{"id":117,"date":"2026-05-26T21:44:50","date_gmt":"2026-05-26T21:44:50","guid":{"rendered":"https:\/\/sms.es\/?page_id=117"},"modified":"2026-06-11T16:37:41","modified_gmt":"2026-06-11T16:37:41","slug":"otp-2fa","status":"publish","type":"page","link":"https:\/\/sms.es\/en\/soluciones\/otp-2fa\/","title":{"rendered":"OTP 2FA"},"content":{"rendered":"<section class=\"sms-use-otp\" id=\"sms-use-otp-page\">\n  <section class=\"otp-hero\" aria-labelledby=\"otp-main-title\">\n    <div class=\"otp-wrap otp-hero-grid\">\n      <div class=\"otp-hero-copy\">\n        <div class=\"otp-kicker\"><span class=\"otp-kicker-dot\"><\/span> OTP \/ 2FA API<\/div>\n        <h1 id=\"otp-main-title\">OTP SMS and authentication 2FA API for <span>banking, fintech, apps, and health<\/span><\/h1>\n        <p class=\"otp-hero-text\">Integrates SMS OTP and authentication 2FA on your systems using APIS. Send verification codes by SMS from flows of login, user registration, account recovery, or sensitive actions.<\/p>\n        <div class=\"otp-btns\">\n          <a class=\"otp-btn otp-btn-primary\" href=\"https:\/\/developers.sms.es\/docs\/sms-https-api\/\">See API documentation<\/a>\n          <a class=\"otp-btn otp-btn-secondary\" href=\"\/en\/contacto\/\">To speak with a specialist<\/a>\n        <\/div>\n        <div class=\"otp-hero-note\">Integrates SMS OTP and authentication 2FA on your systems using APIS.<\/div>\n        <div class=\"otp-hero-links\" aria-label=\"Related links\">\n          <a class=\"otp-mini-link\" href=\"\/en\/api-sms\/\">API SMS<\/a>\n          <a class=\"otp-mini-link\" href=\"\/en\/precios\/\">Prices<\/a>\n          <a class=\"otp-mini-link\" href=\"\/en\/plataforma-omnicanal\/\">Platform CPaaS<\/a>\n        <\/div>\n      <\/div>\n      <div class=\"otp-hero-media\" aria-label=\"Verification OTP SMS using API\">\n        <div class=\"otp-hero-card\">\n          <img fetchpriority=\"high\" src=\"\/wp-content\/uploads\/Casos-de-uso\/otp-2fa\/otp2fa1.webp\" alt=\"API SMS OTP para autenticaci\u00f3n de usuarios\" loading=\"eager\" decoding=\"async\" width=\"1200\" height=\"900\">\n          <div class=\"otp-hero-panel\" aria-label=\"Main uses of OTP SMS\">\n            <div class=\"otp-hero-pill\"><strong>Verification code SMS<\/strong><span>For actions in real time.<\/span><\/div>\n            <div class=\"otp-hero-pill\"><strong>Activation API<\/strong><span>From backend, app, or internal system.<\/span><\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/section>\n\n  <section class=\"otp-section\" aria-labelledby=\"otp-valor\">\n    <div class=\"otp-wrap\">\n      <div class=\"otp-head otp-head-center\">\n        <p class=\"otp-eyebrow\">Technical check<\/p>\n        <h2 class=\"otp-h2\" id=\"otp-valor\">SMS OTP for flows where the time and the identity imported<\/h2>\n        <p class=\"otp-lead\">A page for teams that need to enable SMS verification without converting the OTP in a campaign manual.<\/p>\n      <\/div>\n      <div class=\"otp-grid otp-value-grid\">\n        <article class=\"otp-card otp-value-card\"><div class=\"otp-icon\" aria-hidden=\"true\"><svg viewbox=\"0 0 24 24\"><path d=\"M20 21v-2a4 4 0 0 0-4-4H8a4 4 0 0 0-4 4v2\"><\/path><circle cx=\"12\" cy=\"7\" r=\"4\"><\/circle><\/svg><\/div><h3>Verification of users<\/h3><p>Sends a verification code by SMS when a person registers, confirms or recovers access.<\/p><\/article>\n        <article class=\"otp-card otp-value-card\"><div class=\"otp-icon\" aria-hidden=\"true\"><svg viewbox=\"0 0 24 24\"><rect x=\"4\" y=\"11\" width=\"16\" height=\"10\" rx=\"2\"><\/rect><path d=\"M8 11V7a4 4 0 0 1 8 0v4\"><\/path><path d=\"M12 15v2\"><\/path><\/svg><\/div><h3>Authentication 2FA<\/h3><p>Adds an additional layer of checking on accesses or sensitive actions.<\/p><\/article>\n        <article class=\"otp-card otp-value-card\"><div class=\"otp-icon\" aria-hidden=\"true\"><svg viewbox=\"0 0 24 24\"><path d=\"M16 18l6-6-6-6\"><\/path><path d=\"M8 6l-6 6 6 6\"><\/path><path d=\"M14 4l-4 16\"><\/path><\/svg><\/div><h3>Activation API<\/h3><p>Your system is triggered by the real-time SMS from an app, web, backend or internal software.