OTP SMS in Bangladesh is the most common way to verify a phone number, sign a user in or confirm a payment. A good OTP flow sends a short, clear code from a recognisable sender, expires it quickly, limits retries and never sends the same code twice by accident. This guide covers the practices that keep OTP fast for real users and hard for attackers.

What is OTP SMS?

An OTP (one-time password) is a short code, usually 4 to 8 digits, that your system generates and sends to a user's mobile number. The user types it back into your app or website to prove they control that number. Because it is valid only once and only for a short time, a stolen code is of little use later.

In Bangladesh, OTP is used by e-commerce sites, fintech and mobile wallets, ride-sharing and delivery apps, banks, ed-tech platforms and any service with phone-number login. On GotiSMS, OTP is its own message category, and OTP messages can be sent at any time, with no time window. See the OTP SMS page.

How should you generate OTP codes?

The code itself is the foundation of security.

  • Use a cryptographically secure random generator, such as random_int() in PHP, crypto.randomInt() in Node.js or the secrets module in Python. Avoid ordinary random functions, timestamps or sequential numbers.
  • Use 6 digits for most cases. It balances security and ease of typing. Use fewer only for low-risk actions with strict attempt limits.
  • Store a hash of the code, not the code itself, along with the phone number, purpose and expiry time.
  • Bind the code to one action. A code issued for login should not work for changing a password or confirming a payment.

How long should an OTP stay valid?

Short enough to limit abuse, long enough for a real person to receive and type it. Many services choose a few minutes. Whatever you choose:

  • Show the expiry in the message and on screen.
  • Invalidate the code as soon as it is used.
  • Invalidate older codes when a new one is issued for the same action.

How do you write a good OTP message?

Keep OTP messages short and plain. A good template:

Your GotiShop login code is 482193. It expires in 5 minutes. Never share this code with anyone.

Best practices:

  • Put the code early so it shows in the notification preview.
  • Name your brand, so users know who sent it.
  • Add a warning not to share the code. This helps protect users from social engineering.
  • Write OTP messages in English (GSM-7) where possible. A single English SMS holds 160 characters, while a Bangla (Unicode) SMS holds 70. One emoji also switches the whole message to Unicode. Keeping OTP to one part keeps it cheap and simple. If your users prefer Bangla, keep the text short enough for a single 70-character part. See Bangla SMS character limits.
  • No links in OTP messages. Codes with links look like phishing and train users to click.

Should you use masking for OTP?

For customer-facing OTP, a masking sender ID (your brand name) is usually the better choice. Users recognise it, and it is easier to warn them that "genuine codes only come from GOTISHOP". Masking sender IDs use letters, up to 11 characters, and need approval before use. Non-masking also works on every network and every account has a default non-masking sender, which is useful while your sender ID is being approved. Compare them in Masking vs Non-Masking SMS.

How do you protect OTP from abuse?

OTP endpoints attract bots, because each request costs you money and can be used to flood a victim's phone.

  1. Rate-limit requests per phone number, for example a small number of codes per number per hour.
  2. Rate-limit per IP address and per device to slow automated attacks.
  3. Add a cooldown before "Resend code", and show a countdown timer.
  4. Limit verification attempts per code, then require a new code.
  5. Add a CAPTCHA or similar check after suspicious patterns.
  6. Validate the number format before sending. GotiSMS sends only to Bangladeshi mobile numbers, so reject anything else early.
  7. Monitor spending. A sudden jump in OTP volume is often an attack, not growth.

How do you send OTP through the GotiSMS API?

Send OTP with a POST request to the send endpoint, using "category": "otp":

curl -X POST https://api.gotisms.com/api/messages/send \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: otp-login-7f3c9a12" \
  -d '{
    "recipients": ["01712345678"],
    "senderId": "YOUR_SENDER_ID",
    "message": "Your GotiShop login code is 482193. It expires in 5 minutes.",
    "category": "otp"
  }'

Key points for OTP integrations:

  • **Always send an Idempotency-Key.** If your request times out and you retry with the same key, GotiSMS never sends or charges twice. Without it, a network glitch could send two different codes and confuse the user. Generate one key per OTP issued, and reuse it only for retries of that same request.
  • "Accepted" is not "delivered". The response tells you whether the network accepted each number (accepted, rejected and a results array with a status per number). Delivery reports arrive later and can be read through the API's report endpoints or the Campaigns page.
  • Keep your API key on the server. Never put it in a mobile app or browser code. Use the optional IP allow-list to restrict the key to your servers.
  • Respect the rate limit. The default is 300 requests per minute per key. Queue OTP requests during traffic spikes rather than dropping them.

Full examples in PHP, Node.js and Python are in our SMS API integration tutorial, and the reference is at /docs/sms-api.

What should the user experience look like?

Fast code delivery is only half of a good OTP flow. Also:

  • Auto-focus the code field and allow pasting.
  • On Android, consider the platform's SMS autofill features.
  • Show the number the code was sent to, with an option to correct it.
  • Explain clearly when a code has expired and let the user request a new one after the cooldown.
  • Offer a support route, such as an email address, for users who never receive the code.

Frequently asked questions

Can OTP SMS be sent at night in Bangladesh?

Yes. On GotiSMS, OTP and transactional messages can be sent at any time. Only promotional SMS is limited to 09:00–21:00 Bangladesh time.

How many digits should an OTP have?

Six digits is a good default for most apps. Combine it with short expiry and limited attempts.

Why use an Idempotency-Key for OTP?

It makes retries safe. If you resend a request with the same key, GotiSMS will not send or charge a second time, so the user receives one code, not two.

Does an accepted OTP mean the user received it?

No. Accepted means the network took the message. Delivery status comes later through delivery reports.

Should OTP messages be in Bangla?

They can be, but a Bangla message is Unicode and fits only 70 characters in one part. Short English OTP messages are usually simpler and cheaper.

Build a reliable OTP flow on every Bangladeshi network. Create a GotiSMS account, generate your API key and send your first test code in minutes.