LOW-COST CONTROL
SMS OTP Monthly Limit
SMS OTP is designed with a 1,000-send monthly hard cap. Paid provider activation stays OFF until Owner approval and provider credentials are configured.
1,000
Maximum allowed by this build.80% / 90%
Warning levels before the automatic stop.STOP
Further SMS OTP requests are blocked.Authenticator
Password / Authenticator login remains available.Cost Protection
Minimum 60-second resend cooldown. Default OTP validity is 5 minutes. Provider secrets must be stored as Cloudflare Worker Secrets. No SMS package, DLT registration or other paid service is purchased automatically.
Low-Cost OTP Provider
Selected Provider: 2Factor (India SMS OTP)
Status: Integration-ready / server credentials required.
API key is stored server-side only. OTP expiry, retry limit and rate limiting are included in server-otp.
Use Sandbox first; set OTP_MODE=LIVE only after API key/template testing succeeds.
Email OTP Primary — Low-Cost Mode
Primary: Email OTP via SMTP (Gmail/custom SMTP supported)
Standby: 2Factor SMS OTP after DLT/payment/key rotation.
Email OTP uses the same 5-minute expiry, retry limit and purpose controls. SMTP credentials remain server-side only.
