Skip to main content

Use One-Time Passcodes for Onboarding

NIM Onboarding

Use a one-time passcode (OTP) to verify a new user through their personal email address or mobile number before NIM activates their prepared account.

An OTP onboarding profile lets the user choose an available delivery method, enter the short-lived code NIM sends, set a password, and complete account activation. Use this approach when you have a reliable external contact method for every eligible person.

Before you configure OTPDirect link to Before you configure OTP

Onboarding profileA working onboarding profile and eligible-user data. Start with the onboarding guide if these are not ready.
Contact dataPersonal email and/or mobile number for each eligible user. Store phone numbers in international format, such as +12063332344.
Message servicesWorking email; for SMS, a configured SMS service and SMS license.
Onboarding AppThe current NIM Onboarding App package installed in your environment.
Do not use corporate contact details alone

The person may not yet be able to use the target account. Send verification messages to a personal email address or mobile number that can be accessed before onboarding is complete.

Configure the OTP flowDirect link to Configure the OTP flow

1. Add the delivery and confirmation formsDirect link to 1. Add the delivery and confirmation forms

  1. Open Configuration → Onboarding and select the profile that will use OTP.
  2. In Onboarding profile forms, add the Method form so the user can choose email or SMS, then add the Confirm form so they can enter the received code.
  3. Place Method and Confirm before the form that has Execute selected—normally the Password form.
  4. Set the form variables and onboarding variables to match the OTP pattern used by your installed Onboarding App. In older App configurations, the corresponding components may be named method_select and confirm_secret.

Make the delivery choice useful

NIM presents only delivery methods supported by the contact data available to the user. Configure both email and SMS only if the relevant fields are reliably populated.

2. Set code limitsDirect link to 2. Set code limits

Select the profile’s Settings tab to adjust confirmation-code behavior:

SettingWhy it matters
Code lengthBalances ease of entry with the strength of the code.
Time limitLimits how long a delivered code remains valid.
Maximum sendsLimits repeated code requests and helps control delivery volume.

Use values that match your organization’s security policy. Keep the validity window short enough to reduce risk while allowing for normal mail and SMS delivery delays.

3. Create the delivery notificationsDirect link to 3. Create the delivery notifications

Create an OTP notification template and event action for every enabled delivery channel.

Delivery channelEvent typeRecipient valueRequired code value
Emailonboarding-code-email{var.event.data.voConfirmationCodeAddress}{var.event.data.voConfirmationCode}
SMSonboarding-code-sms{var.event.data.voConfirmationCodeAddress}{var.event.data.voConfirmationCode}

For the template’s Notification Event, use the matching event and your onboarding-profile name, for example onboarding-code-mail: EmployeeOnboarding or onboarding-code-sms: EmployeeOnboarding. Replace EmployeeOnboarding with your actual profile name.

For the complete template and event-action instructions, see configure onboarding notifications.

4. Test as an end userDirect link to 4. Test as an end user

  1. Create or locate a safe test onboarding record with a personal email address and/or mobile number.
  2. Open the onboarding URL and select the available email or SMS option.
  3. Confirm that the code arrives at the selected address or number, then enter it before it expires.
  4. Complete the password form and verify that NIM activates only the expected target account.

Success looks like thisThe user can receive and validate one OTP through an approved delivery channel, set their own password, and sign in to the intended account—without a password being sent or shared by an administrator.

Build the complete onboarding journey
Prepare data, configure actions and notifications, then validate the end-to-end experience.

Gather additional user input
Collect information after verification and use it in the final onboarding action.

Test onboarding safely
Use a test record to validate lookup, verification, password change, activation, and sign-in.