Skip to content

How To Customize OTP Settings

You can customize OTP codes from Texty > OTP in your WordPress dashboard. Choose the code length and type, set its expiry and resend wait, then edit the SMS. These settings apply to checkout, registration, and phone number changes.

Make sure Texty and Texty Pro are active. Your Pro license must show an active status.

You also need a working SMS gateway. OTP cannot reach a phone if no gateway is active. If needed, follow how to connect your first SMS gateway.

How do you set the OTP code length and type?

Section titled “How do you set the OTP code length and type?”

Sign in to your WordPress dashboard. Go to Texty > OTP.

Texty OTP Global Configuration page showing code length, code type, custom message content, and a sample SMS preview on a phone mockup

Find the global OTP settings. Choose a code length.

Close-up of the Texty OTP Code Length and Code type radio button options set to 6 digit and Numeric

Choose a code type. Write the Custom Message if needed, set the expiry time, and resend inteval and save your changes.

SettingOptionsDefault
Code length4, 6, or 8 characters6
Code typeNumeric or alphanumericNumeric

A numeric code uses digits only. An alphanumeric code uses letters and digits. Texty leaves out IO0, and 1 so the code is easier to read.

Find the OTP message field on the same page. The default message is:

Dear customer, your \{OTP_Code} is valid for the next \{expiry} minutes.

You can rewrite it to fit your store. Keep the message clear and place the code near the start. The editor allows up to 160 characters.

Texty OTP Custom Message Content field with the OTP_Code, site_code, and email dynamic variable tags

Use only the tags shown in your Texty settings.

TagWhat it adds
\{OTP_Code}The one-time code
\{expiry}The code expiry in minutes
\{site}Your site name
\{site_code}The short code for your site

Here is a simple example:

Your \{site} code is \{OTP_Code}. It expires in \{expiry} minutes.

Do not ask customers to share the code. Review the live sample before you save.

Use the expiry and resend fields to control how long each code can be used.

SettingWhat it controlsRangeDefault
ExpiryHow long the code stays valid1 to 60 minutes2 minutes
Resend cooldownHow soon another code can be sent to the same phone10 to 600 seconds30 seconds

A short expiry gives less time to use a stolen code. It can also be hard for people who need more time to read the SMS.

Texty OTP Expiry Time and Resend Interval fields set to 2 minutes and 30 seconds

A longer resend wait can reduce repeat sends and gateway costs. Do not make it so long that a delayed message blocks a real customer.

Good starting point: Keep the two-minute expiry and 30-second resend wait. Change them only if your tests show a clear need.

Texty applies these limits to every OTP flow:

  • Five wrong attempts make the current code invalid.
  • One IP address can request up to 10 OTP messages per hour.
  • One IP address can make up to 30 verification attempts per hour.
  • A verified state lasts for 30 minutes.

These limits are built in. You cannot change them from the OTP settings.

Enable one OTP flow, then test with a phone you control.

  1. Request a code.
  2. Check that the SMS uses your new wording.
  3. Confirm that the code has the right length and type.
  4. Enter the correct code.
  5. Request another code and check the resend wait.
  6. Let a code expire, then make sure Texty rejects it.

Do not run repeated tests from a customer phone. Each SMS may add to your gateway bill.

Success check: The SMS uses your saved format, the correct code works, and expired or old codes do not.

What happenedWhat to check
No code arrivesConfirm that a gateway is active and the phone uses an international format.
A tag appears as plain textCopy the tag exactly as shown in Texty.
The message is cut offShorten it and keep it within 160 characters.
Resend is blockedWait for the resend cooldown to end.
A new code failsUse the latest code sent to the phone.
The code expired too soonRaise the expiry time, save, and test again.

The six-character default is a good starting point for most stores. A longer code is harder to guess, but it takes more time to enter.

No. The code, message, expiry, and resend settings are shared by checkout, registration, and profile changes.

No. Texty stores a protected hash of the code, not the raw code.

Developers can extend OTP variables with a Texty Pro filter. Store admins should use only the tags listed in the current settings.

Choose where customers must verify their phone: