My one-time password isn't working
Problem Statement
This article explains what to do when your OTP (one-time password) is not working—for example invalid OTP or OTP email not received—and when testing on Time Machine.
Related Scenarios
- I am an end-user and my OTP isn't working.
- I am a merchant (not using Time Machine) and OTP isn't working.
- I am testing on Time Machine and not receiving OTPs.
- Two types of OTP issues: invalid OTP entered vs OTP email not received.
Solution
Scenario 1: Invalid OTP entered
- Confirm the email address and OTP are correct.
- Delete old OTP emails, request a new OTP, and sign in with the latest OTP only.
Note
After 5 incorrect attempts the account is locked for about 30 minutes. This is a security measure to limit excessive requests.
Scenario 2: OTP email not received
- Ensure you are signing in with the correct email address.
- Check the Spam folder for the OTP email.
- If you use your own SMTP, check logs and bounce list for the email address.
- Ensure you are using the correct domain region (US/EU/AU) for your site. Using the wrong region when resetting password can prevent the reset email from being sent.
Time Machine: If you are a merchant testing on Time Machine and not receiving OTPs, see I am not able to receive OTPs when I test the site using Time Machine.
Temporary workaround: If a customer cannot access the portal and you need to give them access without login, you can create a portal session via the Create a portal session API.
Was this article helpful?