<\/p><\/article>\n        <article class=\"otp-card otp-value-card\"><div class=\"otp-icon\" aria-hidden=\"true\"><svg viewbox=\"0 0 24 24\"><path d=\"M12 22s8-4 8-10V5l-8-3-8 3v7c0 6 8 10 8 10Z\"><\/path><path d=\"M9 12l2 2 4-5\"><\/path><\/svg><\/div><h3>Critical cases of access<\/h3><p>Useful for validations of account, transactions, data changes or administrative access.<\/p><\/article>\n      <\/div>\n    <\/div>\n  <\/section>\n\n  <section class=\"otp-section otp-section-soft\" aria-labelledby=\"otp-sectores\">\n    <div class=\"otp-wrap\">\n      <div class=\"otp-head\">\n        <p class=\"otp-eyebrow\">By sector<\/p>\n        <h2 class=\"otp-h2\" id=\"otp-sectores\">Four sectors, the same logic: event, API, SMS, and validation<\/h2>\n        <p class=\"otp-lead\">The flow technician is similar, but change the time of use. That's why the message, the risk and the experience should be adapted to each environment.<\/p>\n      <\/div>\n      <div class=\"otp-tabs-shell\" data-otp-tabs=\"\">\n        <div class=\"otp-tabs-nav\" role=\"tablist\" aria-label=\"Sectors for OTP SMS and 2FA SMS\">\n          <button class=\"otp-tab-btn\" type=\"button\" role=\"tab\" aria-selected=\"true\" aria-controls=\"otp-panel-banca\" id=\"otp-tab-banca\">Banking<\/button>\n          <button class=\"otp-tab-btn\" type=\"button\" role=\"tab\" aria-selected=\"false\" aria-controls=\"otp-panel-fintech\" id=\"otp-tab-fintech\">Fintech<\/button>\n          <button class=\"otp-tab-btn\" type=\"button\" role=\"tab\" aria-selected=\"false\" aria-controls=\"otp-panel-apps\" id=\"otp-tab-apps\">Apps<\/button>\n          <button class=\"otp-tab-btn\" type=\"button\" role=\"tab\" aria-selected=\"false\" aria-controls=\"otp-panel-salud\" id=\"otp-tab-salud\">Health<\/button>\n        <\/div>\n        <div class=\"otp-tabs-panels\">\n          <article class=\"otp-sector-panel is-active\" id=\"otp-panel-banca\" role=\"tabpanel\" aria-labelledby=\"otp-tab-banca\">\n            <div class=\"otp-sector-copy\"><h3>Check for banking<\/h3><p>SMS OTP as the main channel for flow of access, validation, and confirmation is defined by the architecture of the entity.<\/p><div class=\"otp-sector-lists\"><div class=\"otp-list-box\"><h4>Use cases<\/h4><ul><li>Validation of access to online banking.<\/li><li>Confirmation of transactions initiated by the user.<\/li><li>Account recovery verification or phone.<\/li><\/ul><\/div><div class=\"otp-list-box\"><h4>Practical benefits<\/h4><ul><li>Activation from their own systems via the API.<\/li><li>Your message brief and direct to concrete actions.<\/li><\/ul><\/div><\/div><a class=\"otp-sector-link\" href=\"\/en\/contacto\/\">Consult banking integration<\/a><\/div>\n            <div class=\"otp-sector-image\"><img src=\"\/wp-content\/uploads\/Casos-de-uso\/otp-2fa\/otp2fa2.webp\" alt=\"SMS para banca con c\u00f3digos OTP y autenticaci\u00f3n 2FA\" loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"900\"><\/div>\n          <\/article>\n          <article class=\"otp-sector-panel\" id=\"otp-panel-fintech\" role=\"tabpanel\" aria-labelledby=\"otp-tab-fintech\">\n            <div class=\"otp-sector-copy\"><h3>Authentication for fintech<\/h3><p>SMS OTP as the main channel for validations fast on high, access, and sensitive actions within the flow-own product.<\/p><div class=\"otp-sector-lists\"><div class=\"otp-list-box\"><h4>Use cases<\/h4><ul><li>User registration and verification of your phone.<\/li><li>Identity verification within a flow of its own.<\/li><li>Confirmation of sensitive actions from the app.<\/li><\/ul><\/div><div class=\"otp-list-box\"><h4>Practical benefits<\/h4><ul><li>API integration-oriented digital product.<\/li><li>Use in specific moments of the path of the user.<\/li><\/ul><\/div><\/div><a class=\"otp-sector-link\" href=\"\/en\/contacto\/\">Prepare flow fintech<\/a><\/div>\n            <div class=\"otp-sector-image\"><img src=\"\/wp-content\/uploads\/Casos-de-uso\/otp-2fa\/otp2fa3.webp\" alt=\"SMS para fintech con verificaci\u00f3n por SMS y API OTP SMS\" loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"900\"><\/div>\n          <\/article>\n          <article class=\"otp-sector-panel\" id=\"otp-panel-apps\" role=\"tabpanel\" aria-labelledby=\"otp-tab-apps\">\n            <div class=\"otp-sector-copy\"><h3>Check for apps<\/h3><p>SMS OTP as the main channel to validate number, activate account, login, or retrieve access in apps and web platforms.