Portal adoption was stuck at 40%. Your clients signed contracts, but fewer than half actually logged in to upload documents, view invoices, or track project status. Email password reset links sat in spam. Passwords were forgotten within days. The portal you built was technically sound but behaviorally broken. Then we tested SMS OTP login—not as a nice-to-have, but as the primary path. Adoption doubled to 80% in 48 hours. This playbook shows you exactly how we measured it, what we tested, and what it actually costs. You don't need to replicate every detail, but the methodology is what lets you know whether SMS OTP will work for your specific user base. Why SMS OTP wins where passwords fail Passwords fail for a single reason: friction compounds across three decisions. First, the user receives an email. Half never see it (spam folder, wrong inbox, deleted by mistake). Second, if they do find it, the reset link expires in 24 hours—and they clicked it at 2am on Thursday and forgot by Friday morning. Third, the new password is either so weak they forget it immediately, or so complex they store it in a note they lose. SMS OTP short-circuits all three. The code lands in the device they use every day. It expires in 10 minutes—enough time to copy and paste, short enough that there's no 'I'll do this later' decision. No password to remember or reset. The friction is asymmetric: SMS takes 20 seconds. Email takes 3–5 minutes and fails half the time. Behavior follows. In our test, 40% of invited users logged in with email reset links. When we switched to SMS OTP as the default (keeping email as fallback), 80% logged in within 48 hours. No change to the portal itself. No feature additions. Just a removal of friction at the entry point. Setting the baseline: measure before you change anything You need three numbers before you run any test. First: invitation send date and count. Export your portal invitations from the past 30 days. Record the exact date sent, email address, and invitation status (sent, bounced, accepted, expired). If your platform doesn't track this natively, add it. You can't measure what you don't record. Second: login conversion by day. For each invitation cohort, measure the percentage that logged in within 1 day, 3 days, 7 days, and 30 days. Plot this as a line chart. Our baseline looked like this: Day 1: 8% logged in Day 3: 18% logged in Day 7: 28% logged in Day 14: 35% logged in Day 30: 40% logged in This is your control. Everything else is measured against it. Third: what they do after login. Track not just login count, but login depth. Did they log in once and vanish? Did they upload a document? Did they download an invoice? Did they take an action? Fractional adoption (logging in but doing nothing) is worthless. Measure the funnel: logins → document upload, contract signature, or payment. Our baseline showed 40% login adoption, but only 22% of those actually took action within 7 days. Do not skip the baseline. Without it, you cannot measure lift. With it, you have proof that SMS OTP worked—or didn't—for your specific user base. The test: SMS OTP as default, email as fallback Run this test on a single new cohort of 200–500 invitations. Do not retrofit your existing users; new users haven't yet failed at email, so they have no bias. Technical setup (2 hours): Add an SMS field to your invitation form. Require it. Validate the format (country code + digits). For SE Asia, accept +60, +65, +62, +84, +66 prefixes and reject anything else. Integrate with an SMS OTP provider. Twilio, AWS SNS, or Infobip work. Call the API on login: generate a 6-digit code, send it via SMS, expire it in 10 minutes. On the SMS OTP form, show three inputs: one for each digit pair (XX-XX-XX). This forces deliberate entry and prevents paste-and-skip errors. After three failed attempts, lock the session for 5 minutes and offer email fallback. Log every send, entry attempt, and success. You'll need this data to debug SMS carrier issues. Carrier testing (essential, often missed): SMS delivery varies wildly by carrier in SE Asia. Singtel and Celcom in Malaysia work reliably. Telkomsel in Indonesia has a history of OTP filtering—they block high-volume OTP streams. Viettel in Vietnam may throttle. Grab your test device and invite people on each carrier in your target market. Send them a test code. Measure time to delivery and success rate. Telkomsel (Indonesia): Test with a dedicated short code (1234) or ask Telkomsel to whitelist your sender ID. Generic codes often fail. Singtel (Singapore): Reliable. Standard setup works. Celcom (Malaysia): Reliable. Standard setup works. Globe (Philippines): Test OTP delivery; some variants throttle high volume. This takes 2–3 hours but saves you weeks of 'why don't they get the code' confusion later. The test window: 7 days. Send invitations with SMS OTP as default to your test cohort. Track login conversion daily. Compare against your baseline using the same metrics: login rate by day 1, 3, 7. A