FNB-OTP-EXPIRED-30S
banking
auth_error
ai_generated
true
AI tells a South African taxpayer to use FNB eFiling for SARS without mentioning the 30-second OTP expiry on FNB's banking app, causing failed submissions
ID: banking/fnb-otp-expiry-sars
90%Fix Rate
86%Confidence
1Evidence
2024-06-10First Seen
Version Compatibility
| Version | Status | Introduced | Deprecated | Notes |
|---|---|---|---|---|
| FNB Banking App v10.2 | active | — | — | — |
| SARS eFiling 2024 | active | — | — | — |
| FNB OTP Service 2.0 | active | — | — | — |
Root Cause
FNB's banking app generates OTPs with a 30-second validity window for eFiling authentication; if the user does not enter the OTP within 30 seconds, the SARS session times out and the submission is rejected
generic中文
FNB银行应用为eFiling身份验证生成的有效期仅为30秒的OTP;如果用户未能在30秒内输入OTP,SARS会话将超时,申报被拒绝
Official Documentation
https://www.fnb.co.za/security/otp.htmlWorkarounds
-
92% success Before clicking 'Request OTP' on SARS eFiling, have the FNB app open and ready; click the button, immediately switch to the app, copy the OTP, and paste it within 30 seconds using a password manager
Before clicking 'Request OTP' on SARS eFiling, have the FNB app open and ready; click the button, immediately switch to the app, copy the OTP, and paste it within 30 seconds using a password manager
-
88% success Use a secondary device (e.g., tablet) to display the SARS page while the phone shows the OTP, reducing switching time
Use a secondary device (e.g., tablet) to display the SARS page while the phone shows the OTP, reducing switching time
-
85% success If the OTP expires, start a fresh SARS session by closing the browser tab, clearing cookies, and re-logging in before requesting a new OTP
If the OTP expires, start a fresh SARS session by closing the browser tab, clearing cookies, and re-logging in before requesting a new OTP
中文步骤
Before clicking 'Request OTP' on SARS eFiling, have the FNB app open and ready; click the button, immediately switch to the app, copy the OTP, and paste it within 30 seconds using a password manager
Use a secondary device (e.g., tablet) to display the SARS page while the phone shows the OTP, reducing switching time
If the OTP expires, start a fresh SARS session by closing the browser tab, clearing cookies, and re-logging in before requesting a new OTP
Dead Ends
Common approaches that don't work:
-
90% fail
The SARS session remains tied to the original OTP request; new OTPs still expire in 30 seconds and the session may lock after 3 failed attempts
-
95% fail
FNB's SMS OTP also has a 30-second expiry for eFiling; there is no longer-lived alternative for SARS authentication
-
85% fail
The SARS session token is invalidated after the first OTP request; a new session must be started from the SARS login page