Naming the username key
WHATSAPP - CONTENT STRATEGY - NAMING - PRIVACY FEATURE 2026
What: Naming a brand-new privacy mechanism for usernames on WhatsApp - the code (or discriminator) that lets people control who can message them by username for the first time.
Goals: The name had to be simple enough for a global, multilingual audience, consistent with how WhatsApp already names settings and clear enough among existing privacy terms.
Challenge and scope
How Might We… give people an easy, low-friction way to be reached by trusted strangers with their new username — while making sure that ease doesn't open the door to spam, scraping, or unwanted contact from people they've never interacted with?
As WhatsApp rolled out usernames, we introduced an optional discriminator: a short, numeric code a person sets alongside their username and shares only with the non-contacts they trust — a taxi driver, a tour guide, anyone without their phone number. A non-contact needs both the username and the code to message that person for the first time. The naming challenge sat at the intersection of privacy positioning, translation risk across dozens of markets, and consistency with WhatsApp's existing settings and terms.
How it works
The scenario:
Imagine you’re in a foreign country and hailing a cab. You probably don’t want to share your number with the total stranger who will give you a ride.
Once your WhatsApp username and key are set up, you can share both with the cab driver. They’ll need both to send you the first message.
This way, you can connect with strangers safely without ever revealing your phone number.
Contacts — can message the username easily. They only need to know it.
Connections — people who share a group can see and message the username — shared-group membership is treated as a form of trust.
Strangers — people never interacted with need the username plus the code to send a first message. (ex. Cab driver)
Strategy and process
As the content designer on this workstream, I framed the naming decision around a jobs-to-be-done lens, stress-tested it against WhatsApp's existing settings vocabulary, and ran it through multiple rounds of crit, uxr and company-wide dogfooding before landing on a term.
Jobs to Be Done — Defined the underlying need — people want to limit random messages from strangers while keeping control over who can reach them.
Working Principles — Positioned the code as a privacy benefit, not a barrier, and required that it be given an explicit, easy-to-reference name.
Naming Exploration — Generated and stress-tested terms — PIN, key, code, discriminator, passcode — against clarity, tone, and support-ticket legibility, and existing terms in product.
Localization Check — Ran terms against translation risks, surfacing that "discriminator" fails badly in Spanish and several other markets and isn’t conversational.
"When I create a username and code, I want to limit random messages from strangers so that I can control my experience and who can reach me." - Jobs to be done statement defining the need
Working principles
The code is a privacy benefit against unwanted contact, per UXR — it needed to be positioned this way in messaging, not framed as friction.
In-product explanations must make clear that the code has to be shared with unknown accounts to be reachable by them — knowing the username alone is not enough.
I recommended that the feature needed an explicit name — something like "App lock" or "Secret code" — so people had a consistent way to refer to it, both casually and in support conversations.
Here’s what I presented to WhatsApp leads to understand if the code requires naming.
Terms tested and vetted
Username PIN
Pros: UXR recommendation; fits the mental model of a PIN as a set of numbers used to access something; mirrors BBM PINs, also positioned as something you share; pairing with the qualifier ("UN PIN") helps comprehension; "I need help with my UN PIN" reads clearly in a support ticket.
Cons: a PIN is typically not something you give out and share; WhatsApp already has other PINs (2FA, phone PIN) that could cause overlap.
Username Key
Pro: Simple, term is recognized worldwide for privacy.
Cons: reads like a long string of numbers; evokes encryption keys; overlaps with passkeys, which carry their own rules; "I need help with my key" isn't clear in a support ticket.
Contact key
Could support a marketing story around using a key to contact someone's username; but "contact" risks implying it adds someone to your contacts.
Verification key
There is a quick verification step before a message can be sent with a code; but it may sound like a step to verify or register yourself.
PIN (alone)
Pro: Fits the mental model of PINs as numbers-only
Con: Without a qualifier it might sound like a step to verify or register. People will think it’s their personal bank PIN or use their personal PINs as their code, especially in “new to app” markets.
Contact PIN
Pro: Setting context and body copy help clarify that "contact" refers to the username.
Con: A PIN typically isn't something you give out and share; could be confusing since WhatsApp does other things with contacts already.
Username code
Pairing with the qualifier helps comprehension and reads clearly in a support ticket; but a code typically isn't something you give out and share, and WhatsApp already has other codes (e.g. secret code for Chat Lock). Not approved — more exploration requested from leads.
Discriminator
Too technical, though WhatsApp uses other industry terms like 2FA. Translation risk: in Spanish it literally reads as "someone who discriminates" — code, PIN, or number are better choices. Additional +1 flags from Indonesian, Brazilian Portuguese, Italian, and Japanese localization.
Passcode
Technically stronger than what the discriminator might imply; can be numeric or alphanumeric.
Making a recommendation
First rec: Username PIN
Second rec: Username key
Usage: pair the term with a qualifier rather than using "PIN" alone — e.g. "UN PIN," "Contact PIN" — to support comprehension. "PIN" alone is fine in high-comprehension areas (HCAs) and other established contexts.
Recommended combination: PIN + Username PIN, used contextually depending on placement.
Pivoting to a new term
"Username PIN" was the recommended direction going in — but company-wide dogfooding surfaced enough real-world confusion (PIN association with banking/SSN codes, mismatch with how people naturally described the feature) that the team revisited the decision.
I provided my second recommended term to pivot to and prioritize what actually stuck with people in practice over the initial UXR-backed recommendation.
This pivot is a reminder that naming recommendations — even well-researched ones — need to hold up under real usage, not just initial uxr and internal discussions. Dogfooding at Meta’s scale was the fast, high-signal way to catch that gap before it reached real WhatsApp users.