The OTP Expiry Settings allow administrators to control the expiration and resend options for One-Time Passwords (OTPs) used in a form. This is crucial for enhancing security while providing flexibility to the users.
OTP Expiration Time
This option sets the amount of time (in minutes) that an OTP is valid for, after it is generated. If the OTP is not used within this time frame, it will expire and the user will have to request a new one.
Set the Same Expiration Time for OTP Session
This option allows the admin to synchronize the OTP session duration with the OTP validity period.
- When you select this option, the OTP session will expire at the same time as the OTP itself. This means if you set the OTP expiration time to 5 minutes, the session will also expire after 5 minutes. This ensures that both the OTP and the session in which it was generated expire simultaneously.
- If this option is left unchecked, the session will follow its default expiration time of 4 hours. In this case, even if the OTP expires (for example, in 5 minutes), the session will remain active for up to 4 hours unless manually terminated or interrupted by other actions. This means you are allowing the user more time within the session, but they will need to request a new OTP after the OTP expires. This can be useful in cases where users need more time in their session, but a short OTP expiration time is still desired.
Number of OTP Resend Requests Allowed
This option determines how many times a user can request a resend of the OTP. Select a number from the dropdown. This limits the number of times a user can request for a new OTP to avoid excessive requests for OTP generation.
Show OTP Resend Option After
This option lets you specify the waiting period (in seconds) before the user can request an OTP resend. Set the time delay after which the user will see the option to resend the OTP.
This option controls whether the Form link that is validated with OTP, will expire after a certain time.
If you choose Yes, you can set an expiration period for the page after the OTP verification is completed. Enter the number of hours that the OTP-validated form link will remain valid for to let the users complete their activities (Save/Submit form) within this timeframe.
For example, if you choose it to expire after 2 hours, the OTP-validated form link will remain accessible for 2 hours from the time of OTP verification, after which the it will no longer be accessible.
If you choose No, the form will remain valid indefinitely and will not expire.
Message on Link Expiry
You can enter a custom message (up to 250 characters) that will be displayed to the user when the OTP-validated page expires.