PWA Kit + SFRA cartridge

OTP Login Integration

The package removes passwords from account creation and sign-in on PWA Kit storefronts. Customers register with first name, last name and email, then authenticate with a one-time code sent to that email. Beyond login and registration, the storefront behaves exactly as before: browsing, cart, checkout and order history are unrestricted.

OTP passwordless login lock illustration for PWA Kit
Inside the package

What you get with OTP Login Integration

Production-ready functionality delivered as an ISV package for Salesforce Commerce Cloud.

Password-free registration

The sign-up form keeps only first name, last name and email; the password field is removed entirely. The customer record is created in SFCC and the shopper is logged in automatically.

Email-only login

The login form asks for the email address and then shows a code input. A one-time password arrives by email, and entering it completes the session.

10-minute code expiry

Each code is valid for 10 minutes; after that it stops working even if it was delivered late.

Rate-limited resend

A resend button is disabled for 30 seconds after each request, so a missing email can be recovered without spamming the mail channel.

Lockout after failed attempts

After three failed login attempts the flow imposes a wait time (five minutes in the demo, configurable at implementation) and shows the hour at which retry is allowed. The rule covers both login and resend, so it cannot be bypassed through the other action.

No account enumeration

Unregistered emails receive no code, and the UI shows no message that would reveal whether an address exists.

Unchanged storefront behavior

Registered-without-password customers browse, buy, check out and review order history like any other user; the implementation covers the React templates and the server side, and an SFRA cartridge is included for classic storefronts.

See it working

Package demos

Watch the OTP Login Integration features in action on real SFCC storefronts. More walkthroughs on our YouTube channel.

Password-free login with one-time passcodesPWA Kit
Where it fits

Use cases

E-commerce platforms

Lower sign-up friction while removing weak or reused passwords from the account base.

Security-sensitive storefronts

A short-lived code bound to the email channel, with brute-force protection, supports stricter account security.

High-volume consumer sites

Fewer abandoned registrations and fewer password-recovery tickets.

Banking, insurance and finance

Every login carries a second factor tied to the customer's email, and repeated guessing attempts are shut down automatically.

Healthcare and regulated purchases

Patient or account data stays protected without password policies that push users toward reused credentials.

Travel and ticketing

Itineraries and payment data on customer profiles are guarded by expiring codes rather than long-lived passwords.

Outcomes

Benefits

One credential to protect

No storefront passwords means no password database and no credential-stuffing surface.

Shorter registration

Three fields and no password rules before the first purchase.

Configurable security

Expiry and lockout intervals fit the risk profile of the site.

Self-service logins

There are no passwords to forget: a missed code is one 30-second resend away, and the standard reset-support ticket disappears.

Abuse-resistant by design

Attempt limits across login and resend, plus silent behavior for unknown emails, close the usual guessing and enumeration channels.

Nothing else changes

Orders, addresses, cart and account pages behave identically, so checkout flows and QA need no rework.

Licensing

Pricing details

What the license covers

  • $1 USD package license, one-time, per company.
  • Installation and configuration steps documented in the preview repository README.
  • Optional fixed-price add-ons below: installation, yearly maintenance and branding.

From license to live

After buying the package on AppExchange, install it in a sandbox and follow the setup guide in the preview repository. When it behaves as expected, promote it to production. If you would rather not run the rollout yourself, implementation in your SFCC instance is available as a fixed-price service.

$1 USD one-time, per company
Get it on AppExchange Request a fixed quote Available on AppExchange

Paid add-on required: this solution works with products or services external to Salesforce. Discounts are available for nonprofits.

Optional add-ons

Add-on services

The license ships the package. These fixed-price services cover everything around it.

$500 USD one-time

Installation & configuration

We install and configure the package in your SFCC instance, wire it to your sites and price books, and validate every flow in your sandbox before production.

$1,500 USD per year

Maintenance & compatibility

Version updates that track Salesforce B2C Commerce API and PWA Kit changes, plus priority fixes. Your package keeps working through every platform release.

$1,500 USD one-time

Branding customization

UI adaptation of the package components - store picker, badges, modals, buttons - to your storefront design system and brand guidelines.

GitHub — public preview repository

The preview repo lets you inspect the package architecture, components and setup instructions before you buy. It is a structural preview: the full production code ships with your licensed package.

Open preview repository Preview
Keep exploring

More SFCC packages

All packages are published by AppSpring as a Salesforce ISV partner since January 2023.

Ready to run OTP Login Integration in your storefront?

Tell us about your SFCC instance and we'll send a fixed-price plan with timeline.

Talk to an expert