Skip to main content
Version: 11.3.0

Phone Number / Email Verification

The Phone Number / Email Verification step in HYPR Affirm confirms that the requester controls the phone number or email address that your directory holds for them. Depending on its settings, the step checks a phone number the requester types against the number on file, sends a one-time password (OTP) to that phone number or to the email address on file, or both.

Prerequisites​

The requester's directory record must hold a mobile phone number for the SMS channel and for the phone number match, or an email address for the email channel. See Identity Provider Prerequisites.

Configure the Step​

The step card reads Choose how to verify user contact details and whether to send a one-time passcode (OTP) for Identity Verification during this step of the workflow. A new verification flow includes this step. The following table lists its settings.

SettingWhat It DoesAllowed ValuesDefault
Send OTPSends a six-digit code that the requester must enterCheckboxCleared
Contact PreferenceWhere the code goes; available when Send OTP is selectedSMS, Email or SMS or EmailSMS
Retry LimitNumber of failed attempts allowed before the failure outcome applies1 to 10 attempts, within 0 to 60 minutes in 5-minute steps3 attempts within 0 minutes
Failure OutcomeWhat happens when the retry limit is reachedDeny Verification, Redirect to URL or Continue Workflow (optionally with Escalate to Live Chat)Deny Verification

The settings combine as follows:

  • Send OTP cleared: the requester types their mobile phone number and Affirm compares it with the number on file. No code is sent.
  • SMS: the requester types their mobile phone number. When it matches the number on file, Affirm texts a code to it.
  • Email: the requester does not type anything. Affirm emails a code to the address on file.
  • SMS or Email: the requester chooses Verify by phone or Verify by email, then continues as for SMS or Email.

When your tenant uses the Affirm Risk Policy Builder, the assigned Policy Evaluation Kit sets retries and failure outcomes instead of the Retry Limit and Failure Outcome controls.

What the Requester Sees​

The step has two screens: the contact screen and, when Send OTP is selected, the code screen.

Contact screen: Let's verify your phone, with the country picker, the phone number field and the Next button

Contact Screen​

The contact screen shows the title for the configured channel. For SMS it also shows the last four digits of the number on file, for example "Enter your phone number ending in: 0100." The phone field has a country-code picker, and Next stays disabled until the number is a possible phone number for the selected country. Starting in HYPR 11.3.6, an email address shown to the requester at this step is masked, leaving only the first and last characters of the part before the @.

Contact screen for a flow that offers both channels: Let's verify your phone or email, with Verify by phone and Verify by email

The following table lists the default text. Administrators can change it in Affirm Studio.

ElementDefault Text
Title, SMS"Let's verify your phone"
Title, Email"Let's verify your email"
Title, SMS or Email"Let's verify your phone or email"
Description, SMS or Email"Please select your preferred method of contact for verification."
Choice buttons, SMS or Email"Verify by phone", "Verify by email"
Phone field hint"Enter your phone number ending in: " followed by the last four digits on file
Phone field placeholder"Enter your phone number."
Invalid number"Please enter a valid phone number."
ButtonNext

When Send OTP is selected, a consent notice appears above Next. The notice links to the HYPR Terms and Conditions and Privacy Policy pages. Its default text depends on the channel:

  • SMS: "By entering your phone number and clicking Next you consent to receive a one-time verification code from HYPR. Message and data rates may apply. You can reply HELP or contact" followed by the support email address configured for your tenant, then "For more information see Terms and Conditions and Privacy Policy."
  • Email: "By clicking Next you consent to receive a one-time verification code via Email from HYPR. For more information see Terms and Conditions and Privacy Policy."

If the typed number does not match the number on file, the screen shows "The phone number provided did not match the one on file." and the attempt counts toward the Retry Limit.

Contact screen showing The phone number provided did not match the one on file

Code Screen​

The code screen has six single-digit boxes. The first box has focus when the screen loads, pasting a code fills the boxes and entering the sixth digit submits the code.

The following table lists the code screen's default text for each state.

StateTitleMessageButton
Code sent by SMS"Check your text messages""Enter the code sent to your phone number ending in: " followed by the last four digitsVerify
Code sent by email"Check your email""Enter the code sent to your email address: " followed by the masked addressVerify
Wrong code"Code mismatch""The code you entered does not match the one sent to you."Resend
Code not sent"Send issue""Could not send an sms message to your phone number." or "Could not send an email to your email address."Resend
Verified by SMS"Phone verified""Your phone has been verified. Please proceed with your verification process by clicking Next."Next
Verified by email"Email verified""Your email has been verified. Please proceed with your verification process by clicking Next."Next
Check your email code screen with the masked email address and six code boxes Code mismatch screen with the Resend button

A code that is not six digits shows "Please enter a valid 6-digit verification code." After a wrong code, the requester clicks Resend to receive a new code.

Messages the Requester Receives​

The SMS reads "HYPR: Your verification code is 123456. Reply HELP to learn more. Reply STOP to end messages." With custom SMS branding, your organization's display name replaces "HYPR"; see SMS Notification Branding. For the email, see Email Notification Customization. A flow can also send and check codes through its own SMS or email service with the SMS Send Customization, SMS Verify Customization and Custom Email Sender assignments in Advanced Customization.

What Data Is Collected​

The step uses the mobile phone number and email address from the requester's directory record, the phone number the requester types and the channel the requester chooses.

The verification record keeps the channel used, the time the code was sent and whether the phone number match and the code check passed. Approvers see the channel, the phone number or email check and the OTP result on the scorecard.

Results, Retries and Failure Outcomes​

The step passes when every check for the configured channel passes: the phone number match, the code, or both. A phone number that does not match, a code that cannot be sent and a wrong code each count as one failed attempt, and Affirm counts each of the three separately. When the requester reaches the Retry Limit for any of them, the Failure Outcome applies.

This step's defaults are 3 attempts and Deny Verification. With Continue Workflow, the Verification Unsuccessful screen reads "We are unable to verify your information. You will be taken to the next step momentarily." For what each failure outcome does, including the redirect and escalation to live chat, see Injectable Outcomes and Retry Limits.