By App World Team | Updated 2026 | 12 min read
Can Facebook Send a One-Time Password by Text for the Facebook App?
Short answer: Yes. Facebook has a built-in feature that lets you request a one-time password (OTP) by SMS text message and use it to log into the Facebook app or Facebook.com instead of typing your regular password. This is especially useful if you're signing in on a public computer, a borrowed phone, or any device where you don't want to type your real password. Below, we break down exactly how it works, how to set it up, how long the code lasts, and what to do if it doesn't arrive.
What Is a Facebook One-Time Password (OTP)?
A one-time password is a temporary, single-use code that replaces your normal Facebook password for a single login. Instead of remembering and typing your real password on a device you don't fully trust — like a library computer, an internet café, or a friend's phone — you text a short code to Facebook's shortcode number and receive a unique password back. You then type that temporary password into the password field on the Facebook login screen.
Facebook explains this directly in its Help Center: if your mobile number is already linked to your Facebook account, texting "otp" to the number 32665 gets you a reply with a unique, six-character temporary password. If your number isn't linked to your account yet, Facebook sends you an email instead, with instructions on how to add the number and retrieve your code.
This feature has existed on Facebook for well over a decade and remains active on the platform today, according to Facebook's current Help Center documentation.
How to Get a Facebook One-Time Password by Text (Step-by-Step)
- Confirm your mobile number is added to your Facebook account. Go to Settings & Privacy > Settings > Accounts Center (or the Mobile section, depending on your app version) and make sure the phone number you're about to text from is listed under your account.
- Open your phone's default messaging app. Not Messenger — your regular SMS/text app.
- Send a text message to 32665 (which spells "FBOOK" on a phone keypad). The body of the message should simply say
otp. - Wait for the reply. Facebook texts back a six-character temporary password.
- Enter that code in the password field on the Facebook login screen (app or browser), using your normal username, email, or phone number as the login ID.
- You're in. The one-time password logs you in exactly as your regular password would, just for that single session.
Facebook's own support documentation confirms this exact process: send a text message to get a one-time password, check the carrier list to see which number applies in your country, text "otp" to that number, and if your number is already linked, Facebook replies with the unique six-character temporary password. Once you have the code, enter it in the password section of the Facebook login screen.
How Long Does a Facebook OTP Last?
This is one of the most searched follow-up questions, and the answer is important to remember: the one-time password is temporary, can't be used more than once, and is only valid for 20 minutes before it expires. If you don't use the code within that 20-minute window, you'll need to text "otp" to 32665 again to generate a fresh one. Because it's single-use, even if you successfully log in with it, that exact code cannot be reused for a second login — you'd need to request a new one.
Important: OTP Doesn't Work If Two-Factor Authentication Is On
This catches a lot of people off guard. If you have two-factor authentication (2FA) turned on for your Facebook account, the SMS one-time password feature described above is not available. Facebook states this explicitly: one-time passwords are not available if you have two-factor authentication turned on. This makes sense once you understand the difference between the two features, which people frequently confuse:
- One-time password (OTP): A full password replacement you request on demand by texting "otp" to 32665. It's meant for logging in from an untrusted device without exposing your real password.
- Two-factor authentication (2FA) SMS code: A second security step that Facebook automatically sends by text (or generates via an authenticator app) after you type your real password, when you log in from an unrecognized device or browser.
If your account has 2FA enabled, logging in from a new device will trigger Facebook to require you to enter a code, sent by text message or an authenticator app such as Google Authenticator or Duo Mobile, in addition to your password. That verification code is different from the OTP feature — you can't text "otp" to skip your password when 2FA is active. Instead, you type your real password first, and then confirm the SMS code Facebook automatically sends.
Which Number Do You Text — 32665 or Something Else?
In the United States and many countries, the standard Facebook shortcode is 32665 (spelling "FBOOK" on a phone dial pad). However, Facebook maintains a country-and-carrier-specific list, because the shortcode you should use may differ depending on your country and mobile carrier — for example, some regions use 32655 (FBOOK) instead. Before texting, it's worth checking Facebook's official carrier list in the Help Center (search "Get a one-time password" from Facebook's Help Center) to confirm which number applies to your specific carrier, since using the wrong shortcode means your text simply won't reach Facebook's system.
Why Does Facebook Offer This Feature At All?
The one-time password system was originally introduced to protect users from keylogging and password-capture risks on shared or public devices — think library terminals, hotel business centers, or internet cafés, where malicious software could silently record every keystroke, including your real password. By texting "otp" instead, your actual account password never touches that device's keyboard or screen. Security researchers have long noted this trade-off: the feature replaces passwords for public computer logins rather than functioning as a second authentication factor, meaning it protects against keyloggers but not against other attack vectors such as session cookie theft or phishing. In other words, treat it as a convenient, disposable password for risky devices — not as a replacement for strong account security practices overall.
