SMS Phone Verification Help
Overview
SMS Phone Verification confirms that a guest actually has access to the phone number they entered, using a 6-digit code sent by SMS.
This is not a login feature. A successful verification does not issue the guest a session or an account — guests can keep booking and checking in without logging in, exactly as before. All that's recorded when verification succeeds is a single attribute: "this phone number is reachable by its owner."
This feature is off by default. Sending SMS has a real cost, so nothing is sent unless the facility explicitly configures a sending source and turns on verification on the screens where it wants it.
There are three separate places where verification can be required, and each is toggled independently.
| Surface | Where you configure it | What it applies to |
|---|---|---|
| Native phone field at booking time | Plan Configs tab → edit a reservation config | The native phone number field on the Booking screen |
| Mobile number field on a form | Forms → form editor | The "Mobile Number" field on forms shown at booking, check-in, or membership sign-up |
| Front-desk manual override | Reservation drawer | A fallback for guests whose phone can't receive an SMS |
None of these can be turned on until the facility has configured an SMS sending source (see below).
How to Access
- Sending source: Connection Settings → External Integrations → "SMS/Voice Notifications (Twilio)", or directly at
/integrations/twilio-sms - Native phone field at booking: Booking Management → Plan Configs tab → create/edit a reservation config
- Form mobile number field: Forms → open a form → field list
- Front-desk manual verification: Booking Management → a reservation card → the phone field in the reservation drawer
Features
Feature 1: Configure the SMS/Voice sending source
Before anything else, you must choose a sending source. Opening /integrations/twilio-sms shows the current source: "Not set", "Your own Twilio (BYO)", or "UnlockOS (platform)".
Source options
| Option | Description | Cost |
|---|---|---|
| Send from your own Twilio (BYO) | Register your Twilio credentials (Account SID, Auth Token, sending number) and send through your own account | Billed directly to your Twilio contract. No charge from UnlockOS |
| Send from UnlockOS (platform) | No Twilio contract required — sent over UnlockOS's own line | ¥25/segment for SMS, ¥60/min for voice. Deducted from your pre-paid credit balance every time a message is sent |
Choosing "Send from UnlockOS" requires checking a consent box that states the per-unit price before it can be enabled. It cannot be activated without this consent.
Choosing "Send from your own Twilio" requires registering the Account SID, Auth Token, and sending number (an E.164 phone number, or a Messaging Service SID), and the source is only activated once a connection test succeeds. A failed test never disturbs a connection that is already working.
While using your own Twilio, a failure in your credentials never causes an automatic fallback to UnlockOS's line (to avoid unintended billing). Sending simply fails, and the reason is recorded in the history.
Switching or disabling the source
- You can switch sources at any time via "Switch to sending from UnlockOS" / "Switch to sending from your own Twilio"
- While on your own Twilio, use "Test connection" to check connectivity
- "Disable SMS sending" turns off the following together (after showing you the affected counts):
- If phone verification was "Required", it reverts to "not required" (guests can proceed without verifying)
- Notification workflows whose channel is set to "SMS" or "Voice" are disabled
- Pending SMS notifications are cancelled
- Workflows on the "Auto" channel remain active (they fall back to email/LINE delivery)
Settings that were turned off this way do not come back automatically when you re-configure a sending source. You need to turn them on again.
Feature 2: Require SMS verification on the native phone field at booking time
To require verification on the phone field guests enter directly on the Booking screen (separate from the mobile number field inside a form), use the "Require SMS verification of phone number" checkbox on the reservation config edit screen (Plan Configs tab).
- This checkbox cannot be operated while the sending source is unconfigured ("Please configure a sending source first" is shown)
- Once enabled, the description reads: "Confirms the phone number by SMS at booking time. Guests who cannot receive the SMS cannot book (the facility's contact info is shown to them). Sending has a cost."
- This setting is per reservation config (per booking URL). If you run multiple configs, enable it individually on each one where you want to require it
See the Booking Management Dashboard help for details on the config screen itself.
Feature 3: Require SMS verification on a form's mobile number field
The "Mobile Number" field shown on forms at booking time, check-in time, or membership sign-up can have SMS verification set at the field level. Because the same form definition can appear either at booking or at check-in, this setting lives on the field, and applies uniformly regardless of when the form is shown.
Configure it from Forms → open the target form → field list. The target row shows an "SMS Verification" badge (toggle).
Conditions for enabling it
| Condition | Description |
|---|---|
| The field must be a phone-number type | The badge only appears on phone-type fields (e.g., the default "Mobile Number" field). Once a field has been turned on, the badge keeps showing even if the field's type is later changed |
| The field must be "Required" | Optional fields cannot have this set — an optional field can be submitted blank, which would make verification meaningless |
| The sending source must be configured | While unconfigured, the toggle cannot be operated, and a notice with a link to the setup screen appears above the field list |
The default "Mobile Number" field (formerly labeled "Phone Number") has had its label and type updated to support SMS verification. See the Form Management help for details.
