Your client portal went live. You sent invites. Users came. Then adoption flatlined at 20%, and support tickets exploded: "I forgot my password." "Your reset email never arrived." "I don't want to create another login." This isn't uncommon. A services firm in India deployed a portal with traditional email/password auth, watched 40% of users fail at the password-reset step, and saw adoption limp along at 20% for six weeks. Then they switched to SMS OTP—no signup, no password complexity rules, no reset flow. Adoption hit 65% in 60 days. The difference wasn't new features. It was removing friction. Password resets are a silent adoption killer, especially in markets where email reliability is poor or users manage dozens of login credentials. SMS OTP is simpler, faster, and in developing Asia–Pacific markets, far more reliable. This playbook walks through the cost, compliance, and UX mechanics that made it work. Why Passwords Fail at Scale in Client Portals Password-based auth creates a predictable failure cascade: Signup friction: Users create an account, set a complex password, and immediately forget it before the first login. Email unreliability: In many Southeast Asian markets, corporate email rules vary wildly. Some firms block password-reset emails; others delay them hours. Users assume the portal is broken. Support overhead: Each forgotten password becomes a support ticket. At 20% adoption, you're handling resets for everyone who tries once. Device switching: A client views an invoice on mobile, then tries to access the portal on desktop and gets locked out. They abandon both. The firm in this case found that 40% of signup attempts stalled at password reset. Of those, only 20% ever returned to the portal. The remaining 80% never logged in again. That's not a conversion problem; it's a retention cliff. SMS OTP Removes Signup and Memory Overhead SMS OTP flips the model. There's no signup, no stored password, no recovery flow: Client enters their phone number on the login page. System sends a six-digit code via SMS (expires in 10 minutes). Client enters the code. Session begins. No password ever stored. The friction drops to zero. Clients who already have your phone number in their CRM (because you called them or sent an invoice) can log in without friction. And because there's no password to forget, there's no reset email to wait for. In the case we're examining, this single change—removing the password step—bumped adoption from 20% to 65% in 60 days. Most of that lift came in the first two weeks, as soon as the SMS login went live. Users who had previously bounced off the portal came back, tried once, and it worked. No password, no reset email. Just a code and access. SMS OTP Cost: ₹0.50–₹1 Per Code, Scaled Affordably SMS OTP is cheaper than you think, especially in India and Southeast Asia. Per-message cost: Most Indian SMS providers (AWS SNS, Twilio, MSG91, Exotel) charge ₹0.50–₹1 per OTP sent. Some offer volume discounts; Twilio drops to ₹0.30–₹0.40 at scale. A WhatsApp OTP (if you use WhatsApp API instead of SMS) costs ₹0.80–₹1.20 but has higher delivery rates. Typical volume for a mid-market SaaS/services firm: 500 active portal users, 1 login per week = 2,000 OTPs/month = ₹1,000–₹2,000. 2,000 active portal users, 3 logins per week = 24,000 OTPs/month = ₹12,000–₹24,000. 10,000 active portal users, 2 logins per week = 80,000 OTPs/month = ₹40,000–₹80,000. Compare that to password reset email infrastructure, plus support hours spent on "I forgot my password" tickets. At 40% password-reset failure and 1 hour per ticket, that's significant cost recovery from just reducing support load. Compliance: DNC Lists, WhatsApp vs SMS, and Carrier Rules SMS OTP sits in a regulatory gray zone in most markets. It's not marketing; it's authentication. But you still need to scrub against DNC lists, honor carrier preferences, and choose between SMS and WhatsApp thoughtfully. India (DND/NDNC rules): The National Customer Preference Register (NCPR, governed by TRAI) forbids unsolicited commercial SMS. But SMS OTP for authentication is exempt—you're not marketing. Still, scrub all numbers against the DND registry before you send. Services like MSG91 or Twilio auto-scrub; make sure it's enabled. SMS vs WhatsApp OTP: WhatsApp OTP has higher delivery (98%+ vs 95% for SMS in congested networks) and costs ₹0.80–₹1.20. SMS is cheaper and works on any phone. If your user base spans feature phones and smartphones, stick with SMS. If most users are on WhatsApp, WhatsApp OTP is faster and more reliable. Carrier behavior: Some carriers prioritize SMS by type. OTP SMS gets higher priority than marketing SMS. Don't mix them; use a dedicated OTP sender ID (like "OTP") so carriers route them correctly. Generic sender IDs get throttled. Compliance best practice: Log every OTP sent—who, when, IP address, result. This becomes your audit trail if a customer disputes access or claims they didn't request a code. It's also useful for fraud detect