What OTP, 2FA & Authentication Codes covers

This section covers one-time PINs, two-factor authentication and authenticator apps — the codes that arrive by SMS or appear in an app when you log in, pay for something or change an account detail.

Everything here rests on one rule, and it is worth stating before anything else.

Nobody legitimate will ever ask you for a one-time code. Not your bank. Not SASSA. Not your mobile network. Not a courier, an employer, a colleague, or anyone from a “fraud department”. A request for your code is the fraud, without exception.

The reason is simple once you see it. A one-time PIN exists to prove that the person completing an action is you. It is generated for your session and sent to you. An organisation that sent you the code already knows it and has no reason to ask. Someone who needs it from you is someone trying to complete an action on your account.

The second thing worth understanding is why an authenticator app is stronger than an SMS. Codes sent by text depend on your phone number, and a phone number can be transferred to a criminal through a SIM swap. Authenticator codes are generated on your device from a shared secret and never travel over the network, so a SIM swap does not reach them.

Browse individual used-for guides

Most searched questions in this topic

How the guides in this section differ

Delivery method. SMS codes, authenticator apps, push approvals and hardware keys all do the same job with meaningfully different security. The order of strength is roughly: hardware key, then authenticator app, then push, then SMS. Any of them is far better than none.

One-time code or standing PIN. An OTP is generated per action and expires within minutes. A banking or card PIN is a standing secret. Both should never be shared, but they behave differently and are covered separately.

Service-specific codes. SASSA and mobile network codes attract particular search interest in South Africa, largely because they are so heavily targeted by impersonation scams.

MethodStrengthWeakness
Hardware security keyStrongestCost; can be lost
Authenticator appStrong; resists SIM swapLosing the phone without backup codes
Push approvalGoodApproving out of habit without reading
SMS one-time PINBetter than nothingSIM swap, message interception
No second factorPassword aloneA leaked password is enough

Related topics and alternatives

Safety, accuracy and next-step checks

These guides follow official service-provider and cyber-safety guidance. They will never ask you to enter, forward or confirm a code.

Points worth carrying:

If you have shared a code, act immediately: contact the bank or service, change the password, and report it. Speed limits the damage.

Frequently asked questions

Can my bank ever ask for my OTP? No. Neither can SASSA, SARS, your network or an employer. There is no legitimate exception.

I received a code I did not request. What does that mean? Someone is likely trying to log in with your password. Do not enter or share it. Change the password and enable two-factor authentication.

Is an authenticator app better than SMS? Yes. Authenticator codes are generated on your device and are not exposed to SIM-swap fraud or message interception.

What happens if I lose my phone with the authenticator on it? This is what backup codes are for — save them when you set it up. Most services also offer an account recovery route, though it is slower.

Someone claiming to be from my bank says they need the code to stop a fraudulent transaction. Is that real? No. That is the scam, and it is among the most common in South Africa. End the call and phone the bank on the number on your card.