SMS one-time codes and Connected Apps
Users can sign in with an SMS code, and operators can see which OAuth applications each user has authorized.
Available in English, German, Japanese, and French
From the changelog: SMS one-time codes and a Connected Apps view
Authdog Team

Email OTP and authenticator apps already covered passwordless and MFA. Phone-based sign-in needed the same request/verify pair, and operators needed a place to see which OAuth clients a user had authorized. Authdog now ships both: SMS one-time codes on the identity API, and a Connected Apps view in the console.
This is the longer note behind the August 23 changelog entry.
SMS one-time codes
The identity service exposes:
POST /api/v1/sms-otp/requestPOST /api/v1/sms-otp/verify
Request stores a 6-digit token on users_sms_otp_tokens and delivers it through the configured SMS (or WhatsApp) channel. Verify checks the code, resolves the user by phone, and completes primary sign-in the same way email OTP does.
Verify runs the shared passwordless risk helper (sms_otp_verify), including action hooks. The hosted SMS page may skip captcha when it has no token to send; bot detection still applies. See passwordless risk checks.
Connected Apps
Authentication > Connected Apps lists OAuth applications a user has authorized. It is the admin view of those grants: which clients, when, and enough detail to revoke or investigate a grant you do not recognize.
This is not the Agents module. Connected Apps are user-authorized OAuth clients. Agent identities are machine trust entries.
Set it up
- Configure an SMS provider for the environment.
- Enable SMS OTP on the hosted sign-in methods you want.
- Request a code to a test phone, then verify.
- Open Authentication > Connected Apps after a user has authorized a client, and confirm the grant appears.
Trust boundaries
SMS delivery is only as strong as the phone number and the carrier channel. Treat SMS OTP as a sign-in factor with SIM-swap and rerouting risk; pair it with device risk and bot detection. Connected Apps shows grants the authorization server recorded — it does not detect tokens copied out of band.
Try it
Run a hosted SMS sign-in, then open Connected Apps for that user. The original release note is in the changelog.