Email OTP Two-Factor Authentication
Add a secure email verification step to Paymenter logins with Email OTP Two-Factor Authentication.
The extension requires users with verified email addresses to confirm their login using a single-use email code before an authenticated session is created. Users who already use Paymenter’s authenticator-based 2FA can choose between their authenticator app and email OTP without replacing the native 2FA system.
Features
- Secure 6–8 digit email OTP codes
- Authenticator app or email OTP method selection
- Single-use codes with configurable expiration
- Resend cooldown and maximum resend limits
- Configurable failed-attempt limits and lockout duration
- Optional IP binding to prevent verification from a different network
- User and IP-based rate limiting
- OAuth login protection
- Remember-me login support
- Optional trusted browsers with configurable expiry
- Secure, revocable trusted-browser tokens
- Whitelist entries with activation, expiry, and admin notes
- Redacted OTP values in administrator-visible email logs
