OTP Verification via Email

OTP Verification via Email

When you configure Email OTP verification, respondents who access your form via its public link are required to enter their email address to receive a one-time password and verify it before they can access the form.

Setting Up Email OTP Verification

  1. Open your form to which you want to configure Email OTP verification.
  2. In the left panel, under Form Fields scroll to Advanced Elements and click Verification Page.
  3. In the Verification Page configuration screen, click Configure on the OTP Verification card.
  4. In the Configure OTP Verification popup, select Email.

    Email OTP Verification
  5. Under From, select the email address from which the OTP email will be sent. To display a sender name, click Add From Name.
  6. You can update the default Subject and the Message to display in OTP email as required. You can also include the link to the OTP Verification page where the respondent is required to enter the received OTP in the email message by clicking the    icon. If the respondent has entered the OTP, then the link in the email will redirect to the form and not to the OTP Verification page.The placeholder ${zf:OTP} represents the OTP value and will be replaced with the actual code when the email is sent.
Notes
Note: If you select notifications@zohoforms.com as the From address, the form owner's email address will be set as the From Name by default and cannot be modified.

OTP Expiry Settings

Here you can configure expiration and resend options for the OTP.

OTP Expiry Settings

OTP Expiration Time
This option sets the amount of time (in minutes) that an OTP is valid for, after it is generated. If the OTP is not used within this time frame, it will expire and the respondent will have to request a new one.

Set the Same Expiration Time for OTP Session
This option allows you to synchronize the OTP session duration with the OTP validity period.
  1. When you select this option, the OTP session will expire at the same time as the OTP itself. This means if you set the OTP expiration time to 5 minutes, the session will also expire after 5 minutes. This ensures that both the OTP and the session in which it was generated expire simultaneously.
  2. If this option is left unchecked, the session will follow its default expiration time of 4 hours. In this case, even if the OTP expires (for example, in 5 minutes), the session will remain active for up to 4 hours unless manually terminated or interrupted by other actions. This means you are allowing the user more time within the session, but they will need to request a new OTP after the OTP expires. This can be useful in cases where users need more time in their session, but a short OTP expiration time is still desired. 
Number of OTP Resend Requests Allowed
This option determines how many times a user can request a resend of the OTP. Select a number from the dropdown. This limits the number of times a user can request for a new OTP to avoid excessive requests for OTP generation.

Show OTP Resend Option After
This option lets you specify the waiting period (in seconds) before the user can request an OTP resend. Set the time delay after which the user will see the option to resend the OTP.
Map OTP Verification Field: 
You can pre-fill an email field in the form with the verified email address by selecting the required form field from the dropdown. 

Map OTP Verification field

You can prefill an email field in the form with the verified email address by selecting the required form field from the dropdown.
Map OTP Verification field
You can choose to use the prefilled value of the selected field for OTP verification by selecting the checkbox as shown above. The value can be prefilled from integrated sources like CRM/ Dynamic prefill from Webhooks/ Field Alias/ Static Prefill URLs.

Notes
Note:
  1. The following properties configured for the selected Email field will be applied to the email address entered by the respondent for verification:
  1. Domain Validation
  2. Character Limit
  3. No Duplicates Validation
  4. Email input confirmation 
  1. If you want to restrict your respondent from editing the pre-filled Email field in the live form, select the Disable Field option under Email field Properties.   
  2. If the email field is pre-filled through an integrated service or Field Alias, it cannot be modified on the Verification page. The OTP will be sent exclusively to this pre-filled value.
You can add instructions and a consent declaration for respondents on the Verification Page.

Instructions & Consent
Instructions: Enter any information or guidance you want respondents to read before verifying. 

Consent: To include a consent declaration, select Yes for Do you want to include consent? and enter the consent text. Respondents will need to acknowledge the consent before they can proceed with verification.

CAPTCHA

CAPTCHA

To add an extra layer of security and prevent spam entries, you can enable a CAPTCHA on the Verification Page to evaluate if it is a human or a bot that is filling your form. Under CAPTCHA, select the CAPTCHA Type from the dropdown. Learn more

Info
Plan wise limit for the maximum number of forms that can have OTP configuration:
Basic - 25
Standard - 100
Professional - 200
Premium - 200
Express - 200
Zoho One Enterprise - 200
Zoho One Enterprise Trial - 3


Check out the FAQ on how to access an OTP Verification enabled form with the same email address when the field is mapped to a form field with the No Duplicate  property.