1. Home
  2. OTP SMS & Two-Factor Authentication
OTP & 2FA

OTP SMS & Two-Factor Authentication

An OTP SMS is a text message carrying a short, time-limited code that a user types back to prove they hold the phone — for a login, a payment approval or a sign-up. Because SMS reaches every handset, it is the most widely used second factor in Zambia. Ontech BulkSMS delivers OTP traffic over the same send API as any other message.

Published 2026-09-13 · Updated 2026-09-13 · By Ontech Solutions Limited

Definition.

An OTP SMS is a text message carrying a one-time password — a short code, usually 4 to 6 digits, valid for a few minutes and usable once — that a person types back into your application to prove they hold the phone. It is the most common form of two-factor authentication (2FA) in Zambia because it works on every handset.

Where OTPs are used

How OTP over SMS works

  1. Your application generates the code — random, short-lived, stored server-side with the phone number, a timestamp and an attempt counter.
  2. Your application sends it with one call to the Ontech BulkSMS send API (or a submit over an SMPP bind). The response returns a message ID.
  3. The gateway delivers it to MTN, Airtel or Zamtel based on the number prefix, from your approved sender ID.
  4. The user types the code back, and your application compares it with the stored value, checks expiry and attempts, and lets the action proceed.
  5. The delivery report for the message ID confirms whether the handset received it — useful for support and for deciding when to offer a resend.
Ontech BulkSMS does not generate or verify codes for you, and there is no separate OTP endpoint: OTP traffic uses the same send, status and callback facilities as any other message. That keeps the secret entirely inside your system, which is where it belongs.

Sending an OTP from your code

# Python — send the code you generated
import requests
r = requests.get("https://bulksms.ontech.co.zm/smsservice/httpapi", params={
    "api_key":   "YOUR_ACCESS_ID",
    "phone":     "260970000000",
    "sender_id": "YOURBRAND",
    "msg":       "Your YOURBRAND code is 481920. Valid for 5 minutes. Do not share it.",
})
message_id = r.json().get("message_id")     # {"status": 100, "message": "Success", "message_id": "…"}

# later — did it arrive?
s = requests.get("https://bulksms.ontech.co.zm/smsservice/status",
                 params={"api_key": "YOUR_ACCESS_ID", "message_id": message_id})
print(s.json()["delivery_status"])   # delivered | failed | rejected | queued | submitted

Keys are IP-whitelisted, and API requests are limited to 60 per minute per account, so poll status only when you need it — or register a callback URL and let delivery reports come to you. Note the platform's duplicate guard: an identical message to the same number within three minutes is suppressed, so a "resend" must carry a new code (or at least different text) to go out. See the API reference.

Designing a good OTP flow

OTP delivery speed and reliability

An OTP is only useful if it arrives before the user gives up. Ontech BulkSMS submits messages to the carrier within seconds of the API call; from there, delivery time depends on the network and on whether the handset is reachable. Every message returns a delivery report, so you can monitor the delivered rate per network in your dashboard and see problems as they happen rather than from complaints. For continuous authentication traffic, an SMPP transceiver bind gives the lowest latency and returns receipts on the same connection.

OTP in Zambian financial services

Banks, microfinance institutions and mobile money agents are the heaviest OTP senders in Zambia: a code for every login, every transfer above a threshold, every payout change. The banks and MFIs guide covers the wider set of transactional messages those institutions send — balance alerts, repayment reminders, collections — and how they integrate over API or SMPP with audit-ready delivery records.

Frequently asked questions

What is an OTP SMS?

A one-time password (OTP) SMS is a message containing a code — typically 4 to 6 digits — that is valid for a few minutes and can be used once. The user enters it to confirm a login, a transaction or a phone number, proving they control that phone.

Does Ontech BulkSMS have a special OTP API?

No separate endpoint is needed. Your application generates and stores the code, then sends it with the standard send API (HTTP, JSON or SMPP). Verification is done in your own system by comparing the code the user enters with the one you sent.

How fast is OTP delivery?

Messages are submitted to the carrier within seconds of the API call. Actual handset delivery depends on the mobile network and the recipient's coverage, so design your OTP to be valid for a few minutes and offer a resend option.

Should the OTP message use a branded sender ID?

Yes where possible. A message from your company name is easier for customers to trust than one from an unknown number. Request a sender ID in your dashboard; approval requires a signed authorization letter.

How can I tell whether an OTP reached the user?

Use the message ID returned by the send call to poll the delivery status endpoint, or register a callback URL to receive delivery reports. A status of delivered means the network confirmed handset delivery.

Ready to start sending?

Create a free account with trial credits, or talk to us about enterprise and reseller arrangements.