0 Your Cart $0.00

Cart (0)

No products in the cart.

OTP Authentication

$39.00   $39.00
(Excluding VAT 14.5%)

Adds OTP-based two-factor authentication (2FA) to Botble CMS. Supports email delivery via the built-in Botble email system and SMS delivery via the SH SMS Notifier plugin. Works for admin/staff users, customers (ecommerce), and vendors.

In stock

Need Update?


Need Support?

SKU: SHNX-83324-9BBK6
Categories: Plugins, Botble Plugins
Instant Delivery
Instant Delivery
For all digital products
24/7 Dedicated Support
24/7 Dedicated Support
Anywhere & anytime
Secure Payment
Secure Payment
Guarantee secure payments

Adds OTP-based two-factor authentication (2FA) to Botble CMS. Supports email delivery via the built-in Botble email system and SMS delivery via the SH SMS Notifier plugin. Works for admin/staff users, customers (ecommerce), and vendors.

Features

  • OTP challenge injected into the admin login pipeline (zero login-form changes).
  • OTP challenge intercepted at the customer login response (ecommerce).
  • Per-user enable/disable toggle on the admin profile page.
  • Configurable OTP length (4–8 digits), expiry, resend cooldown, and max attempts.
  • OTP codes stored as SHA-256 hashes — plain codes never persisted.
  • Email delivery via Botble's EmailHandler with a fully editable template.
  • SMS delivery via SH SMS Notifier (SmsHandler::sendUsingTemplate()); SMS toggle auto-disables when SSN is not installed.
  • Comprehensive OTP audit log (otp_logs table).

Requirements

  • Botble CMS ≥ 7.0.0
  • SH SMS Notifier plugin (optional — required for SMS OTP only)
  • Ecommerce plugin (optional — required for customer OTP)

Installation

  1. Copy the otp-auth folder into platform/plugins/.
  2. In the admin panel go to Plugins and activate OTP Authentication.
  3. Run migrations if activation does not trigger them automatically:
php artisan migrate --path=platform/plugins/otp-auth/database/migrations
  1. Publish assets:
php artisan vendor:publish --tag=otp-auth-assets

Configuration

Navigate to Admin → Settings → Others → OTP Authentication.

SettingDefaultDescription
Enable OTP AuthenticationOffMaster switch
Enable Email OTPOnSend code via email
Enable SMS OTPOffSend code via SMS (requires SH SMS Notifier)
OTP Length6Digits in the code (4–8)
OTP Expiry10 minHow long a code stays valid
Resend Cooldown60 sMinimum gap between resend requests
Max Attempts5Failed attempts before OTP is invalidated
Enable for Admins & StaffOnRequire OTP on admin login
Enable for CustomersOffRequire OTP on customer login
Enable for VendorsOffRequire OTP on vendor login

Email Template

The OTP email is managed through Admin → Settings → Email → OTP Authentication.

Available template variables:

VariableDescription
{{ user_name }}Recipient's display name
{{ otp_code }}The one-time verification code
{{ expiry_minutes }}Minutes until the code expires
{{ site_title }}Site name

SMS Template

The OTP SMS template is managed through SH SMS Notifier → Templates → otp_code.

Available variables:

VariableDescription
{{code}}The one-time verification code
{{expiry}}Minutes until the code expires

Default template: Your verification code: {{code}}. Valid for {{expiry}} minutes. Do not share this code.

If the SH SMS Notifier plugin is not installed, the SMS OTP toggle is hidden and a notice is shown in settings.

Per-User OTP Preference

Each admin user can override the global role setting from their profile page:

  • Admin → Profile → OTP Security
  • Options: follow global default, explicitly enable, or explicitly disable OTP for their account.

Per-user preferences are stored in the otp_user_preferences table (polymorphic, supports both admin users and customers).

Database Tables

TablePurpose
otp_codesActive and used OTP codes (SHA-256 hashed)
otp_logsAudit log of all OTP actions (sent, verified, failed, expired, blocked)
otp_user_preferencesPer-user OTP enable/disable overrides

Delivery Logic

  1. Effective method is resolved from settings (email, sms, or both).
  2. If SMS is selected but SH SMS Notifier is not installed, falls back to email.
  3. Both channels attempt delivery when method is both.
  4. If neither channel succeeds, email is retried as last resort (if email is enabled).

Uninstall

Deactivate the plugin from Admin → Plugins → OTP Authentication → Deactivate. All settings, OTP codes, logs, and user preferences are removed automatically.

Changelog

2.0.1

  • Per-user OTP preference toggle on the admin profile page.
  • Botble EmailHandler integration (editable email template in admin).
  • SH SMS Notifier SmsHandler integration (editable SMS template in SSN).
  • Removed custom SMS gateway — SMS exclusively via SH SMS Notifier.
  • Removed custom template editor — all templates managed through standard Botble / SSN interfaces.
  • Plugin appears only in Settings > Others (no admin sidebar entry).
  • SHA-256 code hashing, OTP audit log, and graceful null safety on deleted users.

 

Product Name OTP Authentication
Version 2.0.1
File Type zip
Last Updated 25/05/2026
Compatible Browsers Google Chrome, Mozilla Firefox, Microsoft Edge, Safari, Opera
Framework Laravel
Programming Language PHP
Required Software PHP, Node.js
PHP Version 8.1+
Framework Laravel 10+
Database MySQL 8+
Server Type Apache / Nginx
SSL Certificate
Cron Job Required
File Permissions 755 / 777
Minimum Browser Version Chrome 90+
JavaScript Enabled

Add your review

Your email address will not be published. Required fields are marked *

Please login to write review!

Looks like there are no reviews yet.

Related products

Live Chat Offline

Hi there! How can we help you today?

Glad you’re here.