Membership application forms are built on the same form mechanism, so this field-level setting applies to their mobile number field as well.
Feature 4: The guest's verification flow
Wherever verification is required, a confirmation control appears just below the phone number field.
- Once you enter a phone number, the "Verify by SMS" button becomes clickable
- Clicking it sends a 6-digit code by SMS and reveals a code input field and a "Confirm" button. A message such as "Sent to XXX-XXXX-XX34" shows the destination number (masked except for the last few digits)
- Enter the code you received and tap "Confirm" — the display switches to "✓ Verified"
- Once verified, the input field becomes read-only. To change the number, use the "Edit" link to unlock it temporarily (the verified state is kept until you actually change the number)
Resending and expiry
| Item | Value |
|---|---|
| Code length | 6 digits |
| Expiry | 10 minutes from issuance |
| Resend cooldown | 60 seconds (a countdown "Resend in NN" is shown until then) |
| Attempts allowed per code | Up to 5 |
If the SMS can't be sent
If the "Verify by SMS" attempt itself fails to send, an error message appears along with the facility's contact information (phone number / email, if configured). Voice-call verification is not available at this time. If the SMS never arrives, guests should contact the facility directly using the contact details shown.
Feature 5: Front-desk manual verification (for guests the SMS can't reach)
For guests who cannot receive an SMS (out of signal range, changed their number, using a foreign SIM, etc.), a staff member who has confirmed the guest's identity in person can mark the number verified without sending an SMS.
Location: Booking Management → click a reservation card → the phone number field in the reservation drawer
For a reservation whose phone number is not yet verified, a "Verify at front desk" link appears below the phone field (hidden while creating a new reservation, or if no phone number is entered).
- Clicking "Verify at front desk" expands a confirmation message
- It reads: "This will mark XXX-XXXX-XX34 as verified without sending an SMS. Only use this after confirming the guest's identity in person. Who performs this action is recorded."
- Clicking "Mark as verified" applies immediately, and a "✓ SMS Verified" badge appears next to the phone field
This action is recorded with who performed it. Since it creates a verified attribute without going through SMS, only use it after confirming the guest's identity in person (e.g., checking an ID document).
Feature 6: How verification status appears in the owner screen
The phone field in the reservation drawer shows a green "✓ SMS Verified" badge only when the number is verified (nothing is shown for an unverified field). Hovering over the badge shows when it was verified.
Phone numbers can be formatted in different ways (e.g. "090-1234-5678"). If the text in the field differs from the number that was actually matched at verification time (for example, if it contains full-width characters), the badge shows the actual verified number in parentheses next to it.
Scope of a verified number (current behavior)
- Verification is kept per facility, per phone number. If the same number is entered again — even by a different guest, on the same or another reservation — it is treated as verified within that facility (this supports families or companions who share a phone number)
- Verification is not currently carried over between facilities. At a different facility, even a number verified elsewhere requires SMS verification again
- Verified status does not expire (once verified within a facility, it stays that way)
Pricing
For facilities using "Send from UnlockOS", verification-code SMS is deducted from the same pre-paid balance used for check-ins. It appears in the transaction history as "SMS/Voice usage," on a separate line from check-in usage. See the Billing help for per-unit pricing and what happens when your balance reaches zero.
Facilities using "Send from your own Twilio" are not billed by UnlockOS at all (charges go directly to your Twilio contract).
Troubleshooting
Q: The "SMS Verification" toggle can't be clicked
A: One of the following applies:
- The sending source (Twilio) is not configured — open
/integrations/twilio-smsvia the notice link and configure it - The field is not marked "Required" — turn on the Required toggle first (verification cannot be set on optional fields)
- The field is not a phone-number type — this setting only applies to phone-number type fields
Q: "Require SMS verification of phone number" is greyed out on the reservation config
A: The sending source is not configured. Configure it first from App Integrations → "SMS/Voice Notifications".
Q: A guest told us they never received the SMS
A: First check that your sending source is set up correctly (run a connection test if using your own Twilio). Also check the number's format (missing country/area code). If it still can't be resolved, confirm the guest's identity in person and use "Verify at front desk."
Q: We get an error entering the confirmation code
A: A code expires 10 minutes after it's issued, and each code allows up to 5 verification attempts. If it has expired or you've run out of attempts, use "Resend" to get a new code.
Q: We sent the code to the wrong number
A: Before verification completes, editing the phone field will resend the code to the new number. If you want to restart from an already-verified state, use the "Edit" link to unlock the field, then correct the number.
Q: We get an error when sending too many times in a short period
A: There are limits: a 60-second interval between resends to the same number, up to 5 codes per number per day, and up to 100 sends per facility per hour. Since each SMS has a real cost, these limits guard against abuse or accidental over-sending.
Q: After disabling SMS sending, the "Required" phone verification setting disappeared
A: This is expected. Turning off the sending source automatically reverts any reservation config that required phone verification back to "not required." To require it again, re-configure the sending source and then re-enable it individually on each reservation config and form field (it does not come back automatically).