Every verification channel trades the same four things differently: fraud resistance, latency, coverage, and cost. SMS OTP works on nearly every phone but rides a carrier message most a fraudster can social-engineer. Email OTP moves the attack surface from phone number to mailbox. WhatsApp OTP buys encrypted delivery where the app is installed. SNA (Silent Network Authentication, the CAMARA Number Verify pattern) proves device possession through the mobile data network itself, with no message at all. Passkeys replace the channel with an enrolled credential, and magic links collapse the code into a token the mailbox delivers. This post puts those seven side by side and then maps each one to the moment it belongs to in your flow: arrival, step-up, or sensitive access.
1. The decision table
| Channel | Fraud resistance | Typical latency | Coverage | Deliverability | Cost per attempt |
|---|---|---|---|---|---|
| SMS OTP | Moderate — exposed to SIM swap, rogue-base-station interception, and SMS-pumping traffic | Seconds | Any phone number, global | Depends on sender-identity registration and per-country routes | Per-message fee |
| Voice OTP | Moderate — same SIM-swap exposure as SMS, plus answering-machine disclosure | Seconds to a short call | Landlines and phones with message filtering | High for landline / filtered-message recipients | Per-minute call billing |
| Email OTP | Moderate — moves possession to the mailbox; phishable like SMS | Seconds | Anyone with an email address | Strongest of the message channels when domain authentication (SPF/DKIM/DMARC) is configured | Lowest message cost |
| WhatsApp OTP | Moderate-to-strong — app-level possession plus encrypted transport | Seconds | WhatsApp users only, high in regions where it dominates | High where the app is installed; template approval gates first sends | Per-conversation pricing |
| SNA possession-check | Strong among phone-bound channels — the carrier network confirms possession; a SIM-swap counter for the numbers it covers | Sub-second to seconds | Numbers on supported carrier networks | No message to deliver — the check runs on the data connection | Per-lookup fee, no delivery cost |
| Passkeys / WebAuthN | Strongest of the seven — phishing-resistant enrolled credential bound to the user agent | Device-local, sub-second | Browsers and platforms with WebAuthN support | No delivery step after enrollment | No per-attempt delivery cost; enrollment is the investment |
| Magic links | Similar to email OTP — mailbox possession is the whole proof | Seconds | Anyone with an email address | Matches email OTP | Matches email OTP |
Read the table as a trade-space, not a ranking. SMS OTP wins coverage. Email OTP wins cost. SNA wins fraud resistance among phone-bound methods, when the carrier network supports it. Passkeys sit in a stronger class — they drop the channel step entirely, at the price of an enrollment.
2. Where each fires
Arrival moments — signup, first login, returning login — care most about coverage and friction. SMS OTP carries the highest UX floor here: every phone number works, the user retypes six digits, no enrollment, no mailbox. Choose SMS at arrival, with email OTP as the classic fallback when a number isn't supplied.
Step-up moments — the mid-session second factor, checkout confirmation, risky-payment approval — care most about assurance without another delivery hop. SNA is the strongest step-up proof available among phone-bound methods: the carrier network asserts possession, SIM-swap risk collapses, and the user sees nothing. Where SNA is unavailable, an OTP chain graded by channel (WhatsApp, then SMS, then voice) gets the user through.
Sensitive moments — credential grants, payouts, device binding, admin access — justify the strongest proof of the seven. Passkeys/WebAuthN replace the whole channel model with an enrolled asymmetric credential; OTP channels only stage the enrollment link that gets the user to the passkey. Magic links belong on the login-arrival side: the one-click email token where session risk is bounded.
3. Devotel Orbit wiring: one endpoint, seven-plus channel choices
Orbit's Verify API exposes the channel set behind one endpoint — POST /verify/send. The channel field takes sms, whatsapp, email, voice, viber, rcs, flashcall, sna, or magic_link, plus possession-factor channels (totp, push, backup_code); an SNA attempt expects a device-bound token supplied as deviceToken. Get a code into the user's hands in five steps with the Node SDK over at Send Your First Verify OTP With the Devotel Node SDK, and if you want Orbit's verify surface ranked against the rest of the market, the best verification/OTP APIs ranked listicle is the vendor-comparison hop. A per-channel fallback chain — a channels array on the same endpoint — is how a single send degrades from, say, WhatsApp to SMS to voice without the application re-dispatching.
4. SIM-swap mitigation — pair the channel with a pre-send lookup
When you do pick a phone-bound channel, SIM-swap exposure is the price of possession proofs over carriers. Orbit's mitigation runs pre-send: a number lookup confirms validity and reachability and fires the SIM-swap check before the code goes out. The pre-send pattern is walked end to end in Phone-Number Lookup and SIM-Swap Pre-Send, and the term-level anchor sits in the glossary under SIM swap API. Run the check where the flow can afford the fractions of a second it costs — payouts, device binding, and recovery especially.
Frequently asked questions
Which channel should be the default for a new flow?
SMS OTP at arrival, with an explicit fallback chain — typically WhatsApp or email as the second rung. That covers the widest phone population and costs the least per attempt among message channels.
When does SNA beat an OTP channel?
When the carrier network supports the check, when delivery failure is the failure you see most, and when a SIM-swap answer outweighs a few-tenths of a lookup fee. Step-up moments fit this best.
Do passkeys replace the Verify API's OTP channels?
They replace the OTP hop after enrollment. The OTP channels still do the work passkeys can't reach — first-party contactability at arrival and a delivery path to the enrollment itself.
Is a magic link safer than an email OTP?
Same possession proof, slightly different UX surface. A magic link validates a token from the mailbox rather than a retyped code, so choose by how you want the return path to look.
How do I turn on SNA in Orbit's Verify send?
Set channel: "sna" on POST /verify/send and supply the device-bound token as deviceToken. Without the token the attempt can't run — the channel doesn't fall back silently.
Where does voice OTP earn its slot in a fallback chain?
Landlines, message-filtering recipients, and screen readers. It bills per minute like any phone call, so it typically sits behind the SMS rung rather than before it.