Hacker News new | ask | show | jobs
by kevinold 683 days ago
Regarding SMS only auth, you should be cautious. Here's a blog with more detail: https://stytch.com/blog/totp-vs-sms.

As a suggestion for what to implement (I'm biased because I work there) but I'd encourage you to check out Stytch (https://stytch.com). We're an API-first authentication, authorization and fraud prevention B2C and B2B solution with several methods including email/password, email magic links, social logins and 2FA (OTP, TOTP).