Facebook OTP Text Not Arriving? Try These Fixes
If you texted "otp" to 32665 and nothing came back, work through this checklist:
- Give it a few minutes. Facebook and Facebook's support documentation both note that SMS messages may sometimes be delayed, so don't assume it failed after only thirty seconds.
- Check your phone signal. A weak signal or airplane mode will silently block delivery.
- Make sure your inbox isn't full. Some carriers won't deliver new texts if your SMS storage is maxed out.
- Confirm your number is actually linked to your Facebook account. If it isn't, Facebook won't text a code back — instead it emails you instructions to add the number first.
- Double-check you're texting the right shortcode for your country/carrier — 32665 isn't universal everywhere.
- Turn off 2FA if you specifically need the OTP feature — remember, they're mutually exclusive.
- If you're actually trying to log in with 2FA turned on and the code isn't arriving, that's a different issue — see the next section.
What If You Can't Get Your Two-Factor Authentication Code by Text?
If you're not looking for the OTP shortcut, but instead can't receive your regular 2FA login code by SMS, Facebook recommends trying solutions in a specific order. According to Facebook's Help Center, you should first wait for the SMS code to arrive since text codes can sometimes be delayed by your mobile network, check your phone again after a few minutes, confirm you have signal and that your inbox isn't full, or try approving the login from another device you're already signed into. If none of that works, Facebook also lets you generate codes through an authenticator app, use a saved recovery code, or get help from a trusted contact you previously set up on your account.
Is SMS a Secure Way to Receive Facebook Codes?
SMS-based codes are convenient, but security professionals generally consider them less secure than app-based authenticators, because text messages can potentially be intercepted or redirected through SIM-swapping attacks. Some users choose to disable SMS notifications from Facebook's shortcode entirely and rely solely on an authenticator app for 2FA, precisely to reduce this exposure. As one long-time security commentator put it, requiring SMS or a security key in addition to an authenticator app can feel unnecessary once you're already using app-based codes, since the SMS channel remains a weaker link even if it's just used for notifications. If security is a top priority for your account, consider using an authenticator app (like Google Authenticator or Duo Mobile) as your primary 2FA method, and reserve SMS as a backup only.
Facebook OTP vs. Login Alerts vs. Password Reset Codes: Don't Get Confused
Facebook sends several different types of SMS codes, and mixing them up is a common source of confusion:
| Code Type | When You Get It | Purpose |
|---|---|---|
| One-time password (OTP) | You text "otp" to 32665 on demand | Replaces your password for one login on an untrusted device |
| Two-factor authentication code | Automatically sent after you type your real password on a new device | Confirms it's really you before granting access |
| Password reset / recovery code | You click "Forgotten password?" | Lets you set a brand-new password |
Frequently Asked Questions
Does Facebook's one-time password work in the Facebook app, or only on the website?
It works in both places. Whether you're logging into the Facebook mobile app or Facebook.com in a browser, you enter the six-character code from the text message into the same password field you'd normally use.
How many times can I request a Facebook OTP?
Facebook doesn't publish a hard public limit in its Help Center, but each code you request replaces the previous one and expires after 20 minutes. If your code expires before you use it, simply text "otp" to 32665 again for a new one.
Can I use the OTP feature if I don't remember my password at all?
Yes — this is actually one of the main use cases. Since the OTP fully replaces your password for that one login, you don't need to know or type your real password. Just make sure your phone number is already linked to your Facebook account, since that's how Facebook verifies you.
Why did I get an email instead of a text after messaging "otp"?
This happens when the phone number you texted from isn't yet linked to your Facebook account. Facebook's system emails you instead, with steps to add that number and then retrieve your one-time password.
Is the Facebook one-time password the same as a two-factor authentication code?
No. They're two separate features that serve different purposes and can't be used at the same time — if 2FA is turned on for your account, the OTP-by-text feature is disabled.
Key Takeaways
- Facebook does support sending a one-time password by SMS text — just text "otp" to 32665 (or your region's equivalent shortcode).
- The code is a six-character temporary password valid for 20 minutes and usable only once.
- It only works if your phone number is already linked to your Facebook account and two-factor authentication is turned off.
- It's designed for logging in safely on public or shared devices, not as a replacement for strong everyday security.
- If you have 2FA enabled, you'll receive a different kind of SMS code automatically after entering your real password — that's a separate system from the OTP feature.
This article reflects Facebook's official Help Center guidance as of 2026. Facebook's features and shortcode numbers can change by region, so always verify current details directly on Facebook's Help Center if something doesn't match what's described here.

0 Comments