Real OTPs sent over SMS or email don't scale across thousands of virtual users and can add messaging costs. Handle OTP flows using one of these approaches:
* Static OTP: Configure test accounts to accept a fixed OTP, such as 123456.
* Mock the OTP service: Point the OTP provider to a stub that returns a known value.
* Fetch via internal API: Call a test-only endpoint in your script to retrieve the generated OTP, then submit it.
* Skip the OTP step: Use pre-generated auth tokens from a CSV data file so VUs start already logged in.
Best practices:
* Assign a unique test account to each VU using a CSV data file to avoid session conflicts and rate limits.
* Enable OTP bypasses only in non-production environments.
If you're still unable to test your OTP flow, contact BrowserStack Support for assistance.