Authentication method selection not enforced on bank details & withdrawal flows
Updated
Jul 8, 2026 at 7:42am UTC
Authentication method switching (Email OTP, SMS OTP, PIN) is now fully functional and correctly syncs across all businesses under a merchant account. PIN setup via /dashboard/security/pin is also working as expected. Email OTP and SMS OTP are now correctly respected on the bank details update and withdrawal request flows.
One outstanding issue remains: when PIN mode is selected, the bank details and withdrawal flows incorrectly fall back to SMS OTP instead of presenting PIN entry. Email and SMS modes are unaffected. A fix is in progress and will be deployed shortly.
Affected services
Updated
Jul 7, 2026 at 10:00pm UTC
We have identified the root cause. The bank details update and withdrawal request flows are hardcoded to SMS OTP and do not yet reference the merchant's saved authentication method preference. We are now implementing the fix to route these flows through the selected method (Email OTP, SMS OTP, or PIN). Work is in progress.
Affected services
Created
Jun 26, 2026 at 4:09am UTC
We're rolling out support for multiple authentication methods (Email OTP, SMS OTP, PIN) for sensitive merchant actions. Currently, the bank details update and withdrawal request flows are still hardcoded to SMS OTP regardless of the method a merchant has selected. Merchants who choose Email OTP or PIN will still receive an SMS code instead. A fix to route these flows through the selected method is in progress.
Affected services