Welcome to our new developer portal! Use the "Ask" button to chat with our AI Agent.
For the complete documentation index, see llms.txt. This page is also available as Markdown.

OTP by SMS/email

The payment network TSP can authenticate the End User using a one-time password (OTP) generated and managed by the TSP.

The Issuer delivers the OTP to the End User by SMS or email.

D1 can send SMS and email on behalf of the Issuer. The following conditions apply:

1

Provide contact details

The Issuer must provide the End User’s phone number and/or email according to the preferred method. See Get started for details.

D1 uses this API to retrieve End User contact details from your issuer backend.

2

Configure templates

The Issuer must configure message templates. D1 supports placeholders to include the last four digits of the PAN and the OTP value.

3

Update DNS zone

The Issuer must update its DNS zone file to allow D1 to send emails on behalf of the Issuer and prevent emails from being treated as spam.

The detailed procedure is coordinated by the Thales delivery team. In summary, the Issuer defines and configures a subdomain (for example, email.bankname.com) and shares it with Thales. Thales uses it to generate DNS records that the Issuer adds to its DNS zone file.

Flow

OTP delivery flow (high level)

Sequence diagram

OTP delivery sequence diagram

Last updated

Was this helpful?