Forgotten passwords are a surprisingly expensive problem. One mid-market services firm we worked with was hemorrhaging ₹80K yearly on password reset support tickets —emails, phone calls, manual account unlocks, all for a feature their clients didn't even need. Their client portal adoption was stuck at 35%. New clients would get invited, reset their password three times, give up, and call their account manager instead. The team was doing portal work twice: once in the system, once over the phone. Two weeks after they switched to SMS OTP (one-time passcode) login, adoption jumped to 68%. Support tickets for password resets went to zero. The math was simple: people will use a portal if it takes 10 seconds . Passwords take three minutes. Here's how they did it, what you need to watch, and when this approach actually works. Why passwords fail in client portals A password system has one job: keep the portal secure. It fails at a second, invisible job: getting clients to actually log in . The friction looks small on paper: Client receives invite email Client clicks link, lands on login page Client realizes they don't have a password yet Client clicks 'forgot password' or 'create account' Client receives reset email (check spam folder, wait 2 minutes) Client sets password, tries to remember it Client opens portal, forgets password by next week, repeats In practice, this sequence breaks at step 3. Your support team starts getting emails: "I never got a password reset link." "I have a password but can't log in." "Can you just tell me what my password is?" (No.) The firm we worked with tracked every reset request for a month. 73% came from clients who had logged in before —they simply forgot their password and took the path of least resistance: email support. SMS OTP eliminates the storage problem entirely. No password to remember. No reset link. Just: "What's your phone number?" → Text arrives → Client enters code → They're in. The adoption jump: 35% to 68% in 14 days The firm didn't launch OTP to everyone at once. They ran a soft rollout: Week 1: Offer OTP as an option alongside passwords (20 new clients invited, both methods available) Week 2: Send existing clients an email offering to switch; 60% opted in within 48 hours Week 3: Made OTP the default for all new invites; kept password as a fallback The jump from 35% to 68% happened between week 1 and week 2. Here's what changed: Metric Before OTP After OTP Portal adoption rate 35% 68% Time to first login 3.2 days 22 minutes Password reset tickets/month 12–15 0–1 Support cost/month ~₹6,600 ~₹300 The adoption jump wasn't random. OTP removes the single biggest friction point: password complexity and reset workflows. But adoption only sticks if your user communication is clear, your implementation is fast, and your fallback works when someone loses their phone. The implementation: four decisions you need to make first Before you launch OTP, nail these four things. They make or break the rollout. 1. SMS provider and delivery The firm tested two SMS providers before going live. OTP codes need to land in under 15 seconds . Anything slower and clients switch to the password fallback. They chose a provider with 99.8% delivery in their region (Southeast Asia). Cost: ₹0.50–₹1 per SMS. With 200 new client invites per month, that's ₹100–₹200/month. (Compare to ₹6,600/month in password reset support.) Make sure your SMS provider: Guarantees delivery time under 20 seconds for your region Handles international numbers (if you have remote clients) Logs every message sent (compliance, debugging) Costs less than what you're spending on password support 2. Code length and expiry The firm tested 4-digit, 6-digit, and 8-digit codes. Here's what they found: 4 digits: Too easy to guess. Rejected for security. 6 digits: Sweet spot. Easy to remember while typing. 1 million combinations. Hard to brute-force in 5 minutes. 8 digits: Annoying to type. No measurable security gain over 6. Expiry: 5 minutes . Long enough that a client won't panic if they're slow, short enough that a leaked code is useless after they've logged in. The firm tested 10 minutes and saw clients using old codes by mistake (wrong page refresh, back-button confusion). 5 minutes was the floor where this stopped happening. 3. Fallback for phone loss or unreachable numbers This is where most SMS OTP rollouts fail. What happens when a client says, "I changed my phone number" or "I'm traveling and my number doesn't work"? The firm built a three-tier fallback: Tier 1: Resend OTP to the same number (covers 80% of issues—slow network, phone off) Tier 2: Use an email-based OTP as backup (client clicks 'Didn't get the SMS?' → code sent via email) Tier 3: Account manager manual unlock (for lost phone or number change; takes 5 minutes, happens ~2× per month) Tier 2 is critical. It means you're not locking anyone out permanently. Email OTP is slower (2–3 minute delivery via Gmail), but it works globally. 4. Client communications: the 7