
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
sms-otp-using-myphone
Advanced tools
Twilio Verify alternative for developers. Send and verify SMS OTP codes from your own phone — no Twilio, no Vonage Verify, no MessageBird. No per-OTP fee, no markups, no A2P 10DLC. CLI for 2FA, phone verification, login flows, CI tests. Free 5-day trial a
Send SMS OTP codes using your own phone. No Twilio. No Vonage. No per-OTP fee. Pair your Android phone with the SMS8 cloud and generate, send, and verify one-time codes from any script, server, CI job, or AI agent.
npx sms-otp-using-myphone send +14155550100
# → 6-digit code arrives via your real phone number
CPaaS providers (Twilio Verify, Vonage Verify, MessageBird Verify) charge $0.05 to $0.10 per OTP attempt and require A2P 10DLC registration in the US. At any meaningful signup volume that's hundreds of dollars per month before you've shipped a single feature.
This package routes OTP SMS through the Android phone you already own:
wait command — block until the next code arrives on your test SIM# One-off
npx sms-otp-using-myphone send +14155550100
# Or install globally
npm install -g sms-otp-using-myphone
sms-otp send +14155550100
Node 18 or newer.
export SMS8_API_KEY=sk_xxx
# Send a code (defaults: 6 digits, 5 min expiry, 5 attempts, 60s resend cooldown)
sms-otp-using-myphone otp send +14155550100
# Verify a code the user typed in
sms-otp-using-myphone otp verify +14155550100 482937
# → { "verified": true }
# Block until an SMS code arrives on a paired Android (handy in tests)
# Pass the sender phone (or partial match) — e.g. the bank or Google
CODE=$(sms-otp-using-myphone otp wait +Google --contains="Google" --timeout=180)
echo "Got: $CODE"
The shorter alias
sms-otpworks for every command shown above (e.g.sms-otp otp send +1234).
Tune length, expiry, template, and attempt limit at send time:
sms-otp-using-myphone otp send +14155550100 --length=8 --expires-in=180
sms-otp-using-myphone otp send +14155550100 --template="Your YourApp code: {code}"
sms-otp-using-myphone otp send +14155550100 --max-attempts=3
By default SMS8 sends through your primary paired Android. To pin a specific phone or SIM slot (dual-SIM Androids), or to broadcast:
sms-otp-using-myphone otp send +14155550100 --device-id=10700
sms-otp-using-myphone otp send +14155550100 --device-id=10700 --sim-slot=2
sms-otp-using-myphone otp send +14155550100 --devices=10700,10701|0
sms-otp-using-myphone otp send +14155550100 --option=1 # broadcast all devices
sms-otp-using-myphone otp send +14155550100 --option=2 # broadcast all SIMs
sms-otp-using-myphone otp send +14155550100 --random-device
The same routing flags work on otp wait (which Android device & SIM should watch
for the incoming code). Run sms-otp-using-myphone devices to list device IDs.
otp verify does not take routing flags — the code lives server-side, not on a SIM.
#!/usr/bin/env bash
read -p "Phone (E.164): " PHONE
sms-otp-using-myphone otp send "$PHONE"
read -p "Code: " CODE
if sms-otp-using-myphone otp verify "$PHONE" "$CODE" | grep -q '"verified": true'; then
echo "Welcome!"
else
echo "Wrong code. Try again."
fi
# Trigger your app to send an OTP
curl -X POST https://staging.your-app.com/otp -d 'phone=+14155550100'
# Block until the code arrives on the test SIM (max 3 minutes)
CODE=$(sms-otp-using-myphone wait +14155550100 --timeout=180)
# Submit it to your app
curl -X POST https://staging.your-app.com/verify -d "phone=+14155550100&code=$CODE"
| Setting | Default |
|---|---|
| Code length | 6 digits |
| Expiry | 5 minutes |
| Max attempts | 5 |
| Resend cooldown | 60 seconds |
| Per-phone cap | 5 OTPs per 24 h |
Configurable via the API. See the OTP API docs.
sms8-cli — full SMS + OTP CLI (same backend)sms8-mcp — let Claude / Cursor / Windsurf send OTPs through your AI agentphone-sms-gateway — phone-as-gateway brandMIT
FAQs
Twilio Verify alternative for developers. Send and verify SMS OTP codes from your own phone — no Twilio, no Vonage Verify, no MessageBird. No per-OTP fee, no markups, no A2P 10DLC. CLI for 2FA, phone verification, login flows, CI tests. Free 5-day trial a
The npm package sms-otp-using-myphone receives a total of 27 weekly downloads. As such, sms-otp-using-myphone popularity was classified as not popular.
We found that sms-otp-using-myphone demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.