<\/p><div class=\"otp-sector-lists\"><div class=\"otp-list-box\"><h4>Use cases<\/h4><ul><li>Login with a temporary code.<\/li><li>Check phone number.<\/li><li>Recovery password or account activation.<\/li><\/ul><\/div><div class=\"otp-list-box\"><h4>Practical benefits<\/h4><ul><li>Clear experience for end-users.<\/li><li>Auto-shot from the backend or app.<\/li><\/ul><\/div><\/div><a class=\"otp-sector-link\" href=\"\/en\/contacto\/\">Integrate OTP in one app<\/a><\/div>\n            <div class=\"otp-sector-image\"><img src=\"\/wp-content\/uploads\/Casos-de-uso\/otp-2fa\/otp2fa4.webp\" alt=\"SMS para apps con login por c\u00f3digo de verificaci\u00f3n SMS\" loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"900\"><\/div>\n          <\/article>\n          <article class=\"otp-sector-panel\" id=\"otp-panel-salud\" role=\"tabpanel\" aria-labelledby=\"otp-tab-salud\">\n            <div class=\"otp-sector-copy\"><h3>Secure access to health<\/h3><p>SMS OTP as the main channel for validations administrative, access to portals and confirmations without including confidential medical data.<\/p><div class=\"otp-sector-lists\"><div class=\"otp-list-box\"><h4>Use cases<\/h4><ul><li>Access to the portal of the patient.<\/li><li>Confirmation administrative user.<\/li><li>Check the phone systems of appointment or attention.<\/li><\/ul><\/div><div class=\"otp-list-box\"><h4>Practical benefits<\/h4><ul><li>Brief messages without medical information is sensitive.<\/li><li>Integration with internal software or web portal.<\/li><\/ul><\/div><\/div><a class=\"otp-sector-link\" href=\"\/en\/contacto\/\">Consulting case of health<\/a><\/div>\n            <div class=\"otp-sector-image\"><img src=\"\/wp-content\/uploads\/Casos-de-uso\/otp-2fa\/otp2fa5.webp\" alt=\"SMS para salud con verificaci\u00f3n de usuario y acceso a portal\" loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"900\"><\/div>\n          <\/article>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/section>\n\n  <section class=\"otp-section\" aria-labelledby=\"otp-api\">\n    <div class=\"otp-wrap otp-api-grid\">\n      <div class=\"otp-api-visual\" aria-label=\"API integration OTP SMS\">\n        <img src=\"\/wp-content\/uploads\/Casos-de-uso\/otp-2fa\/otp2fa6.webp\" alt=\"Integraci\u00f3n API SMS para OTP y autenticaci\u00f3n 2FA\" loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"900\">\n        <div class=\"otp-code-card\"><div class=\"otp-code-row\"><span>Main channel<\/span><strong>SMS API<\/strong><\/div><div class=\"otp-code-row\"><span>Activator<\/span><strong>Event in your system<\/strong><\/div><div class=\"otp-code-row\"><span>Validation<\/span><strong>Client architecture<\/strong><\/div><\/div>\n      <\/div>\n      <div>\n        <div class=\"otp-head\"><p class=\"otp-eyebrow\">How it works API<\/p><h2 class=\"otp-h2\" id=\"otp-api\">From a user action to a SMS OTP sent automatically<\/h2><p class=\"otp-lead\">SMS.es acts as a way of sending SMS. The generation, revocation, control attempts, and validation of the code depend on the client system.<\/p><\/div>\n        <div class=\"otp-step-list\">\n          <article class=\"otp-api-step\"><span class=\"otp-step-num\">1<\/span><div><h3>The user initiates an action<\/h3><p>Login, high, account recovery, operation of or access to a portal.<\/p><\/div><\/article>\n          <article class=\"otp-api-step\"><span class=\"otp-step-num\">2<\/span><div><h3>Your system generates or request the code<\/h3><p>The backend logic is defined by the OTP, your expiration and validation rules.<\/p><\/div><\/article>\n          <article class=\"otp-api-step\"><span class=\"otp-step-num\">3<\/span><div><h3>Your backend calling the API SMS SMS.es<\/h3><p>The message is sent over HTTP\/HTTPS with the text and the recipient-defined for your system.