SMS OTP (Short Message Service One-Time Password)
A single-use passcode sent via SMS for authentication, often used in 3D Secure, login flows or account verification.

An SMS OTP is a short code sent by text message that a customer types back in to prove they hold the phone tied to their account. The code works once, and for a short window: a few minutes at most in most setups. It shows up at checkout, at login, and when a customer changes something sensitive such as a payout account. Its appeal is plain. Nearly every customer has a phone that gets texts, no app is needed, and the flow is familiar enough that support calls stay low.
It is also the weakest of the common second factors, and the bodies that write authentication standards say so. The US guidance in NIST SP 800-63B treats an out-of-band code sent over the public telephone network as a restricted authenticator: allowed, but discouraged, with a duty to warn users and a plan to move on. The reason is that the code travels over a network the payment firm does not control, and a phone number is easier to take over than most people assume. Firms tend to keep it anyway, because coverage beats elegance.
How The Flow Runs
The steps are short. The customer starts a payment or a login. The server makes a code, stores a hashed copy against the session with a short expiry, and hands it to a messaging provider. The provider passes it to the mobile network, which delivers it to the handset. The customer reads it and types it back. The server compares the two, clears the stored copy and lets the session through. Nothing on that list is slow on its own, yet the whole chain is only as quick as the mobile network on the day. Every one of those hops can fail, and most of them sit outside the firm's own systems.
Where It Counts As A Factor
Under the European rules, strong authentication rests on two of three kinds of evidence: something the customer knows, something they hold, and something they are. A code sent to a phone is usually counted as possession, so it pairs with a password or a PIN to satisfy strong customer authentication. What it does not do on its own is cover both legs. A flow that sends a code and asks for nothing else has one factor, however secure the code feels.
The Ways It Gets Broken
There are three routes. A SIM swap moves the number to an attacker's handset after a call to the mobile operator, and every code then goes to them. Interception attacks take advantage of old signalling protocols between networks. And social engineering skips the technology altogether: the attacker rings the customer, says they are from the bank, and asks them to read the code out. That last one works far too often, and it is the reason the message wording matters as much as the code length.
Delivery Is Not Under Your Control
Once the message leaves the provider, the outcome rests with the mobile network. Codes arrive in two seconds or in two minutes, and sometimes not at all. Delivery rates vary sharply by country, and some networks filter traffic they read as marketing. Roaming customers may get nothing. A firm that treats delivery as certain will build a flow with no way out, and the fallout lands in the basket as an abandoned order rather than as an alert.
The Cost Nobody Budgets For
Each message is paid for, and the price varies by country by a wide margin. High-volume markets can be cheap, while some are dear enough that the code costs more than the margin on the sale. Retries multiply it, since a customer who does not get the first code will ask for two more. There is also a fraud angle: attackers can drive traffic to premium routes and take a cut, which turns a login page into a bill. Rate limits per number and per session are the usual guard.
What Stronger Looks Like
An app-based authenticator holds the secret on the device rather than sending it over a network. A passkey binds the login to the device and the site, so a code read out to a stranger is worth nothing. Two-factor authentication using either of those is generally seen as stronger than a text. The practical route for most firms is to offer the stronger option, default new customers to it, and keep SMS as the fallback for the ones who cannot or will not move.
Writing The Message Itself
The text itself is a control. Put the code early, so it can be read from a notification without opening the app. Name the firm and say what the code is for. Include a plain line telling the customer that nobody from the firm will ring and ask for it. Keep the code to six digits and the life to a few minutes, and say so in the message. Where a payment is involved, showing the amount and the payee lets a customer spot one they did not start.
Using It Without Relying On It
Treat SMS OTP as a floor, not a finish. Watch delivery rates by country and provider, and set a second provider to take over where one is weak. Give a fallback that does not depend on the same number, such as email or a call back to an agent. Limit how often a code can be asked for, and lock a session after a few wrong tries. Use SCA exemptions where the rules allow, so low-risk payments are not sent through a code at all, and read Article 18 of the regulatory technical standards for what transaction risk analysis is expected to cover. This piece on smart 3D Secure covers the decline side, and payment fraud detection is designed to help decide when a challenge is worth it.
Frequently Asked Questions
It is widely used and widely criticised. Authentication guidance treats codes sent over the public telephone network as a restricted option, allowed but discouraged, because the number can be taken over and the message can be intercepted or talked out of a customer.
Most implementations use a window of a few minutes, which is long enough for a message to arrive and short enough to limit reuse. Pairing a short window with a cap on attempts does more for security than adding digits to the code.
Delivery is in the hands of the mobile network, so late or missing messages are routine in some markets. Sensible flows offer a resend after a delay, a second delivery route, and a fallback that does not depend on the same number.
Partly to control cost, since every message is paid for and prices vary sharply by country, and partly to curb abuse. Attackers can push traffic to expensive routes and take a share, which turns a login page into an unexpected bill.
An authenticator app keeps the secret on the device rather than sending it over a network, and a passkey binds the login to both the device and the site. Offering one of these while keeping SMS as a fallback tends to work better than a hard switch.

Still Have Questions?
Let’s Find the Right Solution for You
Stay Connected with Us!
Follow us on social media to stay up to date with the latest news, updates, and exclusive insights!


