{"id":358133,"date":"2026-08-27T17:02:50","date_gmt":"2026-08-27T17:02:50","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/wakit\/"},"modified":"2026-08-27T17:02:24","modified_gmt":"2026-08-27T17:02:24","slug":"fastkit-otp-authentication-notifications-for-woocommerce","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/fastkit-otp-authentication-notifications-for-woocommerce\/","author":23554299,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.2.8","stable_tag":"1.2.8","tested":"7.1","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"Fastkit OTP Authentication & Notifications for WooCommerce","header_author":"Wakit","header_description":"Connect your WordPress site to Wakit in one click, then send WhatsApp order updates, sign users in with a WhatsApp OTP, and watch every send from the dashboard.","assets_banners_color":"","last_updated":"2026-08-27 17:02:24","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/wakit.in\/wordpress","header_author_uri":"https:\/\/wakit.in","rating":0,"author_block_rating":0,"active_installs":0,"downloads":41,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.2.8":{"tag":"1.2.8","author":"wakitdev","date":"2026-08-27 17:02:24","revision":3669273}},"upgrade_notice":[],"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.2.8"],"block_files":[],"assets_screenshots":[],"screenshots":{"1":"The Wakit dashboard: wallet balance, the WhatsApp number your messages leave from, and the last few sends.","2":"Connecting the site \u2014 mobile number, WhatsApp code, workspace and template, in one window.","3":"Order notifications: one WooCommerce status at a time, each with its own template and variables.","4":"Templates, from \"waiting for Wakit\" through \"with WhatsApp\" to approved.","5":"Sign in with WhatsApp, under the usual login box on wp-login.php.","6":"The send log, with what Meta said about anything that failed."}},"plugin_section":[],"plugin_tags":[602,38803,9210,3160,286],"plugin_category":[38,45],"plugin_contributors":[277931],"plugin_business_model":[],"class_list":["post-358133","plugin","type-plugin","status-publish","hentry","plugin_tags-login","plugin_tags-order-notifications","plugin_tags-otp","plugin_tags-whatsapp","plugin_tags-woocommerce","plugin_category-authentication","plugin_category-ecommerce","plugin_contributors-wakitdev","plugin_committers-wakitdev"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/fastkit-otp-authentication-notifications-for-woocommerce.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Press <strong>Connect to Wakit<\/strong> and a window opens on Wakit. Put in your mobile\nnumber, confirm the code that arrives on WhatsApp \u2014 an account is created there\nand then if you do not have one \u2014 and choose which workspace pays for messages\nand which approved template this site may send on. Approve, and the window\ncloses on your WordPress screen with the workspace, the balance and the template\nalready filled in.<\/p>\n\n<p>Then:<\/p>\n\n<ul>\n<li><strong>Templates.<\/strong> See every template you can send on, write a new one, and watch\nit move from review to approved without leaving WordPress.<\/li>\n<li><strong>Order notifications.<\/strong> When an order moves to Processing, Completed or any\nother status, the customer gets a WhatsApp message. Each status picks its own\ntemplate and its own variables, built from merge tags like <code>{full_name}<\/code> and\n  {order_number}.<\/li>\n<li><strong>Sign in with WhatsApp.<\/strong> A <code>[wakit_otp_login]<\/code> form takes a mobile number,\nsends a code, and signs the matching account in. It also appears under the\nusual login box on <code>wp-login.php<\/code>.<\/li>\n<li><strong>Sign in to wp-admin with a mobile number.<\/strong> Switch on wp-admin sign-in and\nadministrators and shop managers can use the same form: number, code from\nWhatsApp, straight to the screen they were asking for. Each of those accounts\nputs its number on its own profile, under <strong>Sign in with WhatsApp<\/strong>.<\/li>\n<li><strong>Your WhatsApp numbers.<\/strong> The dashboard shows the Cloud API numbers on your\nWakit workspace, which one your customers see the message arrive from, and\nwhether it can send today. Connect a new one on Wakit \u2014 the button gets you\nthere already signed in \u2014 and it appears here on the next look.<\/li>\n<li><strong>Send log.<\/strong> Every attempt, successful or not, with what Meta said about\nthe failures.<\/li>\n<\/ul>\n\n<h4>Two kinds of account, and why the screens differ<\/h4>\n\n<p><strong>You have your own WhatsApp Business number.<\/strong> You own that account, so every\ntemplate on it is yours, and a new one goes straight to WhatsApp for approval.<\/p>\n\n<p><strong>You are on Wakit's shared number.