One-time code (OTP)

OTP · One-time passcode · 2FA code · Verification code

A one-time code is a short number an app or bank sends you, usually by text, so you can prove it is really you when you log in or approve something. It works once and then expires. Because it is the last lock on your account, no real company will ever ask you to read it back to them. Anyone who does is trying to get in.

How we check this: Written and reviewed by the Hunch team; recognition signs reflect how the FTC/FBI describe this scam. · Last reviewed: 2026-08

Check a suspicious message now

Detection runs 100% locally on your device. We store nothing.

Please don’t paste other people’s personal data. Detection runs 100% locally on your device, and we store nothing.

Or try a real one:

Get it free

Or check it on Telegram

Example

You get a text: "Your verification code is 448120." Seconds later someone claiming to be from your bank calls and asks you to read them the code to "confirm your identity." Reading it out hands them the key to your account.

How to recognize it

  • Someone asks you to share, read out, or type in a code you just received
  • The request comes wrapped in pressure, a "fraud check", or a "confirm it is you" story
  • A code arrives that you did not ask for, which can mean someone is already trying to log in as you

How Hunch flags it

Hunch flags messages that ask you to share or forward a login or verification code, a request no legitimate company makes.

FAQ

Should I ever share a one-time code?

No. A one-time code is only for you to type into the app or site you are logging into. No real bank, company, or support agent needs you to read it to them.

I got a code I did not request. What does that mean?

It often means someone has your password and is trying to log in as you. Do not share the code, and change that password if you can.

Related