Glossary
One-time passcode (OTP)
A one-time passcode (OTP) is a short code sent to a signer by text or email that must be entered before a document can be opened or signed.
An OTP, or one-time passcode (also called a one-time password), is a short, single-use code sent to someone's phone or email that they enter to prove they control that channel. In e-signing, OTP verification adds a second step before the signer can view or sign a document, so a forwarded link alone is not enough.
The flow is simple. The sender adds a phone number or relies on the signer's email, the signer clicks the signing link, and the platform sends a code, often six digits, that expires within minutes. Once the code is entered, the session opens and the verification event is written into the audit trail. If the code is wrong or stale, the signer requests a new one.
Imagine an HR team sending offer letters to candidates. The link goes by email, but the team adds an SMS code to the candidate's mobile number from the application. Now, even if the email were forwarded to a colleague, only the person with that phone could sign, and the audit record shows both factors.
People sometimes treat an OTP as proof of identity. It is not quite that; it proves control of a phone number or inbox at a given moment. SIM swapping and compromised mailboxes are real, if uncommon, risks. For most business documents that level of assurance is plenty, but it is weaker than an ID document check or KBA.
OTP is a form of signer authentication and is usually the next step up from a plain email link. It pairs naturally with the audit trail, which captures when the code was sent and verified.
A few practical tips make OTPs smoother. Use the channel the signer actually checks: a mobile number for people on the move, email for desk workers. Keep expiry windows reasonable so signers are not racing the clock, and make it easy to request a fresh code. International numbers can have delivery delays, so an email fallback is worth having. Finally, tell signers in your message that a code will arrive, so the extra step feels expected rather than suspicious.
Our take: an SMS or email code is the sweet spot for documents that deserve a bit more certainty, like offer letters or payment authorizations. It adds seconds, not minutes, and signers already understand it from banking apps.
eSignSimple does not send OTPs yet; SMS and email codes are on our roadmap. Today signers receive a unique link by email, need no account, and every action is logged with timestamps, IP address and device details in the audit trail.
Get your next document signed today.
Start with 5 free documents a month. No card needed.