ConnexBetter LogoConnexBetter

Authentication and OTP that gets through first time

An OTP is a short-lived code sent to a user’s phone to prove they hold the number during login, sign-up or a payment. Indian OTPs must go through a DLT-registered sender and an approved template, and the reliable ones add a second channel for the times SMS does not arrive.

When an OTP is late, the user does not blame the network. They blame your app, and many do not try again. Delivery speed and a sensible fallback are worth more than any tweak to the login screen.

C

CONNEX

SMS · OTP

483920 is your one-time password for Kiran Home Store. It is valid for 5 minutes. Do not share it with anyone.

9:15 AM

An illustrative OTP message.
Delivery
Seconds, on a dedicated transactional route
Fallbacks
WhatsApp authentication template and voice OTP
Must have
DLT entity, header and an OTP template
Code validity
Usually 3 to 10 minutes, single use

What happens between “Send OTP” and “Verified”

  1. 1

    Generate the code and store a hash

    Create a random code, store only a hashed copy with an expiry time, and rate-limit requests per number so nobody can flood a user’s phone.

  2. 2

    Call the API with the template

    Send the number, your template ID and the code as the variable. The message text stays exactly as approved.

  3. 3

    Deliver on the transactional route

    The message goes on a route kept separate from promotions, which is what keeps delivery time in seconds rather than minutes.

  4. 4

    Watch the delivery report

    If the report says failed, or nothing arrives within your threshold, offer the user a resend and switch channel.

  5. 5

    Verify once and invalidate

    Compare the entered code with the stored hash, accept it only once, and expire it straight away. Lock the account after a few wrong attempts.

Which channel does which job

ChannelUse it forWhy
SMSThe default OTP for every userWorks on any phone and needs no data. Delivery is fastest on the transactional route.
WhatsAppFallback or first choice where users live in WhatsAppAuthentication templates support a one-tap copy button. Billed per message by category.
VoiceUsers who cannot receive SMS, or older users on basic phonesA spoken code reaches people who never see texts. Good as a last fallback.
RCSNot recommended as the only OTP channelNot every handset supports it. Use SMS fallback if you send it over RCS.

Message templates worth starting from

Variables are written as {#var#}, the way they appear on a DLT template. Adapt the wording to your brand, then register it.

Login OTP

SMS
{#var#} is your OTP for {#var#}. Valid for {#var#} minutes. Do not share it with anyone.

Keep the brand name in the template. No offers, no links.

Authentication template

WhatsApp
{{1}} is your verification code.
[Copy code]

Use WhatsApp’s authentication category. It has a fixed format and a copy-code button.

Voice OTP script

Voice
Your verification code is {#var#}. I repeat, {#var#}. This code expires in five minutes.

Read the digits slowly and twice. Keep the script short.

What usually goes wrong

Long validity windows

A code that works for an hour is a code that can be stolen. Five minutes is enough for most flows, and it should work only once.

No limit on resends

Unlimited resend requests are how a competitor or bot runs up your SMS bill and annoys your users. Cap it per number and per hour.

Adding a promotion to the OTP

The template can be treated as promotional and blocked. OTP messages should contain the code, the brand and a warning, nothing else.

One channel, no plan B

Phones go off and networks drop. Offer a resend after 30 seconds and a different channel after that.

Getting OTP right the first time

  • OTP template approved on DLT with the brand name inside it.
  • Codes are random, stored hashed and valid for a single use.
  • Resend and attempt limits are set per number.
  • A fallback channel is switched on after the first resend.
  • You log delivery status and can search by number and time.
  • Your app tells the user to never share the code.

Questions we get asked

Is DLT registration mandatory for OTP SMS?

Yes. Every commercial SMS in India, including OTPs, must come from a DLT-registered entity using an approved header and template. Messages that do not match an approved template are blocked.

Are OTPs delivered to DND numbers?

Transactional and service messages such as OTPs are not restricted by DND, as long as they use approved templates and carry no promotional content.

How long should an OTP be valid?

Most services use between three and ten minutes. Shorter is safer, but leave time for delivery delays and typing. Always make the code single use.

Why is my OTP delayed or missing?

Common causes are a template mismatch, an unregistered header, a non-whitelisted link, operator congestion, or the message being sent on a promotional route. Check the delivery report and the template first.

What is the best fallback when SMS OTP fails?

A WhatsApp authentication message or a voice OTP. Both give the user another way to get the code without starting the login again.

Fix slow or missing OTPs

Share your current delivery numbers and the template you use. We will check the route, header and template and tell you what to change.