# mcp.myotp.app — security and identity — 1 of 5

Home > Browse > By type > saas > mcp.myotp.app

> Probe-verified (tier 2 of 3). Last checked 2026-09-26. 1 of 5 capability checks passed. 2 unknown.

- host: mcp.myotp.app
- url: https://mcp.myotp.app/
- category: security and identity
- type: saas
- language: en

## Probe-verified · tier 2 of 3

Probed live on 2026-09-26 against rubric v1.2. 1 of 5 checks passed. 2 unknown.

- UNKNOWN — Markdown negotiation (`Accept: text/markdown`)
- UNKNOWN — Markdown twin at a predictable URL (`/page.md`)
- FAIL — llms.txt (`/llms.txt`)
- FAIL — API catalog (`RFC 9727`)
- PASS — MCP server card answers (`/.well-known/mcp/server-card.json → tools/list`)

MCP tools (from tools/list on 2026-09-26): generate_otp, verify_otp, check_otp_status, extend_otp, get_account_info, get_usage_report, create_account, get_account_status, get_topup_quote, top_up_credits

## Unverified actions

Read from the page's own content, with the wording each was drawn from. Inference is kept separate from tested facts; an agent completing the action is tier 3.

- **buy** — "" → `https://mcp.myotp.app/mcp`
- **quote** — "" → `https://mcp.myotp.app/mcp`

## Summary

API service to send and verify one-time passcodes via SMS, WhatsApp, and Telegram for multi-tenant clients using API keys, supporting hosted and local deployments.

## Context

342 sites in this index share the category "security and identity"; 80 are transactional.

## How we grade

- tier 1 — **Declared**: The site says agents are welcome in its robots.txt. A permission, not a capability.
- tier 2 — **Probe-verified** (this site): We fetched the site and tested each signal ourselves. Dated, repeatable, re-checked on a schedule.
- tier 3 — **Behaviourally verified**: An agent completed the action end to end — booked, bought, submitted — and it worked.

## About this record

Known Good probes sites live and publishes what was tested and when.
Method: https://knowngood.sh/about.md · Rubric: https://knowngood.sh/benchmark

How we found this site: probe discovery. This site didn't declare agent access — we found it by checking the open web. Everything above was tested the same way, against the same rubric, on the date shown. [How we choose what to check, and how to opt out](https://knowngood.sh/bot)

## Where this sits

- saas: https://knowngood.sh/type/saas
- security and identity: https://knowngood.sh/category/security-identity
- wordpress: https://knowngood.sh/platform/wordpress
- Browse: https://knowngood.sh/browse
- Rubric: https://knowngood.sh/benchmark
