Widgets

Patient verification

How Medos widgets verify a patient with a one-time code by phone or email, which widgets verify, and how otpChannels narrows the choice.

Before a widget shows or changes anything about a patient, it confirms they control the contact they typed, with a one-time code.

WidgetVerifiesChannels
BookingYesPhone and email, set with otpChannels
Patient portalYes, to sign inPhone and email, set with otpChannels
Package purchaseYesPhone only — otpChannels isn't accepted
Enquiry formNo— contact details are taken at face value

otpChannels

OptionTypeDefaultDescription
otpChannels("phone" | "email")[]["phone", "email"]Which channels the verification step offers the patient.

Both channels are offered by default, so a patient can verify on whichever one they can actually receive a code on. Narrow it when your workspace only supports one:

// A workspace with no email sending domain configured
MedosBooking.init({
  apiKey: "mk_your_publishable_key",
  otpChannels: ["phone"],
});

The order you list them in doesn't matter — the toggle always reads the same way, with phone first when both are offered.

A bad value falls back to phone only, not to both

If otpChannels isn't an array, or contains nothing usable, the widget uses ["phone"] alone. A garbled value isn't evidence that email delivery works for your workspace, and offering a channel that silently never delivers is worse than offering one fewer.

The portal follows the same rules — pass otpChannels to MedosPatientPortal.init().

On this page