<\/p><\/div><\/article>\n          <article class=\"otp-api-step\"><span class=\"otp-step-num\">4<\/span><div><h3>The user receives the SMS OTP<\/h3><p>The code you reach the number indicated to continue the flow of verification.<\/p><\/div><\/article>\n          <article class=\"otp-api-step\"><span class=\"otp-step-num\">5<\/span><div><h3>Your system validates the code<\/h3><p>The final decision to accept, reject, or ask for a new attempt is managed on your platform.<\/p><\/div><\/article>\n        <\/div>\n        <div class=\"otp-btns\"><a class=\"otp-btn otp-btn-primary\" href=\"https:\/\/developers.sms.es\/docs\/sms-https-api\/\">See API documentation<\/a><a class=\"otp-btn otp-btn-secondary\" href=\"\/en\/api-sms\/\">Knowing API SMS<\/a><\/div>\n      <\/div>\n    <\/div>\n  <\/section>\n\n  <section class=\"otp-section otp-section-soft\" aria-labelledby=\"otp-flujo\">\n    <div class=\"otp-wrap\"><div class=\"otp-head otp-head-center\"><p class=\"otp-eyebrow\">Flow technical<\/p><h2 class=\"otp-h2\" id=\"otp-flujo\">A simple flow for authentication SMS<\/h2><p class=\"otp-lead\">The integration should be clear to the technical team and transparent to the end user.<\/p><\/div><div class=\"otp-tech-flow\" aria-label=\"Flow technical OTP SMS\"><div class=\"otp-flow-node\">App or system<\/div><div class=\"otp-flow-arrow\">\u2192<\/div><div class=\"otp-flow-node\">API SMS.es<\/div><div class=\"otp-flow-arrow\">\u2192<\/div><div class=\"otp-flow-node\">SMS OTP<\/div><div class=\"otp-flow-arrow\">\u2192<\/div><div class=\"otp-flow-node\">User<\/div><div class=\"otp-flow-arrow\">\u2192<\/div><div class=\"otp-flow-node\">Validation in your system<\/div><\/div><\/div>\n  <\/section>\n\n  <section class=\"otp-section\" aria-labelledby=\"otp-canales\">\n    <div class=\"otp-wrap otp-scope-grid\"><div class=\"otp-scope-main\"><p class=\"otp-eyebrow\">Channels and scope<\/p><h2 class=\"otp-h2\" id=\"otp-canales\">The focus of this page is SMS OTP API<\/h2><p>SMS.es is part of a platform CPaaS more broad, but in OTP\/2FA the main channel of this page is the SMS that is sent from the client systems via the API. Other channels can complement communications service according to use case, permissions, and availability, but should not be confused with the flow of OTP SMS.<\/p><\/div><div class=\"otp-scope-list\"><div class=\"otp-scope-item\"><strong>SMS<\/strong><span>Main channel for verification code SMS and authentication SMS API.<\/span><\/div><div class=\"otp-scope-item\"><strong>WhatsApp or Telegram<\/strong><span>Can be part of communications complementary if the case permits.<\/span><\/div><div class=\"otp-scope-item\"><strong>Platform CPaaS<\/strong><span>General context of SMS.it is, without presenting the OTP as the campaign manual.<\/span><\/div><\/div><\/div>\n  <\/section>\n\n  <section class=\"otp-section otp-section-soft\" aria-labelledby=\"otp-acciones\">\n    <div class=\"otp-wrap\"><div class=\"otp-head\"><p class=\"otp-eyebrow\">For frequent actions<\/p><h2 class=\"otp-h2\" id=\"otp-acciones\">Moments where it can be activated an SMS OTP<\/h2><p class=\"otp-lead\">Each card represents a trigger technical usual. The level of security will depend on the complete design of the flow.<\/p><\/div><div class=\"otp-carousel\" aria-label=\"Actions that may require OTP SMS\"><div class=\"otp-actions-track\">\n      <article class=\"otp-action-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83d\udd10<\/span>Login<\/strong><span>Apps \u00b7 Banking<\/span><p>Temporary code to validate the access in a controlled flow.<\/p><\/article>\n      <article class=\"otp-action-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83c\udd95<\/span>Account<\/strong><span>Fintech \u00b7 Apps<\/span><p>Number verification for user registration.<\/p><\/article>\n      <article class=\"otp-action-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83d\udd11<\/span>Password recovery<\/strong><span>Apps \u00b7 Companies<\/span><p>Additional validation before allowing the change of credentials.<\/p><\/article>\n      <article class=\"otp-action-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\u2705<\/span>Confirmation of operation<\/strong><span>Banking \u00b7 Fintech<\/span><p>Prior check in actions initiated by the user.