Glossary
One-Time Password (OTP) Verification
TL;DR
OTP (One-Time Password) verification provides an optimal balance between security and frictionless user experience for electronic signing ceremonies. It proves that the signer currently possesses and controls the email inbox or mobile device associated with the agreement.
In Signbee, OTP verification is used during anonymous dispatches and recipient signature capture. A cryptographically random 6-digit code is generated, hashed with SHA-256 before database persistence, and dispatched via high-deliverability transactional email. The signer enters the code to confirm identity and affirmative consent before applying their digital signature.
**How Cryptographic OTP Verification Works in E-Signing**
1. **Initiation**: The sender or automated API dispatches a document contract (`POST /api/v1/send`). 2. **Challenge Generation**: The signing engine creates a high-entropy 6-digit numeric token (`crypto.randomInt(100000, 999999)`), computes the SHA-256 hash (`createHash('sha256').update(code).digest('hex')`), and saves the digest with an immutable 15-minute expiration timestamp (`expiresAt = now + 15m`). 3. **Out-of-Band Delivery**: The plaintext OTP is emailed to the verified recipient address (`recipientEmail`). 4. **Verification & Audit Sealing**: The recipient enters the OTP in the signing ceremony. The backend hashes the user input and compares it in constant time (`crypto.timingSafeEqual`) against the stored digest. Upon match, the OTP is invalidated to prevent replay attacks, and the ceremony state transitions to signed. 5. **Audit Trail Certification**: The audit certificate records the verification timestamp, signer IP address, user-agent telemetry, and OTP challenge ID.
**OTP vs API Key Authentication**
For automated agentic systems and high-volume SaaS workflows, API key Bearer authentication is instant and headless. OTP verification is specifically tailored for human recipients and first-time signers without registered developer credentials.
**Legal Admissibility under ESIGN, eIDAS & UETA**
Under US ESIGN Act § 101, EU eIDAS Article 25 (SES/AES), and UETA § 9, email OTP verification combined with cryptographic SHA-256 certificate sealing provides strong non-repudiation and evidential attribution in commercial and civil litigation.
Related terms
Further reading
Related resources
Try Signbee — e-signatures via API.