OTP SMS (One-Time Password) is the backbone of digital authentication in India - used for login, payments, KYC, and account recovery. This guide covers compliance, routing, and integration best practices.
DLT Requirements for OTP
Every OTP message in India must be sent through a DLT-registered transactional template with an approved sender ID (header). Promotional templates cannot be used for OTP.
- Register your business entity on the DLT portal
- Apply for a transactional sender ID (e.g. SMSTKE) - approved by the operator's DLT platform
- Register OTP template with variable placeholder for the code
- Map template to your SMS provider (SMSTAKE)
OTP Message Best Practices
- Keep OTP length 4 - 6 digits; expire within 5 - 10 minutes
- Include brand name and purpose in template text
- Use secure fallback channels for high-risk verification flows
- Rate-limit resend requests per phone number
- Use webhooks to confirm delivery before showing errors
API Integration Example
An illustrative request with your DLT template ID (the exact endpoint and field names are in the API documentation shared during onboarding):
POST /v1/messages/send
{
"to": "+919876543210",
"channel": "sms",
"sender": "SMSTKE",
"message": "Your OTP is 482910. Valid 5 min. - SMSTAKE",
"dlt_template_id": "1207165123456789012"
}
OTP Delivery Performance
Choose a provider with priority transactional routes and direct operator connectivity. SMSTAKE routes OTP traffic on priority transactional routes across Jio, Airtel, Vi, and BSNL, with real-time delivery reports.
Fallback option: Voice OTP when SMS delivery fails - available on the same SMSTAKE platform.