Receiving MFA Verification Codes via WhatsApp

PurposeSwitch multi-factor authentication code delivery between SMS and WhatsApp for your account or another user.
Best forCloudbeds PMS users managing phone verification code delivery for themselves or other users.
Use this whenYou want to use WhatsApp for phone verification codes, manage WhatsApp delivery for another user, or return to SMS delivery.
RequirementsPhone (SMS) verification must already be enrolled, and the enrolled phone number must have an active WhatsApp account.
Expected resultFuture phone verification codes use the selected delivery channel. If WhatsApp delivery is unavailable, Cloudbeds automatically falls back to SMS.
LimitationsThe delivery-channel option becomes available after you have been signed in for at least 10 minutes.

Introduction

Cloudbeds PMS supports WhatsApp as a delivery channel for multi-factor authentication codes. WhatsApp can provide faster and more consistent delivery when SMS is slow, unreliable, or costly in your region, with no additional delivery fee.

WhatsApp delivery is an alternative delivery channel for an enrolled Phone (SMS) verification method. It is not a separate multi-factor authentication method. You can enable WhatsApp for your own account from your profile, or manage WhatsApp delivery for another user from User Management. Use this article to confirm the requirements, choose the applicable workflow, and resolve common delivery issues.

Table of contents

Before you start

Complete Phone (SMS) verification enrollment before changing its delivery channel to WhatsApp. WhatsApp does not appear during initial phone enrollment. After Phone verification is enrolled, WhatsApp can be enabled from the user's profile or through User Management.

Confirm both requirements before continuing:

  • Phone (SMS) multi-factor authentication is already enrolled for the applicable user.
  • The enrolled phone number has an active WhatsApp account.

 Why does WhatsApp not appear during initial phone setup? Complete Phone (SMS) enrollment first. WhatsApp can then be enabled for the enrolled Phone verification method.

Enable WhatsApp delivery

Phone (SMS) verification must already be enrolled before WhatsApp can be used. You can enable WhatsApp for your own account from your profile, or enable it for another user through User Management.

Enable WhatsApp for your own account

  1. Sign in to Cloudbeds PMS.
  2. Select the Account Account Menu.jpg icon in the top-right corner, and select My Profile.
  3. Go to Sign-in & security.
  4. Under Two-factor authentication, select Manage methods.

Cloudbeds My Profile page showing the Sign-in and security section and the Manage methods button under Two-factor authentication.

  1. Find the enrolled Phone verification method.
  2. Turn on Send authentication codes via WhatsApp instead of SMS.

In the Two-factor authentication panel, the WhatsApp delivery toggle appears within the enrolled Phone method.

Cloudbeds Two-factor authentication panel showing the enrolled Phone method and the Send authentication codes via WhatsApp instead of SMS toggle. 

The next time you use Phone to verify your identity, Cloudbeds sends the verification code through WhatsApp. If WhatsApp delivery is unavailable, Cloudbeds automatically falls back to SMS.

 Availability: The delivery-channel option becomes available after you have been signed in for at least 10 minutes. If it is not visible, wait a few minutes and refresh the page.

Enable WhatsApp for another user

You can enable WhatsApp delivery for another user if that user already has Phone (SMS) verification enrolled. WhatsApp changes the delivery channel for the existing Phone verification method; it does not add a separate authentication method.

  1. Sign in to Cloudbeds PMS.
  2. Select the Account Account Menu.jpg icon in the top-right corner.
  3. Select Settings Settings icon.png and go to Users Users.png
  4. In the Property Users table, find the user whose WhatsApp delivery you want to manage.
  5. In the Actions column, select the three-dot menu and choose Edit User.

Cloudbeds User Management page showing the Users section, the Property Users table, and the Actions menu with Edit User available for a selected user.

  1. In the Edit User window, turn on Send authentication codes via WhatsApp instead of SMS.

The WhatsApp option appears in the Edit User window when the user has Phone verification available.

Cloudbeds Edit User window showing the Send authentication codes via WhatsApp instead of SMS toggle before it is enabled.

  1. Review the confirmation message and select the checkbox to confirm that the user can receive WhatsApp messages and understands that they will need to enter the code sent via WhatsApp when signing in to Cloudbeds. The Save button remains unavailable until the checkbox is selected.
  2. Select Save.

After the toggle is enabled, the Edit User window displays the confirmation requirement before you save the change.

Cloudbeds Edit User window showing WhatsApp authentication enabled, the confirmation that the employee can receive WhatsApp messages, and the Save button. 

After WhatsApp delivery is enabled, verification codes for the user's Phone authentication method are sent through WhatsApp. If WhatsApp delivery is unavailable, Cloudbeds automatically falls back to SMS.

Receive verification codes after enabling WhatsApp

Enabling WhatsApp does not change the Phone authentication flow. After entering your password, select Phone when Cloudbeds asks how you want to verify your identity.

If WhatsApp delivery is enabled for the enrolled phone number, Cloudbeds sends the verification code through WhatsApp. If WhatsApp is unavailable or the phone number cannot receive WhatsApp messages, Cloudbeds automatically falls back to SMS.

During Phone verification, the sign-in screen indicates that the code can be delivered by SMS or WhatsApp.

Cloudbeds Verify with your phone screen showing that a verification code can be sent by SMS or WhatsApp to the enrolled phone number. 

Switch back to SMS delivery

Return to the Phone verification method in your profile if you prefer to receive future verification codes by SMS instead of WhatsApp.

  1. Sign in to Cloudbeds PMS.
  2. Select the Account Account Menu.jpg icon in the top-right corner, and select My Profile.
  3. Go to Sign-in & security.
  4. Under Two-factor authentication, select Manage methods.
  5. Find the enrolled Phone verification method.
  6. Turn off Send authentication codes via WhatsApp instead of SMS.

When the toggle is off, the Phone verification method returns to SMS delivery.

Cloudbeds Two-factor authentication panel showing the Phone method with the Send authentication codes via WhatsApp instead of SMS toggle turned off. 

Troubleshoot WhatsApp delivery

Use the issue that matches what you see in your profile or during sign-in. If WhatsApp delivery is unavailable, Cloudbeds automatically falls back to SMS.

The WhatsApp option does not appear in my profile

WhatsApp delivery requires Phone (SMS) verification to be enrolled first. If you have not enrolled phone verification, complete that setup before returning to your profile. Refer to Set up Okta Verify or Set up alternative MFA methods for the applicable enrollment workflow.

If Phone (SMS) verification is already enrolled and the WhatsApp option is not visible, confirm that you have been signed in for at least 10 minutes. If needed, wait a few minutes and refresh the page.

A WhatsApp verification code does not arrive

If Cloudbeds cannot deliver the verification code through WhatsApp, such as during a WhatsApp delivery issue or when the enrolled phone number cannot receive WhatsApp messages, Cloudbeds automatically falls back to SMS.

Check the text messages sent to the enrolled phone number for the verification code.

I received a WhatsApp code that I did not request

 Do not share the code. An unrequested code may mean that someone is attempting to sign in to your account. Change your Cloudbeds password immediately, and contact your property administrator to review recent account activity.

Understand WhatsApp delivery security

WhatsApp delivery is more reliable than SMS in many regions and does not carry an additional fee. Like SMS, it remains vulnerable to real-time phishing when an attacker captures and immediately reuses a verification code.

For stronger phishing protection, use a passkey when available. Refer to Setting up passkeys (the gold standard) for the passkey workflow.


Now that you can manage WhatsApp delivery for verification codes, review these resources for adjacent multi-factor authentication methods and security guidance:

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.