Design an OTP Notification Service

Problem Low-level design of an OTP-based notification system: generate an OTP for a user action, deliver it over a channel, and validate it — with working interface/class code, then extend the design for new channels and providers.

Requirements

  • API: generateOtp(userId, purpose) → dispatches via the user's channel; validateOtp(userId, purpose, code) → success/failure.
  • OTP rules: N-digit random code, TTL (e.g. 5 min), limited attempts, single-use, resend with cooldown.
  • Pluggable delivery channels (SMS/email → later push/WhatsApp) and swappable providers per channel.

Areas to design

  • The class seams that let a new channel or provider drop in without touching the core service.
  • The validation path: expiry, attempts, single-use, constant-time compare.
  • Security: hashed OTP storage, rate limiting, and non-revealing error responses.
asked …
LeaderboardSalaryAccount