Authentication resource

One-Time Passcode (OTP) Templates

Use a short, clear message to deliver a code for one specific verification or sign-in step. These examples cover email and SMS wording; your application remains responsible for generating and validating the code.

Message preview

A useful OTP message names the action, gives the code, and explains its expiry. Keep security instructions easy to notice.

Subject: Your {app_name} verification code Hello {name}, Your code to verify your sign-in is {otp}. It expires in {minutes} minutes. Do not share this code with anyone. If you did not request this code, you can ignore this message. {company_name}

Features and use cases

The example has a clear purpose, a replaceable code and expiry value, a recognizable product name, and a safe instruction for an unexpected request. Use it for account verification, a sign-in challenge, or another short-lived confirmation. For a low-connectivity or accessible flow, consider offering a second delivery channel or a way to request a new code without making the message ambiguous.

Email provides room for context and recovery instructions. SMS suits brief, time-sensitive delivery when the recipient has agreed to receive it. Keep the same purpose and expiry behavior across channels.

Customize the placeholders

Replace {app_name}, {name}, {otp}, {minutes}, and {company_name} with values from your application. Use a safe fallback when a name is missing, localize the expiry wording, and preview long names or product names before shipping.

This is message copy, not an OTP implementation. Generate codes with a secure server-side process, bind them to the intended action, expire and invalidate them after use, and rate-limit requests and verification attempts. Never put a real code in source control or analytics logs.

Technology and how to use it

Choose an email or SMS sample from the email template library or SMS library. Copy the text into the template field of your mail or messaging provider, then have your backend substitute approved values at send time. There is no package to install and the page does not send messages.

Send only after the server creates the challenge. Align the text expiry with the actual validation expiry, and test delivery, resend, expired-code, and repeated-attempt flows in a staging account.

Accessibility, license, and limitations

Keep the code as selectable text, use readable contrast, and do not communicate validity through color alone. For HTML email, provide a plain-text alternative and check the result with images disabled and at narrow widths. This text preview is not a screenshot of a specific mail client.

No separate license is displayed for this sample. Review the Terms of Use and any resource-specific terms before reuse or redistribution. These samples are not a security certification or delivery guarantee.