Intelligent communication flow across multiple channels

Explore
Back to Use Cases
Security & Authentication

OTP, Authentication & Verification

Verify phone numbers, authenticate users and confirm sensitive actions.

OTPAuthenticationSecurity

Authentication messages sit inside critical product flows. A user may be signing up, logging in, recovering access or confirming an important action. The communication should be generated by the application at the exact point where verification is required.

A customer is trying to create an account.

They enter their phone number, tap Continue, and are waiting for the verification code.

A few seconds later:

Sender: AbcBank

Your AbcBank verification code is 482731. It expires in 10 minutes. Do not share this code.

The customer enters the code and continues.

That simple interaction sits behind a large number of digital services.

From customer action to verified account

The process typically looks like this:

Sign up / Login / Account action
↓
Application requests OTP
↓
Emisri sends SMS
↓
Customer enters code
↓
Application verifies code
↓
Customer continues

The important part is that the SMS is generated because something happened in the application.

Where OTP SMS is used

A fintech application might use it when a customer signs in from a new device.

Sender: PayFlow

Your PayFlow login code is 739214. It expires in 5 minutes. Do not share this code.

An online store may use it to verify a phone number during registration.

Sender: SwiftCart

Your SwiftCart verification code is 391624. Enter it to verify your phone number.

A customer resetting a password might receive:

Sender: FlowDesk

Your FlowDesk password reset code is 815302. It expires in 10 minutes.

The exact wording changes, but the purpose remains the same: deliver the code clearly so the customer can complete the action.

OTP is different from ordinary SMS

Authentication messages are part of a critical product flow.

That means the application needs to be able to:

  • Request an OTP when required
  • Insert the generated code into the message
  • Send from the appropriate sender
  • Handle expiry
  • Allow verification
  • Deal with failed or delayed delivery
  • Prevent unnecessary repeat messages

Emisri's SMS API can connect the application's authentication event to SMS delivery.

Keep the message focused

An OTP message should not compete with the action the customer is trying to complete.

The customer needs to immediately understand:

  1. What is this code for?
    What is the code?
    How long is it valid?
    Should I keep it private?

For sensitive authentication flows, businesses should also follow their own security requirements and avoid putting unnecessary account information into the SMS.

Common applications

01.

Account registration

02.

Login verification

03.

Password recovery

04.

Phone verification

05.

New-device verification

06.

Sensitive account actions