<\/p><\/article>\n      <article class=\"otp-action-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83d\udcf2<\/span>Check phone<\/strong><span>Apps \u00b7 Health<\/span><p>Confirmation that the number belongs to the registered user.<\/p><\/article>\n      <article class=\"otp-action-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83d\udcdd<\/span>Change of data<\/strong><span>Fintech \u00b7 Banking<\/span><p>Validation before you modify important information of account.<\/p><\/article>\n      <article class=\"otp-action-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83c\udfe5<\/span>Access to portal<\/strong><span>Health Services \u00b7<\/span><p>Access code for portals administrative or private areas.<\/p><\/article>\n      <article class=\"otp-action-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\u26a0\ufe0f<\/span>Action sensitive<\/strong><span>Internal systems<\/span><p>Additional check in flows with higher operative risk.<\/p><\/article>\n      <article class=\"otp-action-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83d\udd10<\/span>Login<\/strong><span>Apps \u00b7 Banking<\/span><p>Temporary code to validate the access in a controlled flow.<\/p><\/article>\n      <article class=\"otp-action-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83c\udd95<\/span>Account<\/strong><span>Fintech \u00b7 Apps<\/span><p>Number verification for user registration.<\/p><\/article>\n      <article class=\"otp-action-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83d\udd11<\/span>Password recovery<\/strong><span>Apps \u00b7 Companies<\/span><p>Additional validation before allowing the change of credentials.<\/p><\/article>\n      <article class=\"otp-action-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\u2705<\/span>Confirmation of operation<\/strong><span>Banking \u00b7 Fintech<\/span><p>Prior check in actions initiated by the user.<\/p><\/article>\n    <\/div><\/div><\/div>\n  <\/section>\n\n  <section class=\"otp-dark\" aria-labelledby=\"otp-seguridad\">\n    <div class=\"otp-wrap otp-dark-grid\"><div><p class=\"otp-eyebrow\">Security practice<\/p><h2 class=\"otp-h2\" id=\"otp-seguridad\">OTP by SMS for help, but does not replace, a secure architecture<\/h2><p class=\"otp-lead\">The SMS OTP can add a layer of verification. The final security depends on how the client to design your authentication, validation, control attempts, expiration, and risk management.<\/p><div class=\"otp-btns\"><a class=\"otp-btn otp-btn-dark\" href=\"\/en\/contacto\/\">To speak with a technical team<\/a><\/div><\/div><div class=\"otp-dark-points\"><div class=\"otp-dark-point\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\u23f1\ufe0f<\/span>Code expiration<\/strong><span>Defines from your system-how long it will be valid each code is OTP.<\/span><\/div><div class=\"otp-dark-point\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83d\udea6<\/span>Control attempts<\/strong><span>Limited retries and bevel gearboxes to reduce abuse and friction.<\/span><\/div><div class=\"otp-dark-point\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83e\udde9<\/span>Internal validation<\/strong><span>The acceptance of the code must be resolved in your backend or platform.<\/span><\/div><div class=\"otp-dark-point\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83d\udee1\ufe0f<\/span>Messages prudent<\/strong><span>Please do not include any sensitive data or unnecessary information in the SMS.<\/span><\/div><\/div><\/div>\n  <\/section>\n\n  <section class=\"otp-section\" aria-labelledby=\"otp-equipo\">\n    <div class=\"otp-wrap\"><div class=\"otp-head otp-head-center\"><p class=\"otp-eyebrow\">Integration and technical team<\/p><h2 class=\"otp-h2\" id=\"otp-equipo\">Designed for development teams, integrators, and enterprises with their own systems<\/h2><p class=\"otp-lead\">OTP\/2FA by SMS fits when the shipment must be triggered from an action in real time, not from the campaign manual.<\/p><\/div><div class=\"otp-dev-grid\">\n      <article class=\"otp-dev-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83d\udda5\ufe0f<\/span>Backend own<\/strong><span>Send SMS OTP from internal services, microservicios platforms or corporate.