// the find
knadh/otpgateway
Standalone server for user address and OTP verification flows with pluggable providers (e-mail, SMS, bank penny drops etc.)
A standalone Go server from Zerodha that centralizes OTP/verification flows (email, SMS, bank penny drop, custom webhooks) behind one HTTP API and a drop-in JS widget. Useful for teams who want verification logic out of their main app and don't want to hand-roll rate limiting, expiry, and attempt counting themselves.
The address/OTP abstraction is genuinely clean — both are just opaque strings, so a bank penny-drop verification and an email OTP use the exact same API surface. The webhook provider means you can bolt on any SMS/email vendor without forking Go code, just point it at a JSON endpoint. It's been running in a real fintech (Zerodha) for KYC-adjacent flows, which is a stronger signal than most side-project auth tools. The built-in modal widget (otp.js) plus raw JSON API gives you a fast path and a build-your-own-UI path in the same package.
Redis is the only storage backend (internal/store/redis) — there's no SQL option, so OTP state durability is tied entirely to your Redis config, which is a rough fit for anything with audit requirements. Multi-tenancy is just BasicAuth with a namespace+secret pair; there's no visible per-request rate limiting beyond the max_attempts counter on an individual OTP. Provider configuration lives in a single static TOML file, so adding or rotating a provider means a redeploy, not an API call. Test coverage is thin — only handlers_test.go and redis_test.go exist, with no tests for the smtp, pinpoint, kaleyra, or webhook provider implementations that make up most of the actual integration surface.