Loading
View Categories

How does One-Time Password (OTP) verification protect ProVide shared links?

ProVide 17.3.1 adds one-time password (OTP) verification for shared links, confirming exactly who opens, uploads to, or edits a link with a 6-digit code sent to their email, no account or corporate login required.

It’s part of Share and Collaborate, available from the Maxi license, and it covers all four link types: Share (download), Receive (upload), Collaborate (online editing), and one-time secret links.

Why OTP verification closes a gap SSO can’t #

As a managed file transfer (MFT) platform, ProVide already secures file transfer over SFTP and FTPS between systems you control. OTP verification extends that same security model to the harder case: external collaboration with people who sit outside your organization entirely.

Single sign-on (SSO) works well for colleagues and partners already inside your identity system, but it’s the wrong fit for a client, contractor, or one-off recipient.

Until now, a link either stayed open to “anyone with the link,” or required a full identity-provider integration to restrict it to one outside person.

OTP verification names specific recipients by email, without SSO setup on either end. For teams tracking GDPR compliance, that named, auditable access is easier to justify than an open link.

Setting up OTP verification as an administrator #

For each link type, an admin picks one verification method: OTP by email, your organization’s existing SSO provider, or none. That choice applies to every new link of that type automatically, so day-to-day link creation needs no extra configuration.

What the recipient sees when opening a verified link #
  1. Open the link and enter your email address, finally click Send Code.



  2. If the address is on the approved list, ProVide emails a 6-digit code.



  3. Enter the Code and press Verify and you will be taken to the link.

An unapproved address gets the identical “check your email” response. ProVide never confirms or denies whether an address is on the list, so the list can’t be probed by trial and error.

How ProVide keeps the OTP process secure #

Guess attempts are capped and codes expire quickly, so brute-forcing a code isn’t worth attempting.
A link with no approved recipients stays locked by default rather than opening.

ProVide checks the recipient list on every visit, not just at first verification, so removing someone revokes their access on their next request, even if they’d already verified once. Protection holds under clustered and high-availability deployments with no loss of coverage under load.

Example use cases for OTP-verified links #

A consulting or accounting firm can send a Share link for a sensitive report to a named client contact with no identity-provider setup.

A Receive link can collect files from a job applicant or vendor, limited to the specific addresses invited rather than a public upload page.

A Collaborate link lets an external reviewer edit a document online, verified by their own inbox. A one-time secret link hands off a password or access key the same way.

YOUR CART

CUSTOMERS ALSO ADD

HAVE A COUPON?
ORDER SUMMARY
We'll send a tailored quote to your inbox.
The invoice will be e-mailed once your order is confirmed.
ProVide Server

Your cart is empty

maxi_provideserver

Choose your version of ProVide Server to download

For the ultimate experience of ProVide’s features and functions,
we recommend choosing the MAXI License.

Follow the 3 easy steps below to install ProVide Server
  1. Download the version you need using the buttons below.
  2. Get a free MAXI trial license by clicking the “Get Maxi Trial License” button and enter your email. The license key will be sent to your email.
  3. Activate the license key by following this simple step-by-step-guide.

Free Trial

Get
ProVide Software