<\/span><\/article>\n      <article class=\"otp-dev-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83d\udcf1<\/span>Mobile App<\/strong><span>Active codes in registration, login or account recovery.<\/span><\/article>\n      <article class=\"otp-dev-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83c\udf10<\/span>Web platform<\/strong><span>Validates users, changes or access to private areas.<\/span><\/article>\n      <article class=\"otp-dev-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83c\udfe6<\/span>Financial system<\/strong><span>Integrates authentication SMS in flows defined by your institution.<\/span><\/article>\n      <article class=\"otp-dev-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83c\udfe5<\/span>Portal of patients<\/strong><span>Uses short message for validations administrative without sensitive data.<\/span><\/article>\n      <article class=\"otp-dev-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\u2699\ufe0f<\/span>Internal Software<\/strong><span>Added check in operational processes or accesses corporate.<\/span><\/article>\n    <\/div><div class=\"otp-btns otp-center-btns\"><a class=\"otp-btn otp-btn-primary\" href=\"https:\/\/developers.sms.es\/docs\/sms-https-api\/\">See API documentation<\/a><a class=\"otp-btn otp-btn-secondary\" href=\"\/en\/contacto\/\">Request technical contact<\/a><\/div><\/div>\n  <\/section>\n\n  <section class=\"otp-section otp-section-soft\" aria-labelledby=\"otp-comparativa\">\n    <div class=\"otp-wrap\"><div class=\"otp-head\"><p class=\"otp-eyebrow\">Choosing the right service<\/p><h2 class=\"otp-h2\" id=\"otp-comparativa\">Not all sending SMS has the same logic<\/h2><p class=\"otp-lead\">This page is for OTP\/2FA. If your need is another, SMS.es has different services for campaigns, certification, conversation management or omnicanal.<\/p><\/div><div class=\"otp-compare-grid\">\n      <article class=\"otp-compare-card is-featured\"><small>OTP \/ 2FA<\/small><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83d\udd10<\/span>API SMS<\/strong><p>Verification codes activated from systems, apps or backend.<\/p><a href=\"\/en\/api-sms\/\">See API SMS<\/a><\/article>\n      <article class=\"otp-compare-card\"><small>Campaigns<\/small><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83d\udce3<\/span>SMS bulk<\/strong><p>Shipments to commercial or informational hearings authorized.<\/p><a href=\"\/en\/sms-masivo\/\">See SMS mass<\/a><\/article>\n      <article class=\"otp-compare-card\"><small>Legal test<\/small><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83d\udcc4<\/span>SMS certificate<\/strong><p>Communications with associated certificate when the case requires it.<\/p><a href=\"\/en\/sms-certificado\/\">See SMS certificate<\/a><\/article>\n      <article class=\"otp-compare-card\"><small>Conversation<\/small><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83d\udcac<\/span>SMS two-way<\/strong><p>Flows where the user can reply to or initiate interaction.<\/p><a href=\"\/en\/sms-bidireccional\/\">See SMS two-way<\/a><\/article>\n      <article class=\"otp-compare-card\"><small>Visual management<\/small><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83e\udded<\/span>Platform omnicanal<\/strong><p>Campaigns, contacts, and communications management, not OTP manual.<\/p><a href=\"\/en\/plataforma-omnicanal\/\">See platform<\/a><\/article>\n    <\/div><\/div>\n  <\/section>\n\n  <section class=\"otp-section\" aria-labelledby=\"otp-buenas-practicas\">\n    <div class=\"otp-wrap\"><div class=\"otp-head otp-head-center\"><p class=\"otp-eyebrow\">Good practices<\/p><h2 class=\"otp-h2\" id=\"otp-buenas-practicas\">Recommendations for a flow OTP more clear<\/h2><p class=\"otp-lead\">These guidelines are not a substitute for a safety review, but help you to better design the use of authentication SMS.<\/p><\/div><div class=\"otp-practice-grid\">\n      <article class=\"otp-practice-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83d\ude48<\/span>Please do not include any sensitive data<\/strong><span>The SMS should contain only what is necessary to verify the action.