DEV Community

Cover image for The One Time Password
Sreya Satheesh
Sreya Satheesh

Posted on

The One Time Password

👉 Try The One Time Password

We've all entered an OTP before.

Six digits. Enter. Verify. Done.

But what happens behind those six digits?

Where is the OTP generated?

Where is it stored?

How does it expire?

What happens when someone enters the wrong code?

And what happens when millions of users need an OTP at the same time?

I built The One Time Password to explore these questions.

What Is It?

The One Time Password is an interactive walkthrough of how an OTP service can be designed.

Instead of showing the whole system as one architecture diagram, the app lets you follow a request through each part of it.

A simplified flow looks like this:

User → API → OTP Service → Redis → Delivery Provider → User → Verification

The user requests an OTP.

The service generates one, stores it with an expiration time, and sends it to the user.

The user enters the code.

The service checks it and returns the result.

What Happens to the OTP?

An OTP is temporary, so the system needs to keep track of a few things:

  • The code
  • Who requested it
  • How long it is valid
  • Whether it has already been used
  • How many verification attempts have been made

For the temporary storage, the design uses Redis.

An OTP can be stored with a TTL (time-to-live):

Generate OTP
     ↓
Store OTP + TTL
     ↓
Send OTP
     ↓
User enters OTP
     ↓
Verify
     ↓
Success → Invalidate
Expired → Reject
Enter fullscreen mode Exit fullscreen mode

Once the TTL expires, Redis removes the entry.

The Security Part

A six-digit OTP has only a limited number of possible combinations.

So generating the code is only one part of the problem.

The service also needs to handle:

  • Rate limiting
  • Brute-force attempts
  • Resending OTPs
  • Replay attempts
  • OTP expiration
  • Secure random generation
  • Preventing an OTP from being reused

For example, what should happen if someone keeps trying different codes?

Or keeps requesting new OTPs?

These are the kinds of cases the system needs to account for.

What Happens at Scale?

Now take the same service and give it millions of users.

A few more questions come up:

  • Can multiple application servers handle the requests?
  • How do they share OTP state?
  • What happens if Redis goes down?
  • What happens if the SMS or email provider is slow?
  • What happens when a request is retried?
  • How should repeated OTP requests be handled?

The six-digit code is straightforward.

The system around it is where most of the design decisions are.

Inside the App

The walkthrough covers:

  • OTP generation
  • Redis
  • TTL and expiration
  • Verification
  • Rate limiting
  • Security
  • Scaling
  • Retries
  • Failures
  • System architecture

You can move through the request and see how these pieces connect.

Try It Yourself

👉 The One Time Password

Start with an OTP request and follow it through the system.

Top comments (0)