---
id: KB-GL-008
url: https://app.codecontract.io/help/glossary/what-is-a-one-time-code
idioma: en
categoria: glosario
subcategoria: firma
audiencia: usuario
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-CO-006, KB-GL-007]
citadoPor: [KB-GL-005]
---

# What is the code sent to your phone

_The most common second factor when signing, and why it adds so much._

**Responde a:** what is a one-time code · what is the code sent when signing for · the one-time code is not arriving · sms verification when signing

**One-time code** — A short number, valid for a few minutes and only once, sent to a channel only the signer controls — usually their phone — to check they are who they claim to be.

It does the same job as asking for ID at a counter: checking that the person in front of you is who they say. Only here, what is checked is access to a specific phone number.

## Why it adds so much

**En corto**

- An email can be read by anyone with access to that inbox.
- The code additionally requires holding the phone.
- It expires in minutes, so an old one is useless.

It is the difference between "someone with access to this inbox accepted" and "the person holding this phone accepted". In a dispute, the second sentence is far harder to argue with.

> [!WARNING]
> Never share that code with anyone, not even whoever sent you the document. No legitimate party will ask for it by phone: the code is yours and is typed into the screen, not dictated.

> [!NOTE]
> If it does not arrive, request another. Requesting another does not invalidate the document or force you to start again.

**How long does it last?**

A few minutes. After that you request a new one.

**Does receiving it cost anything?**

Not for the signer.

**What if I no longer have that number?**

Tell whoever sent the document so they can update the contact.

## Ejemplos

**Someone receives a call asking for the code that just arrived on their phone.**

- Does not give it
- Warns the company that sent the document

→ Prevents a third party signing in their name; the code was the only piece the caller was missing.

**A signer does not receive the code and cannot sign.**

- Checks the registered number and resends

→ The blockage clears without changing the document.

**The code is shared with a colleague so they can sign instead.**

- Explains the signature will stand in the name of whoever received the code

→ Each signature still points to one specific person.

**A mobile number is mistyped in the contact record.**

- Corrects the contact before resending the request

→ The code reaches whoever has to sign.

**Somebody phones asking for the code, posing as support.**

- It is not given and whoever sent the document is alerted

→ An attempt to sign in someone else's name is stopped.

**A signer with no signal cannot receive the message.**

- Agrees another verification route with whoever sent it

→ The signature is resolved without giving up the second factor.
