Beginner OTP Login Architecture Through Code-Owned SMS and Email Templates
TL;DR: Keep the password-reset template and its security-critical fields in the authentication service, then let channel adapters render constrained SMS and email variants. SMS can be the first delivery attempt and email the fallback, but neither channel should decide the token, expiry, eligibility, or recovery policy. Poll delivery events into an internal ledger; never treat a provider's…
We haven't written up this one. Dev.to has the full story — the link below goes straight to it.