<\/strong> You send from a number other businesses\nalso send from, so you use the templates Wakit has assigned to you \u2014 never\nanybody else's, and nobody else ever sees yours. A template you write is read by\nWakit before WhatsApp is shown it: on a shared number, WhatsApp holds everyone\nto what any one of them sends.<\/p>\n\n<h4>What the site can and cannot do<\/h4>\n\n<p>This site can only send templates the workspace already has. Naming anything\nelse is refused by Wakit, not by the plugin \u2014 so a compromised WordPress install\ncannot invent a message to send, and a plugin added here never widens what may\ngo out from a workspace.<\/p>\n\n<p>The API key is swapped for on the server, never travels through a browser, and\nis stored encrypted with a key that lives in <code>wp-config.php<\/code>. A database dump on\nits own is not a working credential.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin connects your site to Wakit (https:\/\/wakit.in), which is the service\nthat actually delivers the WhatsApp messages. Without a Wakit account the plugin\ncannot send anything, so using this plugin means using that service.<\/p>\n\n<p>Everything below is sent from your server to <code>https:\/\/wakit.in\/api\/v1<\/code> over\nHTTPS, signed with the API key this site was given when you connected it.<\/p>\n\n<ul>\n<li><strong>Connecting the site.<\/strong> Pressing \"Connect to Wakit\" opens\n  https:\/\/wakit.in\/connect\/authorize in a window and gives it this site's\nwp-admin address to come back to. When you approve there, the one-time code\nthat comes back is exchanged at <code>\/connect\/exchange<\/code> for an API key. Nothing\nabout your WordPress users is part of this step.<\/li>\n<li><strong>Sending a WhatsApp message.<\/strong> When an order reaches a status you have\nswitched on, the plugin posts to <code>\/messages\/template<\/code>: the customer's mobile\nnumber in international format, the name of the approved template to send, and\nthe values you mapped into that template's variables \u2014 usually the customer's\nname and the order's number, total and status. A test send does the same with\nthe number you type in.<\/li>\n<li><strong>Signing in with a code.<\/strong> The sign-in form posts the mobile number typed\ninto it to <code>\/otp\/send<\/code>, then that send's id together with the code the visitor\ntyped to <code>\/otp\/verify<\/code>.<\/li>\n<li><strong>Reading your account.<\/strong> The admin screens fetch <code>\/account<\/code>, <code>\/connect\/me<\/code>,\n  \/numbers and <code>\/templates<\/code> for your wallet balance, the WhatsApp numbers on\nyour workspace and the templates you may send on. Writing a template posts its\nname, language, category and text to <code>\/templates<\/code>. Opening Wakit from a button\nin wp-admin asks <code>\/connect\/sso<\/code> for a one-time signed-in link.<\/li>\n<\/ul>\n\n<p>Nothing is sent anywhere until you connect the site, and no customer data is\nsent until you switch on a feature that needs it.<\/p>\n\n<p>Wakit's terms of service: https:\/\/wakit.in\/terms\nWakit's privacy policy: https:\/\/wakit.in\/privacy<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the <code>fastkit-otp-authentication-notifications-for-woocommerce<\/code> folder to\n   \/wp-content\/plugins\/, or install the zip from\n<strong>Plugins \u2192 Add New \u2192 Upload<\/strong>.<\/li>\n<li>Activate it.<\/li>\n<li>Go to <strong>Wakit<\/strong> and press <strong>Connect to Wakit<\/strong>.<\/li>\n<\/ol>\n\n<p>Your site must be on HTTPS. Wakit refuses to send the connect code back over\nplain http, where it would travel in clear text \u2014 the one exception is a site\nrunning on <code>localhost<\/code> for development.<\/p>\n\n<p>To point at a self-hosted Wakit, define this in <code>wp-config.php<\/code> before the\nplugin loads:<\/p>\n\n<pre><code>define( 'WAKIT_BASE_URL', 'https:\/\/wakit.example.com' );\n<\/code><\/pre>\n\n<!--section=faq-->\n<dl>\n<dt id=\"nothing%20arrives%2C%20but%20the%20log%20says%20%22sent%22.\"><h3>Nothing arrives, but the log says \"Sent\".<\/h3><\/dt>\n<dd><p>\"Sent\" means Meta accepted the message. Delivery after that depends on the\nnumber having WhatsApp and not having blocked the sender. Open the Wakit\ndashboard to follow a specific message.<\/p><\/dd>\n<dt id=\"a%20send%20fails%20with%20%22template%20name%20does%20not%20exist%22.\"><h3>A send fails with \"template name does not exist\".<\/h3><\/dt>\n<dd><p>The template was approved on a different WhatsApp number than the one the\nworkspace now sends from. Reconnect from the Wakit screen and pick it again.<\/p><\/dd>\n<dt id=\"sends%20fail%20after%20i%20changed%20the%20number%20of%20variables.\"><h3>Sends fail after I changed the number of variables.<\/h3><\/dt>\n<dd><p>Meta counts the variables and rejects a mismatch. The template decides how many\nthere are \u2014 fill in exactly that many rows and leave the rest blank.<\/p><\/dd>\n<dt id=\"can%20an%20administrator%20sign%20in%20to%20wp-admin%20with%20a%20code%3F\"><h3>Can an administrator sign in to wp-admin with a code?