Back to marketplace
228

SMS Verify

Buy now

Requires every user to confirm a mobile phone number by SMS before they can use the platform.

Requires every user to confirm a mobile phone number by SMS before they can use the platform.

Features

  • One-time verification for every user, or only for the groups you choose.
  • 6 SMS providers, most of them EU-based: seven.io (πŸ‡©πŸ‡ͺ), Infobip (πŸ‡­πŸ‡·), Brevo (πŸ‡«πŸ‡·), Twilio, the HumHub SMS module, and a log-only driver for testing.
  • Gradual rollout β€” limit to groups, exempt existing members, exempt LDAP/SSO logins, or allow a few grace logins before it becomes mandatory.
  • Cost protection β€” per-user, per-IP and site-wide daily send limits, plus a country allowlist. Administrators are notified if the daily limit is ever hit.
  • Automatic code entry on iOS and Android, where the phone offers the code from the message.
  • Admin tools β€” see who is verified, verify someone manually, reset one user or everyone.
  • GDPR-ready β€” documented data flows, automatic IP purging, per-user export and erasure.

How it works

  1. A user who has not verified is sent to a verification page instead of the page they asked for. Logging out always stays possible.
  2. They pick their country and enter their mobile number.
  3. They receive a short code and type it in. Their phone may offer to fill it in for them.
  4. Done β€” they continue to where they were going, and are never asked again.

The number is saved to a profile field of your choice, in international format (+33608567485) so it is unambiguous and dialable. If it later changes, verification is asked for once more. Reformatting the same number changes nothing.

Not two-factor authentication

SMS VerifyHumHub's 2FA module
AskedOnce, everOn every login
ProvesThe person controls a phone numberThe person logging in owns the account

They are independent and work fine together. Neither replaces the other.

Setup

Everything is on the module's configuration page. It checks your settings as you go and warns you about anything that would stop codes from arriving.

Switching this on asks every user in scope to verify on their next request. The configuration page shows how many people that is before you save, and lets you narrow it down first.

If you ever lock yourself out, run this from a shell in HumHub's protected directory:

php yii sms-verify/disable

Nothing is deleted β€” switching it back on restores every existing verification.

Privacy

Stored: the phone number, its country, and when and how it was verified. While a code is pending, also a hash of the code (never the code itself), attempt counters and the requesting IP address β€” IPs are deleted automatically after 7 days.

Sent to the SMS provider: the destination number and the message text. Nothing else β€” no name, no e-mail address, no user id.

Two things you need to handle yourself:

  • The SMS provider is a processor. You need a data processing agreement (AVV) with them, and for a provider outside the EU also a valid transfer mechanism. Each provider's data residency is shown on the configuration page.
  • The legal basis is your decision. Is phone verification necessary for your service, or does it need consent? If it is not necessary, someone who declines must still be able to use the platform β€” which, with this module on, they cannot. Get advice if the answer is not obvious.

A ready-to-adapt paragraph for your records of processing, and the commands for subject access and erasure requests, are in ?#developer.

Pricing

  • €45 including one-year of updates and support
  • €25 each year for updates and support
  • Possible discount for non-profit organizations or countries with a very low median income

You can:

Support, questions & feature requests

Module Information

Price:
45 €
Latest version release:
1.0.0 - September 27, 2026
Publisher:
Author(s):
Website:
Compatibility:
HumHub 1.19 - 1.19