravity Forms
validation, including on the final page of multi-page forms. If the token is missing,
invalid, expired, already used or for a different phone number, the form shows a
field error and is not submitted. The check is enforced even if the OTP field is
hidden by conditional logic.

### Does it work with multi-page and AJAX forms?

Yes.

### Why can’t visitors type a + in the phone field?

The Gravity Forms Phone field’s “Standard” format only accepts US numbers in (###)###-####
form. Change the field’s Phone Format to “International” so visitors can enter numbers
such as +14155552671.

### Can I use conditional logic on the OTP field?

Yes. The OTP field itself can be hidden or shown by conditional logic without weakening
verification: the server always requires a valid token whenever the phone field 
is visible. If the phone field is hidden by conditional logic (including by a hidden
page or section), no phone number is collected, so verification is skipped.

### Where are my API keys and tokens stored?

Gravity Forms stores plugin settings in the WordPress options table as plain text.
To encrypt them at rest, define the `GF_ENCRYPTION_KEY` constant in `wp-config.php`(
see the Gravity Forms documentation); Gravity Forms then encrypts the stored settings.
The settings screens never print a saved secret: a saved Auth Key or token shows
only a “A value is saved” note, leaving the field blank keeps it, and the “Remove
the saved value” checkbox clears it.

### Can I send different messages or use conditional logic per notification?

Yes. Each SMS or Slack notification is a feed, and each feed has its own message
and its own conditional logic (“Send this notification if …”). Feeds are skipped
for spam entries. Failed notifications are written to the entry notes and, if you
turn on Gravity Forms logging (Forms > Settings > Logging), to the Gravity Forms
log for this plugin.

### Which placeholders can I use in messages?

{{field_ID}} and `{{field_ID.SUBID}}`, where ID is the Gravity Forms field ID and
SUBID is the input ID for multi-input fields such as Name. You can also use Gravity
Forms merge tags such as `{Name:1}`, `{Phone:3}`, `{entry_id}` or `{all_fields}`.
Merge tags are not replaced in the test message, because a test has no entry; they
are sent as written.

### How do I reduce SMS fraud?

Three things help: (1) set the SMS region policy in the Firebase console (Authentication
Settings  SMS region policy) to allow only the countries you serve; (2) optionally
enable Firebase App Check by entering a reCAPTCHA site key under App Check on the
Forms > Settings > Phone OTP page (register the key in the Firebase console first,
and test with enforcement in monitor mode, because a wrong key with enforcement 
on rejects every OTP request); (3) keep the Firebase SMS quotas and billing budget
alerts at low values.

### I used the earlier “Gravity Forms OTP and SMS Notifications” plugin by Cindova. Can I switch?

Yes. Install and activate this plugin, then deactivate and delete the earlier one.
Your Firebase, SMS and Slack settings, the phone and OTP fields of each form, and
your SMS and Slack messages are copied automatically into Forms > Settings > Phone
OTP, Forms > Settings > SMS & Slack and into notification feeds. The earlier plugin’s
data is left untouched, so you can switch back if you need to.

### Which Slack permissions are needed?

Create a Slack app with a bot token that has chat:write, channels:read and groups:
read (for private channels), and invite the bot to the channel.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Cindova Phone OTP & SMS for Gravity Forms” is open source software. The following
people have contributed to this plugin.

Contributors

 *   [ Cindova Technologies ](https://profiles.wordpress.org/cindova/)

[Translate “Cindova Phone OTP & SMS for Gravity Forms” into your language.](https://translate.wordpress.org/projects/wp-plugins/cindova-phone-otp-sms-for-gravity-forms)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/cindova-phone-otp-sms-for-gravity-forms/),
check out the [SVN repository](https://plugins.svn.wordpress.org/cindova-phone-otp-sms-for-gravity-forms/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/cindova-phone-otp-sms-for-gravity-forms/)
by [RSS](https://plugins.trac.wordpress.org/log/cindova-phone-otp-sms-for-gravity-forms/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.0

 * Initial release.
 * Phone number verification with a Firebase one-time code, verified on the server.
 * SMS notifications through MSG91 (Flow API v5 or legacy API) or Twilio.
 * Slack notifications to public and private channels.
 * Notification feeds per form, each with its own message and conditional logic.
 * Gravity Forms merge tags and {{field_ID}} placeholders in messages.
 * Send a test SMS or Slack message from the feed screen.
 * Optional Firebase App Check.
 * Supports AJAX forms, multi-page forms and several OTP forms on one page.
 * Suggested privacy policy text and clean-up of plugin data on uninstall.

## Meta

 *  Version **1.0.0**
 *  Last updated **2 days ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.5 or higher **
 *  Tested up to **7.1.3**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [firebase](https://wordpress.org/plugins/tags/firebase/)[gravity forms](https://wordpress.org/plugins/tags/gravity-forms/)
   [otp](https://wordpress.org/plugins/tags/otp/)[phone verification](https://wordpress.org/plugins/tags/phone-verification/)
   [sms](https://wordpress.org/plugins/tags/sms/)
 *  [Advanced View](https://wordpress.org/plugins/cindova-phone-otp-sms-for-gravity-forms/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/cindova-phone-otp-sms-for-gravity-forms/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/cindova-phone-otp-sms-for-gravity-forms/reviews/)

## Contributors

 *   [ Cindova Technologies ](https://profiles.wordpress.org/cindova/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/cindova-phone-otp-sms-for-gravity-forms/)