<\/span><\/article>\n      <article class=\"otp-practice-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\u23f3<\/span>Defined expiry<\/strong><span>The code must have a window use limited in your system.<\/span><\/article>\n      <article class=\"otp-practice-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83d\udea6<\/span>Control attempts<\/strong><span>Manages retries, locks and forwards from your backend.<\/span><\/article>\n      <article class=\"otp-practice-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\u2709\ufe0f<\/span>Use clear messages<\/strong><span>Indicates the code and the context without adding unnecessary friction.<\/span><\/article>\n      <article class=\"otp-practice-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83d\udcca<\/span>Keep traceability<\/strong><span>Records relevant events in your internal systems.<\/span><\/article>\n      <article class=\"otp-practice-card\"><strong><span class=\"otp-card-emoji\" aria-hidden=\"true\">\ud83e\uddea<\/span>Test before production<\/strong><span>Validates the full flow with real-life scenarios and possible errors.<\/span><\/article>\n    <\/div><\/div>\n  <\/section>\n\n  <section class=\"otp-section otp-section-soft\" aria-labelledby=\"otp-faq\">\n    <div class=\"otp-wrap\"><div class=\"otp-head otp-head-center\"><p class=\"otp-eyebrow\">Frequently asked questions<\/p><h2 class=\"otp-h2\" id=\"otp-faq\">FAQ about OTP SMS, 2FA SMS and SMS verification<\/h2><\/div><div class=\"otp-faq-list\" data-otp-faq=\"\">\n      <article class=\"otp-faq-item is-open\"><button class=\"otp-faq-question\" type=\"button\" aria-expanded=\"true\">What is a SMS OTP?<\/button><div class=\"otp-faq-answer\"><p>A SMS OTP is a message with a code of a single-use, which is used to verify an action, an access or a phone number within a digital stream.<\/p><\/div><\/article>\n      <article class=\"otp-faq-item\"><button class=\"otp-faq-question\" type=\"button\" aria-expanded=\"false\">What is 2FA by SMS?<\/button><div class=\"otp-faq-answer\"><p>2FA via SMS is the use of a code sent by SMS as a second layer of verification, in addition to other factor such as password, or session started.<\/p><\/div><\/article>\n      <article class=\"otp-faq-item\"><button class=\"otp-faq-question\" type=\"button\" aria-expanded=\"false\">Can I send OTP from the visual platform?<\/button><div class=\"otp-faq-answer\"><p>The flows OTP\/2FA are designed to be integrated via the API, as they usually rely on real-time actions within an app, web, or internal system.<\/p><\/div><\/article>\n      <article class=\"otp-faq-item\"><button class=\"otp-faq-question\" type=\"button\" aria-expanded=\"false\">How do you integrate OTP by API?<\/button><div class=\"otp-faq-answer\"><p>Your backend generates or manages the code and call the API SMS to send the message to the number of the user. You can review the <a href=\"https:\/\/developers.sms.es\/docs\/sms-https-api\/\">documentation of the API SMS<\/a>.<\/p><\/div><\/article>\n      <article class=\"otp-faq-item\"><button class=\"otp-faq-question\" type=\"button\" aria-expanded=\"false\">Who generates and validates the code OTP?<\/button><div class=\"otp-faq-answer\"><p>The generation, revocation, control attempts, and validation of the code depend on the client system. SMS.es is responsible for sending SMS using API.<\/p><\/div><\/article>\n      <article class=\"otp-faq-item\"><button class=\"otp-faq-question\" type=\"button\" aria-expanded=\"false\">What SMS OTP serves to banking or fintech?<\/button><div class=\"otp-faq-answer\"><p>Yes, you can be a part of flows of authentication, confirmation or verification defined by banks and fintech. The final configuration should match the architecture and requirements of each entity.<\/p><\/div><\/article>\n      <article class=\"otp-faq-item\"><button class=\"otp-faq-question\" type=\"button\" aria-expanded=\"false\">Can I use OTP SMS in one app?<\/button><div class=\"otp-faq-answer\"><p>Yes. It is common to use SMS OTP for login, check telephone, account activation or recovery password in apps and web platforms.