OTP (One-Time Password)

What is an OTP?

An OTP (One-Time Password) is a short code, valid once and for a limited time, sent to or generated on something the user controls — most commonly a mobile number by SMS, but also email, an authenticator app or a voice call. Returning the code correctly demonstrates possession of that channel at that moment.

In verification flows OTP does one specific job well: it proves that the person filling in the form can receive messages at the number they supplied. That is a genuine and valuable check, and it is routinely over-interpreted as something stronger.

Where OTP verification is used

What an OTP does not prove

It does not prove identity. It proves channel control, and only at the instant of the check. The gap between the two is where most OTP-related fraud lives: numbers registered on documents belonging to someone else, codes handed over to a caller impersonating a bank, malware or forwarding rules intercepting messages, and SIM swaps moving a number to an attacker’s device.

Because of this, an OTP should be treated as one signal among several. It pairs naturally with checks that reach an independent record — a bank account in the same name, an employment record, a document signed by its issuer.

Operational details that matter in India

Related terms

Verify it with Veriqos

Send and verify codes without building telecom plumbing yourself:

See how these checks are applied in Fintech & Digital Lending, E-commerce & Marketplaces.

← Back to the verification glossary