TL;DR: For a startup login flow, begin with a hosted SMS OTP API. It removes code generation, expiry, replay defense, and verification storage from the application. Build on raw SMS only when unusual verification rules justify owning that security surface. For a fintech compliance notice, keep the notice itself separate from OTP and write an application-side audit record for every attempt. Path Who owns the OTP template and verification state? Pick it when Main trade-off ...