Auth and identity · Pattern

One-time passwords (OTP)

A short code, usually six digits, that works once and expires within minutes. It is sent by SMS or email, or generated by an authenticator app, to prove a person controls that phone, inbox or device.

Ways to sign in · Pay as you go · updated

How it works

There are two families. Sent codes are created by the server, delivered by SMS, email or WhatsApp, and checked against a stored copy; they prove the person can receive messages at that number or address. Generated codes come from an authenticator app such as Google Authenticator, Microsoft Authenticator or a password manager, using TOTP (time-based one-time passwords): the app and the server share a secret, set up once by scanning a QR code, and both work out the same code every 30 seconds without any message being sent.

Codes serve either as the whole sign-in (phone-number login is common in mobile-first markets such as India) or as a second step after a password. Good implementations keep codes short-lived, allow only a few attempts, limit how often codes can be sent and store them hashed. SMS has known weaknesses: numbers can be hijacked through SIM swapping, messages can arrive late or not at all, and attackers run 'SMS pumping' fraud, triggering thousands of paid messages to numbers they profit from.

One-time passwords (OTP) pros and cons

Pros

  • Familiar to almost everyone, with nothing to install for SMS or email
  • Phone numbers work as an identity where email is less used
  • Authenticator app codes are free and work offline
  • Easy to add as a second step after a password

Cons

  • SMS codes cost money per message and can be delayed or lost
  • SIM swapping lets attackers take over a phone number
  • Codes can be typed into a convincing fake site
  • Open SMS endpoints attract costly pumping fraud

When to use One-time passwords (OTP)

Pick it when

  • Phone-number sign-in for mobile apps where that is the norm
  • A second factor after a password, ideally from an authenticator app
  • Confirming that an email address or phone number is real

Skip it when

  • High-value accounts, where passkeys or security keys resist phishing
  • SMS costs and fraud controls would not pay off at your volume

One-time passwords (OTP) pricing

Pay as you go

Email and authenticator app codes cost nothing extra. SMS is billed per message, from about a cent in the US to tens of cents elsewhere; Twilio Verify adds $0.05 per successful check.

One-time passwords (OTP) pricing page (opens in a new tab)Approximate, checked September 2026.What the other tools cost

One-time passwords (OTP) vs the alternatives

More in Auth and identity

Ways to sign in

All 17 Auth and identity terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.