Back to overview
Degraded

Authentication method selection not enforced on bank details & withdrawal flows

Jun 26, 2026 at 4:09am UTC
Affected services
Withdrawal
Sensitive Action Authentication
Authentication API

Updated
Jul 8, 2026 at 7:42am UTC

Authentication method switching (Email OTP, SMS OTP, PIN) is now fully functional and correctly syncs across all businesses under a merchant account. PIN setup via /dashboard/security/pin is also working as expected. Email OTP and SMS OTP are now correctly respected on the bank details update and withdrawal request flows.

One outstanding issue remains: when PIN mode is selected, the bank details and withdrawal flows incorrectly fall back to SMS OTP instead of presenting PIN entry. Email and SMS modes are unaffected. A fix is in progress and will be deployed shortly.

Updated
Jul 7, 2026 at 10:00pm UTC

We have identified the root cause. The bank details update and withdrawal request flows are hardcoded to SMS OTP and do not yet reference the merchant's saved authentication method preference. We are now implementing the fix to route these flows through the selected method (Email OTP, SMS OTP, or PIN). Work is in progress.

Created
Jun 26, 2026 at 4:09am UTC

We're rolling out support for multiple authentication methods (Email OTP, SMS OTP, PIN) for sensitive merchant actions. Currently, the bank details update and withdrawal request flows are still hardcoded to SMS OTP regardless of the method a merchant has selected. Merchants who choose Email OTP or PIN will still receive an SMS code instead. A fix to route these flows through the selected method is in progress.