Hello!!
A few days ago we released SMS Auth for login meaning that you could set up two-factor authentication using a phone and SMS.
Today we are going 1 step further. From now you can log in just with your phone number! no need for email. We will send you an SMS to the phone attached to your account and if the code is correct you will be logged in ;)
But that's not all! We have also released registering with the phone!
- The user inputs his phone
- We send him an SMS
- He enters the code, if valid
- We ask for an email
- User registered ;)
Running SMS login safely in 2026: what changed and what to set up
Phone login and phone registration are still part of Yclas. Today you switch them on in your admin under Panel > Integrations > 2Factor: add your 2Factor API key, then turn it on. Once it is active, a phone registration form appears with the normal sign-up form and a phone login option appears on the login page. Clickatell, used in our earlier SMS article, is no longer offered in the admin. Two things have changed since 2022, and both affect how you should run this feature.
1. SMS codes are now a "restricted" authenticator
The US National Institute of Standards and Technology finalized SP 800-63B-4 in 2025. It names sending codes over the phone network (SMS or voice) as the only "restricted" authenticator. You can still use it, but NIST says services should:
- offer at least one alternative that is not restricted;
- tell users about the risks of SMS and about the safer option;
- use codes of at least six digits, used within 10 minutes;
- allow no more than 100 consecutive failed attempts;
- consider risk signals such as SIM changes, device swaps and number porting, which are how attackers take over phone numbers.
Yclas already covers the first point: its two-step login also works with Google Authenticator. Treat SMS as the easy option for buyers, and encourage admins, moderators and high-volume sellers to use an authenticator app.
2. SMS pumping fraud can run up your bill
Any public form that sends a text can be abused. Twilio describes SMS pumping as fraudsters requesting large numbers of text messages from unprotected forms, using phone numbers they can make money from, while your business pays for every message sent. Your phone registration form is exactly that kind of field. Twilio's prevention checklist recommends:
- blocking SMS to countries where you have no users;
- rate limits per user, per IP address and per number prefix, with growing delays between repeat requests;
- tracking the ratio of verified codes to codes sent, and alerting when it suddenly drops;
- bot protection on the form and alerts when usage spikes.
Quick setup checklist
- If your SMS provider allows it, restrict sending to the countries your marketplace serves and set a low-balance alert.
- Keep in mind that the phone sign-up and phone login forms do not show a CAPTCHA of their own, so the limits at your SMS provider are your main protection.
- Check your SMS provider's delivery log weekly. A spike in codes sent with no new accounts to match is the classic sign of pumping.
- Mention Google Authenticator on your help page so users who care about security have a stronger option.
I hope you find this functionality useful and that you enjoy it!