finds.dev← search

// the find

CuriousLearner/django-phone-verify

★ 291 · Python · GPL-3.0 · updated Sep 2026

A Django app to support phone number verification using security code / One-Time-Password (OTP) sent via SMS.

django-phone-verify is a Django/DRF app that handles the send-code/verify-code flow for phone number verification, with pluggable backends for Twilio and Nexmo/Vonage. It's aimed at teams building 2FA, signup verification, or account recovery who don't want to hand-roll OTP session handling and SMS vendor integration themselves.

The backend is genuinely pluggable — Twilio and Nexmo ship built-in, and swapping vendors means implementing one base class rather than rewriting the flow. Verification state isn't just phone+code in a table: JWT session tokens tie a code to a specific session, and the migration history shows a failed_attempts field was added to the model later, so brute-force lockout is enforced at the schema level, not just suggested in docs. There's a dedicated management command to purge expired verification rows, which a lot of OTP packages skip and just let the table grow forever. Sandbox mode lets you exercise the full flow in CI without spending real SMS credits.

It's GPLv3, which is a real license bear trap for a library meant to live inside someone else's API service — most comparable DRF packages are MIT/BSD, and dropping this into a closed-source product pulls in obligations most teams won't want. The README leans heavily on emoji marketing bullets ("production-ready," "GDPR/CCPA compliance guidance," "rate limiting support") without a dedicated throttle or compliance module in the tree to back them up — those read as aspirational, not shipped. Only two SMS vendors are actually implemented; anything else (SNS, MessageBird) is "write your own," so the pluggability is more of a documented contract than a library of adapters. Rate limiting on the send-code endpoint isn't built in — you're expected to wire up DRF throttle classes yourself despite the feature-list bullet implying otherwise.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →