Login OTP
SMS{#var#} is your OTP for {#var#}. Valid for {#var#} minutes. Do not share it with anyone.Keep the brand name in the template. No offers, no links.
An OTP is a short-lived code sent to a user’s phone to prove they hold the number during login, sign-up or a payment. Indian OTPs must go through a DLT-registered sender and an approved template, and the reliable ones add a second channel for the times SMS does not arrive.
When an OTP is late, the user does not blame the network. They blame your app, and many do not try again. Delivery speed and a sensible fallback are worth more than any tweak to the login screen.
CONNEX
SMS · OTP
9:15 AM
Create a random code, store only a hashed copy with an expiry time, and rate-limit requests per number so nobody can flood a user’s phone.
Send the number, your template ID and the code as the variable. The message text stays exactly as approved.
The message goes on a route kept separate from promotions, which is what keeps delivery time in seconds rather than minutes.
If the report says failed, or nothing arrives within your threshold, offer the user a resend and switch channel.
Compare the entered code with the stored hash, accept it only once, and expire it straight away. Lock the account after a few wrong attempts.
| Channel | Use it for | Why |
|---|---|---|
| SMS | The default OTP for every user | Works on any phone and needs no data. Delivery is fastest on the transactional route. |
| Fallback or first choice where users live in WhatsApp | Authentication templates support a one-tap copy button. Billed per message by category. | |
| Voice | Users who cannot receive SMS, or older users on basic phones | A spoken code reaches people who never see texts. Good as a last fallback. |
| RCS | Not recommended as the only OTP channel | Not every handset supports it. Use SMS fallback if you send it over RCS. |
Variables are written as {#var#}, the way they appear on a DLT template. Adapt the wording to your brand, then register it.
{#var#} is your OTP for {#var#}. Valid for {#var#} minutes. Do not share it with anyone.Keep the brand name in the template. No offers, no links.
{{1}} is your verification code.
[Copy code]Use WhatsApp’s authentication category. It has a fixed format and a copy-code button.
Your verification code is {#var#}. I repeat, {#var#}. This code expires in five minutes.Read the digits slowly and twice. Keep the script short.
A code that works for an hour is a code that can be stolen. Five minutes is enough for most flows, and it should work only once.
Unlimited resend requests are how a competitor or bot runs up your SMS bill and annoys your users. Cap it per number and per hour.
The template can be treated as promotional and blocked. OTP messages should contain the code, the brand and a warning, nothing else.
Phones go off and networks drop. Offer a resend after 30 seconds and a different channel after that.
Yes. Every commercial SMS in India, including OTPs, must come from a DLT-registered entity using an approved header and template. Messages that do not match an approved template are blocked.
Transactional and service messages such as OTPs are not restricted by DND, as long as they use approved templates and carry no promotional content.
Most services use between three and ten minutes. Shorter is safer, but leave time for delivery delays and typing. Always make the code single use.
Common causes are a template mismatch, an unregistered header, a non-whitelisted link, operator congestion, or the message being sent on a promotional route. Check the delivery report and the template first.
A WhatsApp authentication message or a voice OTP. Both give the user another way to get the code without starting the login again.
Share your current delivery numbers and the template you use. We will check the route, header and template and tell you what to change.