<\/h3><\/dt>\n<dd><p>Yes, but two things have to be true, and neither happens on its own. Tick\n<strong>wp-admin sign-in<\/strong> under <strong>Wakit \u2192 OTP sign-in<\/strong>, and put the mobile number on\nthe account itself \u2014 <strong>Users \u2192 Profile \u2192 Sign in with WhatsApp<\/strong>. An\nadministrator usually has no billing address, so without that field there is no\nnumber to match and the form will say no account uses it.<\/p>\n\n<p>It is off by default for a reason. A phone number that reaches an account which\ncan edit the whole site is a much bigger thing to hand over than one that\nreaches a customer account: whoever holds that SIM, or can have it reissued,\nholds the site.<\/p><\/dd>\n<dt id=\"i%20signed%20in%20with%20a%20code%20and%20landed%20on%20the%20shop%27s%20account%20page%2C%20not%20wp-admin.\"><h3>I signed in with a code and landed on the shop's account page, not wp-admin.<\/h3><\/dt>\n<dd><p>Fixed in 1.1.0. The form now carries the page you were sent to the login screen\nfrom, and anyone who can edit posts or orders is taken to wp-admin by default.\nThe destination is checked on the server, so a link cannot use the login form to\nbounce you off to another site.<\/p><\/dd>\n<dt id=\"two%20accounts%20have%20the%20same%20mobile%20number.\"><h3>Two accounts have the same mobile number.<\/h3><\/dt>\n<dd><p>Only one can keep it. The profile field refuses a number that already signs in\nanother account, and names the account holding it \u2014 the sign-in form has to be\nable to say which account a code belongs to.<\/p><\/dd>\n<dt id=\"a%20customer%27s%20number%20keeps%20changing%20back%20after%20checkout.\"><h3>A customer's number keeps changing back after checkout.<\/h3><\/dt>\n<dd><p>A number typed on the profile screen is fixed to the account and a later\ncheckout no longer moves it. A number that was only ever copied from the billing\naddress still follows the billing address; the profile screen says which of the\ntwo you are looking at. Clear the field to go back to following billing.<\/p><\/dd>\n<dt id=\"someone%20could%20spam%20the%20sign-in%20form%20and%20spend%20my%20balance.\"><h3>Someone could spam the sign-in form and spend my balance.<\/h3><\/dt>\n<dd><p>An unknown number is turned away before anything is sent, and each number and\neach address is capped per hour. Switching on \"create an account for a number\nthat does not have one\" removes the first of those protections, which is why it\nis off by default.<\/p><\/dd>\n<dt id=\"i%20deleted%20the%20plugin.%20is%20the%20key%20gone%3F\"><h3>I deleted the plugin. Is the key gone?<\/h3><\/dt>\n<dd><p>The copy stored here is deleted on uninstall. The key itself stays live on\nWakit until you revoke it there, under API keys.<\/p><\/dd>\n<dt id=\"where%20did%20my%20template%20go%3F\"><h3>Where did my template go?<\/h3><\/dt>\n<dd><p>Check <strong>Templates<\/strong>. \"Waiting for Wakit\" means it is in their review queue;\n\"With WhatsApp\" means it has been passed on and they are reading it. A refusal\nfrom either shows the reason on the row.<\/p><\/dd>\n<dt id=\"i%20wrote%20%22order_update%22%20but%20the%20list%20shows%20something%20longer.\"><h3>I wrote \"order_update\" but the list shows something longer.<\/h3><\/dt>\n<dd><p>On Wakit's shared number a name is claimed once for everyone, so your account\nname goes in front of yours. Nobody else can then take it, and you can tell your\ntemplates apart from the rest at a glance.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.2.8<\/h4>\n\n<ul>\n<li>A mobile number can only become an account on a site that is open to new\naccounts. \"Create an account for a number that does not have one\" now does\nnothing on its own: WordPress's own Settings \u2192 General \u2192 Membership \u2192 Anyone\ncan register has to be ticked as well, so this plugin cannot become a second\nway in past a door the site has shut.<\/li>\n<li>The roles that setting may create an account in are now decided by what a\nrole is allowed to do rather than by what it is not. Only a role that grants\nnothing beyond reading the site \u2014 what a subscriber and a WooCommerce\ncustomer have \u2014 is offered, so a role added by another plugin cannot slip\nthrough on a capability this plugin had not heard of.<\/li>\n<\/ul>\n\n<h4>1.2.7<\/h4>\n\n<ul>\n<li>The name now starts with Fastkit \u2014 \"Fastkit OTP Authentication &amp;\nNotifications for WooCommerce\" \u2014 so that it names a particular plugin rather\nthan describing a category of them. Same plugin, same people behind it.<\/li>\n<\/ul>\n\n<h4>1.2.6<\/h4>\n\n<ul>\n<li>The plugin is no longer called \"Wakit\". Nothing about how it works has\nchanged, and it is still built and run by Wakit \u2014 the name is the one the\nWordPress plugin directory will list it under. A site that had the old plugin\ninstalled keeps its connection, its templates and its send log: the settings\nlive in the database, not in the folder the plugin sits in.