Temporary SMS Verification Codes: How They Work, Why They Expire, Why They Are Single-Use
Need quick verification codes? Start your verification journey now
A temporary SMS verification code, also called an SMS one-time password or OTP, is a short random number, usually 4 to 8 digits, that a service texts to a phone number to prove you control it. It works for one signup or login session only, expires within minutes, and is rejected after its first successful use. How long it lasts is set by the service that sends it.
This page explains the code itself: how it is made, what the message around it means, why it stops working, and what that means when you receive it on a temporary number. For choosing a platform or for the wider rules around SMS verification, see the links at the end.
What happens between "Send code" and the SMS
When you tap "Send code", the service does roughly this:
- Checks the number. Large services look up the line type (mobile, VoIP or landline), whether the number is already tied to an account, and whether the country fits the rest of the request. A number can be refused at this point, before any SMS exists.
- Generates a random code with a secure random generator and stores a record of it on its server. That record usually holds the code (often hashed), your phone number, the session it belongs to, an expiry time and a counter of wrong attempts.
- Hands the message to an SMS provider, which routes it through the mobile network to the carrier that owns the number.
- Waits for you to type the code back. When you submit it, the server compares it with the stored record, checks the expiry time and the attempt counter, and either accepts it and closes the record, or counts a failed attempt.
Two things follow from this. The code is bound to one session: a code requested in one browser tab will not work in another. And the service does not care what kind of phone receives the text, as long as the number passed the checks in step 1.
SMS codes are not the same as authenticator codes
People often mix up SMS codes with the six-digit codes in authenticator apps. They work differently:
| SMS one-time code | Authenticator app code (TOTP) | |
|---|---|---|
| Where it comes from | Generated by the service's server, sent by text | Calculated on your device from a shared secret |
| How long it lasts | Set by the service, usually minutes | Changes every 30 seconds by default (RFC 6238) |
| Needs mobile signal | Yes | No |
| Tied to a phone number | Yes | No, tied to the app's secret key |
| Main risks | SIM swap, interception, phishing | Phishing, losing the device without backups |
That difference is why the usual advice is to use SMS to create an account and then switch the account's ongoing security to an authenticator app or passkey. It matters even more when the SMS went to a temporary number.
Reading a verification text
Most verification texts contain more than the code. Knowing the parts helps you copy the right thing:
- The code. The digits you need. Some services add a prefix: Google, for example, sends codes in the form
G-123456, and you type only the digits unless the form asks for the prefix. - The sender name or number. Useful for telling apart two codes that arrive close together.
- An expiry note. Many messages say how long the code is valid. That is the only reliable figure for that service, because it can change without notice.
- A warning line such as "do not share this code". The service means it: anyone with the code can finish the action it was sent for.
- An 11-character string at the end. That is an app hash used by Android's SMS Retriever API so the app can read the code automatically. It is not part of the code.
- A last line like
@example.com #123456. This is the domain-bound one-time code format, which lets browsers offer to fill the code only on the right website. The digits after#are the code.
On SMS-Act you see the whole text in your order, so you can check the sender and the expiry note before copying.
Why codes expire
A code that never expired would act like a password that anyone could read off a lock screen, a leaked message log or a forwarded text. Short validity limits that risk. Services balance it against real delays: a slow route or a user switching apps. Banks and payment apps usually sit at the strict end; social and consumer apps give a bit more time.
With a temporary number there are two clocks:
- The code's validity, set by the service.
- The number's hold time on the platform. On SMS-Act a number is held for you for 15 minutes.
The code must arrive and be used inside both windows. In practice that means: have the signup form open and filled before you order the number, request the code once, and type it in as soon as it appears.
Why codes are single-use, and why numbers are too
A code is closed as soon as it is accepted. Submitting it again gets an "expired" or "already used" error, even if the time limit has not passed. This is what stops someone reusing a code they saw later.
Services apply a similar idea to phone numbers. Most remember which numbers have already verified an account and refuse to use the same number again, often with a message like "this number is already in use". That is why temporary numbers are one-time: SMS-Act gives each order a number for a single verification. If you need to verify again later, you need a new number.
