Prompt
What should I use for sending OTPs and login codes?
Latest observation
Oct 5, 2026
OpenAI APIWeb search: off
For OTPs and login codes, the best option depends on your product, region, and security needs—but in general:
Best practice
- For highest security: use authenticator apps or passkeys instead of SMS OTPs.
- If you need email-based codes: use email OTPs for lower-friction verification, but not for high-risk actions.
- If you need phone-based OTPs: use SMS only when necessary, and preferably as a backup.
Recommended delivery channels
-
Passkeys / WebAuthn
- Best modern login method
- Phishing-resistant
- No code delivery needed
-
Authenticator apps
- Good security
- No network delivery delays
- Example: Google Authenticator, Microsoft Authenticator, Authy
-
Email codes
- Easy to implement
- Works well for account verification and low-risk login flows
- Less secure than authenticator apps/passkeys
-
SMS codes
- Widely supported
- Convenient, but weakest of the common OTP options
- Vulnerable to SIM swap, interception, and delivery issues
If you mean which service/provider to use
Common OTP delivery providers include:
- Twilio
- Vonage
- MessageBird
- AWS SNS / Pinpoint
- Firebase Authentication for mobile-focused apps
Practical recommendation
- If you’re building a new system: use passkeys + authenticator apps, with email or SMS OTP as fallback.
- If you just need a simple login code flow: email OTP is often easiest.
- If you must use phone OTPs at scale: Twilio or AWS Pinpoint/SNS are common choices.
If you want, I can recommend the best OTP solution for your exact use case (web app, mobile app, banking, SaaS, etc.).