<\/li>\n<\/ul>\n\n<h4>1.2.5<\/h4>\n\n<ul>\n<li>A mobile number can no longer become an account that can change the site.\n\"Role for new accounts\" now offers only roles that cannot write, upload or\nadminister anything, and the role is checked again at the moment the account\nis created \u2014 so a site that had picked something more powerful stops handing\nit out.<\/li>\n<li>The page that closes the connect popup takes its styles and its script from\nfiles like every other screen, rather than printing them into the page.<\/li>\n<\/ul>\n\n<h4>1.2.4<\/h4>\n\n<ul>\n<li>First release on the WordPress plugin directory. On the Plugins screen the\nplugin is now simply \"Wakit\", and updates come from wordpress.org the same\nway they do for every other plugin there.<\/li>\n<li>The readme now sets out exactly what this site sends to Wakit, when, and\nunder whose terms \u2014 see \"External services\".<\/li>\n<\/ul>\n\n<h4>1.2.3<\/h4>\n\n<ul>\n<li>Updates arrive the ordinary way. WordPress offers a new Wakit release on the\nPlugins screen with \"update now\", a changelog behind View details, and\nauto-updates if the site has them on \u2014 no more downloading a zip and\nuploading it by hand.<\/li>\n<\/ul>\n\n<h4>1.2.2<\/h4>\n\n<ul>\n<li>Order notifications is one status at a time. The statuses are a list down the\nside, each marked when it is switched on, and only the one being edited is\nopen \u2014 rather than eight cards stacked into a page nobody could see the end\nof. Nothing is hidden from the save: every status still posts, so switching\nbetween them never loses what was typed.<\/li>\n<li>Template variables sit two or three across instead of one per row, and the\nmerge tags are two short columns rather than one long table.<\/li>\n<\/ul>\n\n<h4>1.2.1<\/h4>\n\n<ul>\n<li>Fixes an install that failed on activation with \"Plugin file does not exist.\"\nThe 1.2.0 zip was packed with the wrong path separator, so WordPress unpacked\nit into files it could not then find. Nothing inside the plugin changed.<\/li>\n<li>The plugin's own screens are now Wakit green rather than WordPress blue, so\nthey match the Wakit tab the connect button opens. The WhatsApp sign-in form\nis painted to match too, on wp-login.php and wherever the shortcode is used.<\/li>\n<li>Templates now says what to do about it when you are on Wakit's shared number:\nadd your own WhatsApp Business number, get the business behind it verified,\nand write templates in your own words. The button that starts it is on the\nscreen rather than somewhere on Wakit you have to go looking for.<\/li>\n<\/ul>\n\n<h4>1.2.0<\/h4>\n\n<ul>\n<li>The dashboard now shows the WhatsApp Cloud API numbers on your Wakit\nworkspace, which one your messages actually leave from, and whether it may\nsend today. Connect a number on Wakit and it appears here on the next look \u2014\nnothing to copy across.<\/li>\n<li>Every link out to Wakit signs you in on the way: the dashboard, your numbers,\nconnecting a new number, and recharging are each one click, with no second\nsign-in.<\/li>\n<\/ul>\n\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>Sign in to wp-admin with a mobile number and a WhatsApp code.<\/li>\n<li>A mobile number on the user profile, so an account with no billing address \u2014\nevery administrator \u2014 can be reached by the sign-in form. It is fixed to the\naccount: a later checkout no longer moves it, and no two accounts may share\none.<\/li>\n<li>Signing in now returns to the page you came from, and sends anyone who works\non the site to wp-admin rather than the shop's account page.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>One-click connect: mobile number, WhatsApp code, workspace and template.<\/li>\n<li>Write your own templates and follow them through review to approved.<\/li>\n<li>WooCommerce order notifications, a template and variables per status.<\/li>\n<li>Sign in to WordPress with a WhatsApp code.<\/li>\n<li>Send log, test send, and a one-time link into the Wakit dashboard.<\/li>\n<\/ul>","raw_excerpt":"Connect your site to Wakit in one click, then send WhatsApp order updates and let customers sign in with a code.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/358133","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=358133"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/wakitdev"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=358133"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=358133"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=358133"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=358133"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=358133"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=358133"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}