A mid-sized digital agency in Bangalore had a problem that looked like a tech issue but wasn't. They'd built a slick client portal—real-time project tracking, invoice history, payment receipts—and nobody used it. After 90 days, active users sat at 18%. Clients were ignoring reminder emails, payment deadlines were slipping, and the accounts team was manually chasing down ₹4L in unpaid invoices. The issue wasn't the portal. It was how clients got into it. The password reset trap: why friction kills adoption The portal required login credentials. Standard stuff: email, password. But "standard" is exactly the problem. Here's what actually happened when clients received an invite link: Click the link. Create a password (or use their password manager, which often fails on custom apps). Confirm the password. Receive a confirmation email. Click the confirmation link. Log in again. By step 3, half of the invited clients had abandoned the flow. By step 6, 82% had moved on. Password reset requests piled up. Support tickets multiplied. The agency's customer success team was spending 4+ hours per week resetting forgotten credentials for clients who had visited the portal once, if at all. The team had inadvertently built a friction machine that made paying invoices harder, not easier. The three-tier adoption reality: password vs OTP vs sessionless SMS Authentication methods aren't all equal. Real-world adoption tells a clear story: Password-based portals: 18% active user rate. Clients set a password on day one and forget it by day two. Support cost is high. Adoption velocity is flat. SMS OTP (one-time password) portals: 56% active user rate. A significant jump. Clients receive a text, enter a six-digit code, and land in the portal. No password to remember. But the OTP flow still takes 2-3 minutes per session and expires in 10 minutes, creating urgency anxiety. Sessionless SMS links (no OTP, no password): 78% active user rate. A single text arrives with a magic link. One click. Instant access. Session persists for hours or days. The friction floor drops to near zero. This wasn't the agency's hypothesis. It was their measured outcome after testing each approach with different cohorts of clients over three weeks. How the agency made the switch in 48 hours The technical lift was smaller than expected because the agency wasn't building authentication from scratch. They were swapping one login method for another on an existing portal. Day 1 (4 hours): The team mapped the current authentication flow—password entry, backend validation, session creation. They identified the exact place to intercept: instead of prompting for a password, prompt for a phone number. Day 1 (3 hours): Backend logic: receive phone number → generate a cryptographic token → store it in Redis with a 24-hour expiration → send an SMS with a clickable link that includes the token → link validates the token and creates a session → redirect to the portal. Day 1 (2 hours): QA and staging. Test the SMS delivery, verify the link works from desktop and mobile, confirm the session persists across page reloads, check that expired tokens show a clear error message. Day 2 (2 hours): Migrate the password table. Existing client records were updated to point to the new SMS login method. Old passwords were retained (but unused) in case a client ever needed account recovery. Day 2 (2 hours): Roll out to 10% of the client base as a canary. Monitor SMS delivery, track click-through rates, log any errors. Day 2 evening: Roll out to 100% of active clients. Send a single SMS to each: "Your invoice is ready. View it here: [link]." No password to set. No confirmation email. One tap. The entire process—scoping, coding, testing, deployment—took 13 hours across two calendar days. Not because it was simple, but because the team already owned the codebase and authentication layer. A custom-built portal can do this quickly. A third-party portal often can't. The results: ₹4L to ₹80K in 48 hours On day 3, the metrics moved: SMS delivery rate: 94% (carrier bounce-backs accounted for the 6%). The team sent retries to failed numbers on day 4, pushing delivery to 99%. Link click-through rate: 67% within 12 hours. Compare that to the 18% who had ever logged in before. Portal session duration: 8 minutes (clients actually reviewing invoices, project status, payment history). Password portals averaged 2 minutes—most were failed login attempts. Invoice payment rate: within 48 hours, ₹3.2L of the outstanding ₹4L was paid or scheduled. The remaining ₹80K was genuinely disputed or delayed for other reasons. The biggest win wasn't just the money collected. It was the shift in client behavior. Clients stopped calling to ask "How do I log in?" and started proactively viewing invoices before asking payment questions. The support team reclaimed 8 hours per week. The accounts team went from reactive collection to predictable cash flow. 30 days later, active monthly users stabilized at 71%—slightly lower th