<\/p><\/div><\/article>\n      <article class=\"otp-faq-item\"><button class=\"otp-faq-question\" type=\"button\" aria-expanded=\"false\">Can I use OTP SMS in health?<\/button><div class=\"otp-faq-answer\"><p>Yes, in validations or administrative access to portals, always avoid include medical information is sensitive in the content of the SMS.<\/p><\/div><\/article>\n      <article class=\"otp-faq-item\"><button class=\"otp-faq-question\" type=\"button\" aria-expanded=\"false\">Where is the API documentation?<\/button><div class=\"otp-faq-answer\"><p>Technical documentation is available at <a href=\"https:\/\/developers.sms.es\/docs\/sms-https-api\/\">developers.sms.es\/docs\/sms-https-api\/<\/a>.<\/p><\/div><\/article>\n      <article class=\"otp-faq-item\"><button class=\"otp-faq-question\" type=\"button\" aria-expanded=\"false\">What is the difference between OTP, SMS and mass SMS certificate?<\/button><div class=\"otp-faq-answer\"><p>OTP is integrated by API for codes in real-time. SMS mass is used for campaigns and communications to audiences. SMS certificate is used when it is required for a certificate associated with the communication.<\/p><\/div><\/article>\n      <article class=\"otp-faq-item\"><button class=\"otp-faq-question\" type=\"button\" aria-expanded=\"false\">How do I request technical help?<\/button><div class=\"otp-faq-answer\"><p>You can contact with SMS.es is from the page <a href=\"\/en\/contacto\/\">contact<\/a> to review your use case, technical scope and business needs.<\/p><\/div><\/article>\n    <\/div><\/div>\n  <\/section>\n\n  <section class=\"otp-final\" aria-labelledby=\"otp-final-title\">\n    <div class=\"otp-wrap\"><div class=\"otp-final-card\"><div><h2 id=\"otp-final-title\">Integrates SMS OTP in your flows authentication with an API written for companies<\/h2><p>Active SMS verification for banking, fintech, apps, and health from your own systems, with technical and commercial support of SMS.is.<\/p><\/div><div class=\"otp-btns\"><a class=\"otp-btn otp-btn-primary\" href=\"https:\/\/developers.sms.es\/docs\/sms-https-api\/\">See API documentation<\/a><a class=\"otp-btn otp-btn-dark\" href=\"\/en\/contacto\/\">To speak with a specialist<\/a><\/div><\/div><\/div>\n  <\/section>\n<\/section>","protected":false},"excerpt":{"rendered":"<p>OTP \/ 2FA por API OTP SMS y autenticaci\u00f3n 2FA por API para banca, fintech, apps y salud Integra SMS OTP y autenticaci\u00f3n 2FA en tus sistemas mediante API. Env\u00eda c\u00f3digos de verificaci\u00f3n por SMS desde flujos de login, alta de usuario, recuperaci\u00f3n de cuenta o acciones sensibles. Ver documentaci\u00f3n API Hablar con un especialista&#8230;<\/p>","protected":false},"author":1,"featured_media":0,"parent":99,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_kadence_starter_templates_imported_post":false,"_kad_post_transparent":"disable","_kad_post_title":"hide","_kad_post_layout":"fullwidth","_kad_post_sidebar_id":"","_kad_post_content_style":"unboxed","_kad_post_vertical_padding":"hide","_kad_post_feature":"hide","_kad_post_feature_position":"","_kad_post_header":true,"_kad_post_footer":false,"_kad_post_classname":"","footnotes":""},"class_list":["post-117","page","type-page","status-publish","hentry"],"_hostinger_reach_plugin_has_subscription_block":false,"_hostinger_reach_plugin_is_elementor":false,"_links":{"self":[{"href":"https:\/\/sms.es\/en\/wp-json\/wp\/v2\/pages\/117","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sms.es\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sms.es\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sms.es\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sms.es\/en\/wp-json\/wp\/v2\/comments?post=117"}],"version-history":[{"count":2,"href":"https:\/\/sms.es\/en\/wp-json\/wp\/v2\/pages\/117\/revisions"}],"predecessor-version":[{"id":237,"href":"https:\/\/sms.es\/en\/wp-json\/wp\/v2\/pages\/117\/revisions\/237"}],"up":[{"embeddable":true,"href":"https:\/\/sms.es\/en\/wp-json\/wp\/v2\/pages\/99"}],"wp:attachment":[{"href":"https:\/\/sms.es\/en\/wp-json\/wp\/v2\/media?parent=117"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}