How do I require a one-time passcode on an onboarding link?
Last updated: June 16, 2026
Require a one-time passcode (OTP) so an employee confirms their identity — by email or SMS — before they can open an onboarding link and reach their tasks.
Before you start
Access to create onboarding links from an employee record.
The employee has an email address on file for email OTP, or a phone number for SMS OTP — whichever methods you allow.
Steps
Onboarding links are passwordless by default — there are no employee logins, so the employee opens the link and goes straight to their tasks. For compliance-sensitive onboarding — signed documents, I-9s, policy acknowledgments — you often need to confirm the person opening the link is who they say they are. A one-time passcode adds that check: before the employee reaches their tasks, they enter a short code sent to their email or phone.
Open
Create Onboarding Linkfor the employee.Set
Require OTP VerificationtoYes. TheAllowed OTP Delivery Methodsfield appears.Choose the methods under
Allowed OTP Delivery Methods—Email,SMS, or both. If you turn OTP on without choosing a method, Onboarded defaults toEmail.Set the
Delivery Methodfor the link itself — copy, email, or SMS — then create the link the way you normally would.
Delivery Method controls how the link reaches the employee. Allowed OTP Delivery Methods controls how the passcode reaches them. They're separate — you can email the link but require an SMS passcode, or any other combination.
The employee needs the matching contact detail on file. If you allow only SMS but the employee has no phone number, the passcode can't reach them. Allow Email as a fallback, or confirm the contact detail before you send.
What the employee sees
When the employee opens the link, Onboarded asks them to confirm their identity before showing any tasks. Onboarded sends a passcode to the email or phone you allowed, and the employee enters it to unlock their tasks. Each passcode is single-use.
Enforcing OTP on links you don't create by hand
Many onboarding links aren't created one at a time — they're generated by an integration (for example, when a placement runs in TempWorks) or by an automation. The same OTP settings apply there. An automation that creates an onboarding link carries its own Require OTP Verification setting, so you can require a passcode on every link the automation sends. For integration-generated links, OTP can be enabled by default and locked so it can't be switched off per link — your Onboarded implementation or support contact sets that up. Locking it keeps the identity check in place across every link and reduces the chance someone turns it off by accident.
Verify
Create a link to yourself: put your own email or phone on a test employee record, generate the link with Require OTP Verification set to Yes, and open it. You should be prompted for a passcode before you reach any tasks. If you're not prompted, OTP wasn't required on that link — reopen Create Onboarding Link and confirm Require OTP Verification is set to Yes.