What is OTP (One-Time Password)?

A short numeric code sent via SMS, WhatsApp, or email that the signer enters to authenticate before signing.

A One-Time Password (OTP) is a 4-8 digit code sent to a signer through a separate channel (SMS, WhatsApp, email) that they must enter on the signing page to proceed. OTP authentication is a low-friction way to bind a signature to a verified communication channel: if the signer received the code at the email/phone the contract was sent to, they likely are who the contract names. PDF Verified supports OTP via email and WhatsApp for any document with the "Require OTP" flag enabled.

Drop your document here and sign it now. PDF, Word and Excel all work: a .docx or .xlsx is laid out in your browser exactly as it was written, so there is nothing to convert first. Add a signature, a date, a company stamp or a watermark, then download it sealed. Free to start, no account, and the file is never uploaded to open it.

OTP vs KYC

OTP proves the signer controls the email/phone in the contract. KYC proves the signer is the named individual with a verified government ID. Use OTP for everyday contracts where channel-binding is sufficient; layer KYC on top for regulated or high-value transactions.

How PDF Verified generates and sends OTPs

When the signer clicks the sign link, PDF Verified generates a 6-digit code, hashes it, stores the hash, and sends the plaintext via Resend (email) or WhatsApp Business API. The code expires in 10 minutes. The signer enters it on the portal; PDF Verified hashes and compares. The plaintext is never stored.

OTP failure modes

SMS delivery can fail in low-coverage areas. WhatsApp requires the signer's phone to be active on the network. Email OTP is the most reliable globally. PDF Verified falls back to email when WhatsApp delivery fails for resilience.

What PDF Verified is, and what it is not

An identity check establishes that a document was presented and, where liveness is used, that a live person presented it. It does not establish everything about a person, and it does not discharge an obligation a regulator has placed on you: your KYC, KYB and anti-money-laundering duties come from your own regulator and your own risk assessment, not from a signing tool. A verified identity is also not authority to act for somebody else, and signing in another person name without their authority is forgery.

PDF Verified is a tool for preparing, signing, stamping and checking documents. It is not a law firm, a compliance service or a forensic examiner, and nothing here is legal, financial or compliance advice. Requirements differ by country, by document type and by the party asking, so check what applies to your document before you rely on it, and take advice where the document matters. You are responsible for the documents you create, sign and send, and for having the authority to do so: signing or stamping in somebody else name, or as an organisation you do not represent, is forgery whatever tool is used. To the extent the law allows, we accept no liability for how a document made with this tool is used or relied on. The full position is in our terms of service.