Passwordless Authentication

SMS OTP Login

Estimated reading: 4 minutes 118 views

SMS OTP Login allows users to securely authenticate and sign in to their WordPress site using a one-time verification code delivered directly to their mobile phone via SMS. Powered by Twilio, this passwordless authentication method eliminates the need for traditional passwords while providing a secure and frictionless login experience.

Why Use SMS OTP Login?

Mobile phones are highly personal devices that users typically keep in their possession. By delivering verification codes directly to a user’s phone, SMS OTP Login verifies both identity and device ownership, significantly reducing the risk of unauthorized access and account compromise.

Setting Up SMS OTP Login on Your WordPress Site

Follow the steps below to configure SMS OTP Login:

Navigate to the Passwordless Authentication Settings

  • Go to WordPress Dashboard → AIO Login → Passwordless Authentication
  • Open the OTP Login sub-tab.
otp-navigation
  • Locate the SMS OTP Login card.
  • Toggle SMS OTP Login to Enabled.
sms-otp-toggle

Configure Your Twilio Account

SMS OTP Login requires an active Twilio account to send verification messages.

Step 1: Obtain Your Twilio Credentials

  • Sign in to your Twilio Console.
  • Create or configure a messaging project.
  • Locate the following credentials:
  • Account SID
  • Auth Token
  • Twilio Phone Number or Messaging Service SID
twilio-config

Step 2: Add Twilio Credentials to AIO Login

Enter the following information in the SMS OTP settings:

  • Account SID – Your Twilio Account SID.
  • Auth Token – Your Twilio Auth Token.
  • Sender Number – Your Twilio phone number, Sender ID, or Messaging Service SID.

Geographic & Phone Configuration

Default Country Code

Choose the default country code that will automatically appear on the login form.

Allowed Countries

Select the countries that are permitted to request SMS verification codes.

Features include:

  • Multi-select support
  • Country-specific authentication restrictions
  • Protection against spam and unauthorized international requests

Users from countries not included in this list will not be able to request an SMS OTP.

Note: If a country does not appear in the dropdown, add it to the Allowed Countries list under AIO Login → Passwordless Authentication → OTP Login → SMS OTP Login, save the settings, and try again.

SMS OTP Configuration Options

OTP Length

Select the verification code length:

  • 4 digits
  • 6 digits
  • 8 digits

Default: 4 digits

OTP Expiration (Minutes)

Specify how long the verification code remains valid.

Allowed Range: 1–60 minutes

Resend Timer (Seconds)

Define how long users must wait before requesting another SMS verification code.

Allowed Range: 30–600 seconds

Maximum Retry Attempts

Specify the number of incorrect OTP submissions allowed before a temporary lockout is triggered.

Allowed Range: 1–20 attempts

Block Duration (Minutes)

Define how long the requesting IP address remains blocked after exceeding the maximum retry attempts.

Allowed Range: 1–1440 minutes

Note: The user’s IP has exceeded the maximum allowed OTP verification attempts and is temporarily blocked until the configured lockout period expires or the lock is manually removed from AIO Login → Activity Log → Lockouts.

Skip 2FA for SMS Login

Enable this option if users who authenticate through SMS OTP should bypass any additional Two-Factor Authentication steps.

  • Click Save Changes to apply the configuration.
sms-otp-settings

Frontend Login Experience

When SMS OTP Login is enabled, users will see an additional authentication option on the WordPress login page.

Step 1: Launch SMS OTP Login

  • A Login with SMS OTP button (.aio-login-otp-launcher) appears below the standard username and password fields.
  • Clicking the button opens the SMS OTP authentication panel.
sms-otp-login

Step 2: Enter Phone Number

The panel initially displays the Contact Stage (data-step=”contact”).

Users can:

  • Select their country from the #aio-login-otp-country dropdown.
  • Enter their phone number in the #aio-login-otp-phone field.
  • View the synchronized dial code beside the phone number field.
  • Complete CAPTCHA verification if Google reCAPTCHA, hCaptcha, or Cloudflare Turnstile is enabled.
  • Click Send OTP to request a verification code.

Only countries configured under Allowed Countries are displayed in the country selector.

continue-with-sms-modal

Step 3: Verify OTP

After successfully requesting an SMS OTP, the panel switches to the Verification Stage (data-step=”verify”).

Users can:

  • Enter the verification code in the #aio-login-otp-code field.
  • View the resend countdown timer.
  • Click Verify to complete authentication.

The code input automatically matches the configured OTP length (4, 6, or 8 digits).

otp-verification

Back Navigation

Users can select Back to Login at any time to exit the SMS OTP panel and return to the standard WordPress login form.

back-to-login-btn

Need Help?

If you face any issues or have questions, feel free to contact our support team. We’re here to help you get the most out of AIO Login.

Leave a Reply

Your email address will not be published. Required fields are marked *

Share this Doc

SMS OTP Login

Or copy link

CONTENTS
Scroll to Top

Subscribe

×
Cancel