OTP (One-Time Password)
Short answer: An OTP (one-time password) is a short code, usually 4 to 8 digits, that is valid for a single login or transaction and expires quickly. Apps send OTPs by SMS, voice call, email or an authenticator app to prove you control a phone number or device.
OTPs are the codes you type after entering a phone number on WhatsApp, Telegram or a bank site. Because each code works once, a stolen code is useless after it has been used or has expired.
How it works
The service generates a random code or derives one from a shared secret and the current time (TOTP, RFC 6238) or a counter (HOTP, RFC 4226). It stores the expected value, sends the code to you, and accepts it only once within a short window, often a few minutes.
SMS and voice OTPs are tied to a phone number, so the number must be able to receive texts or calls from the sending service.
OTP types and delivery
| Type | How the code is made or delivered |
|---|---|
| TOTP (RFC 6238) | Derived from a shared secret and the current time |
| HOTP (RFC 4226) | Derived from a shared secret and a counter |
| SMS OTP | Texted to your phone number |
| Voice OTP | Read out in a call to your phone number |
How it applies to ZuteSIP
Every ZuteSIP number receives unlimited incoming SMS and unlimited incoming calls, and codes appear in the SMS inbox in your dashboard. Numbers work with WhatsApp, Telegram, Google, Facebook and thousands more. If an app does not accept a number or codes don't arrive, the 7-day replacement guarantee gives you a free new number in the same country.
Related terms
- Two-factor authentication (2FA)
- SMS verification
- Non-VoIP number
- Mobile number
Frequently asked questions
How long is an OTP valid?
It depends on the service; most expire within a few minutes and all stop working after one use.
Is an SMS OTP the same as 2FA?
An SMS OTP is one way to deliver the second factor in two-factor authentication, but 2FA can also use authenticator apps or security keys.
Can I receive OTPs on a ZuteSIP number?
Yes. Incoming SMS is unlimited and shown in your dashboard inbox, and the 7-day replacement guarantee covers numbers an app won't accept.
Related pages
- two-factor authentication
- SMS verification
- non-VoIP numbers
- verification code not received
- real numbers vs free SMS sites
- WhatsApp use case
- Number Porting
- PBX (Private Branch Exchange)
Sources
- IETF: RFC 6238, TOTP: Time-Based One-Time Password Algorithm (as of September 2026)
- IETF: RFC 4226, HOTP: An HMAC-Based One-Time Password Algorithm (as of September 2026)