Where temporary numbers fit and where they do not
| Scenario | Temporary number? |
|---|---|
| Creating an account that asks for a phone once | Yes, this is the main use |
| Trying a service without giving your personal number | Yes |
| Testing sign-up flows in different countries | Yes |
| Ongoing SMS two-factor on an account you keep | No: move 2FA to an app or passkey |
| Password recovery by SMS | No: the number will not be yours later |
| Bank, payment or government identity checks | No: those check identity, not phone access |
SMS-Act numbers are real carrier mobile lines, not VoIP, which matters for services that check line type in step 1 above. They receive text messages only, so if a service offers "call me with the code", stay on the SMS option.
When a code goes wrong
| What you see | Likely cause | What to do |
|---|---|---|
| "This number cannot be used" before any SMS | The number failed the service's checks (line type, reuse or country) | Cancel and try a number from another country |
| Nothing arrives | Route filtered, or the service quietly declined to send | Wait a few minutes, then start a new order with a different country. On SMS-Act the credits go back to your account automatically if no code arrives. |
| Code rejected as invalid | Typo, a space pasted in, or you requested a newer code | Type the digits by hand; use only the most recent code |
| Code rejected as expired | It sat too long, or the session timed out | Restart the signup and use the new code immediately |
| "Too many attempts" | Several wrong codes or repeated requests | Wait out the lock before trying again |
| The service switches to a phone call | Some services fall back to voice after retries | SMS-Act cannot receive calls. Stay on SMS, wait for the cooldown, then use a new number or another country. |
Security: what an SMS code proves and what it does not
An SMS code proves that someone could read a text sent to that number at that moment. It does not prove who they are. Its known weaknesses are phishing (a fake login page can ask for the code), SIM swaps, and interception. That is why stronger options exist:
| Method | Phishing resistance |
|---|---|
| Passkeys and hardware security keys | Very high |
| Push approval with number matching | Medium to high |
| Authenticator app (TOTP) | Medium |
| SMS one-time code | Low to medium |
| Email one-time code | Low |
For low-stakes sign-ups, an SMS code is fine. For anything you care about, use SMS to get in, then set up an authenticator app, a passkey and a recovery email.
Checklist for using a temporary code
- Open and fill the signup form before ordering a number.
- Request the code once. Every extra request can cancel the previous code.
- Copy only the digits, and check the sender if two texts arrive.
- Finish within the code's validity and the 15-minute hold.
- After signing up, add a recovery email and move two-factor to an app or passkey.
Each SMS-Act verification costs a flat 8 credits, the same for every country and service.
Frequently asked questions
How long is a temporary SMS verification code valid?
The service that sends the code decides, and it is usually a matter of minutes. Many messages state the limit themselves, for example that the code expires in 10 minutes. On SMS-Act there is a second clock: the number is held for you for 15 minutes, so request the code only when the signup form is ready.
Can a temporary SMS code be used twice?
No. Once a code has been accepted, the service marks that signup or login session as used, and the same code is rejected if you submit it again. A new attempt needs a new code.
Why was my code rejected even though I typed it correctly?
The three usual causes are that the code has expired, that you requested a second code which replaced the first, or that the code belongs to a different session, for example one opened in another browser tab. Request one fresh code, use it straight away and do not request another in between.
What are the extra characters at the end of some verification texts?
They are for automatic code filling. An 11-character string at the end is an Android app hash used by the SMS Retriever API, and a last line like @example.com #123456 tells browsers which website the code belongs to. They are not part of the code; only the digits are.
Related reading
- SMS verification: complete guide and regulation — the whole process and the rules around it
- Temporary phone numbers for verification — getting and using the number itself
- SMS verification FAQ — quick answers to common errors
Disclaimer
This platform is designed to support development testing, business verification, and international service scenarios, helping users complete processes in a reasonable and compliant manner.
Users are expected to ensure that their use of the service complies with applicable laws, regulations, and the policies of third-party platforms. The platform does not participate in or control how the service is used.
Accounts associated with abnormal or improper usage may be subject to restrictions in accordance with platform policies.
Users must be at least 18 years old and acknowledge that they are fully responsible for their own use and any resulting outcomes. If you do not agree with these terms, please discontinue use of the service.