Phone Number / Email Verification
The Phone Number / Email Verification step in HYPR Affirm confirms that the requester controls the phone number or email address that your directory holds for them. Depending on its settings, the step checks a phone number the requester types against the number on file, sends a one-time password (OTP) to that phone number or to the email address on file, or both.
Prerequisites
The requester's directory record must hold a mobile phone number for the SMS channel and for the phone number match, or an email address for the email channel. See Identity Provider Prerequisites.
Configure the Step
The step card reads Choose how to verify user contact details and whether to send a one-time passcode (OTP) for Identity Verification during this step of the workflow. A new verification flow includes this step. The following table lists its settings.
| Setting | What It Does | Allowed Values | Default |
|---|---|---|---|
| Send OTP | Sends a six-digit code that the requester must enter | Checkbox | Cleared |
| Contact Preference | Where the code goes; available when Send OTP is selected | SMS, Email or SMS or Email | SMS |
| Retry Limit | Number of failed attempts allowed before the failure outcome applies | 1 to 10 attempts, within 0 to 60 minutes in 5-minute steps | 3 attempts within 0 minutes |
| Failure Outcome | What happens when the retry limit is reached | Deny Verification, Redirect to URL or Continue Workflow (optionally with Escalate to Live Chat) | Deny Verification |
The settings combine as follows:
- Send OTP cleared: the requester types their mobile phone number and Affirm compares it with the number on file. No code is sent.
- SMS: the requester types their mobile phone number. When it matches the number on file, Affirm texts a code to it.
- Email: the requester does not type anything. Affirm emails a code to the address on file.
- SMS or Email: the requester chooses Verify by phone or Verify by email, then continues as for SMS or Email.
When your tenant uses the Affirm Risk Policy Builder, the assigned Policy Evaluation Kit sets retries and failure outcomes instead of the Retry Limit and Failure Outcome controls.
What the Requester Sees
The step has two screens: the contact screen and, when Send OTP is selected, the code screen.
Contact Screen
The contact screen shows the title for the configured channel. For SMS it also shows the last four digits of the number on file, for example "Enter your phone number ending in: 0100." The phone field has a country-code picker, and Next stays disabled until the number is a possible phone number for the selected country. Starting in HYPR 11.3.6, an email address shown to the requester at this step is masked, leaving only the first and last characters of the part before the @.
The following table lists the default text. Administrators can change it in Affirm Studio.
| Element | Default Text |
|---|---|
| Title, SMS | "Let's verify your phone" |
| Title, Email | "Let's verify your email" |
| Title, SMS or Email | "Let's verify your phone or email" |
| Description, SMS or Email | "Please select your preferred method of contact for verification." |
| Choice buttons, SMS or Email | "Verify by phone", "Verify by email" |
| Phone field hint | "Enter your phone number ending in: " followed by the last four digits on file |
| Phone field placeholder | "Enter your phone number." |
| Invalid number | "Please enter a valid phone number." |
| Button | Next |
When Send OTP is selected, a consent notice appears above Next. The notice links to the HYPR Terms and Conditions and Privacy Policy pages. Its default text depends on the channel:
- SMS: "By entering your phone number and clicking Next you consent to receive a one-time verification code from HYPR. Message and data rates may apply. You can reply HELP or contact" followed by the support email address configured for your tenant, then "For more information see Terms and Conditions and Privacy Policy."
- Email: "By clicking Next you consent to receive a one-time verification code via Email from HYPR. For more information see Terms and Conditions and Privacy Policy."
If the typed number does not match the number on file, the screen shows "The phone number provided did not match the one on file." and the attempt counts toward the Retry Limit.
Code Screen
The code screen has six single-digit boxes. The first box has focus when the screen loads, pasting a code fills the boxes and entering the sixth digit submits the code.
The following table lists the code screen's default text for each state.
| State | Title | Message | Button |
|---|---|---|---|
| Code sent by SMS | "Check your text messages" | "Enter the code sent to your phone number ending in: " followed by the last four digits | Verify |
| Code sent by email | "Check your email" | "Enter the code sent to your email address: " followed by the masked address | Verify |
| Wrong code | "Code mismatch" | "The code you entered does not match the one sent to you." | Resend |
| Code not sent | "Send issue" | "Could not send an sms message to your phone number." or "Could not send an email to your email address." | Resend |
| Verified by SMS | "Phone verified" | "Your phone has been verified. Please proceed with your verification process by clicking Next." | Next |
| Verified by email | "Email verified" | "Your email has been verified. Please proceed with your verification process by clicking Next." | Next |
A code that is not six digits shows "Please enter a valid 6-digit verification code." After a wrong code, the requester clicks Resend to receive a new code.
Messages the Requester Receives
The SMS reads "HYPR: Your verification code is 123456. Reply HELP to learn more. Reply STOP to end messages." With custom SMS branding, your organization's display name replaces "HYPR"; see SMS Notification Branding. For the email, see Email Notification Customization. A flow can also send and check codes through its own SMS or email service with the SMS Send Customization, SMS Verify Customization and Custom Email Sender assignments in Advanced Customization.
What Data Is Collected
The step uses the mobile phone number and email address from the requester's directory record, the phone number the requester types and the channel the requester chooses.
The verification record keeps the channel used, the time the code was sent and whether the phone number match and the code check passed. Approvers see the channel, the phone number or email check and the OTP result on the scorecard.
Results, Retries and Failure Outcomes
The step passes when every check for the configured channel passes: the phone number match, the code, or both. A phone number that does not match, a code that cannot be sent and a wrong code each count as one failed attempt, and Affirm counts each of the three separately. When the requester reaches the Retry Limit for any of them, the Failure Outcome applies.
This step's defaults are 3 attempts and Deny Verification. With Continue Workflow, the Verification Unsuccessful screen reads "We are unable to verify your information. You will be taken to the next step momentarily." For what each failure outcome does, including the redirect and escalation to live chat, see Injectable Outcomes and Retry Limits.
Related
- Configure Verification Steps: table of all verification steps
- Injectable Outcomes and Retry Limits: retry and failure-outcome configuration
- Identity Provider Prerequisites: the mobile phone number or email address this step requires
- SMS Notification Branding: customize SMS OTP content
- Email Notification Customization: customize email OTP content