Account security with
One-Time PIN solution
What is the Citi One-Time PIN (OTP)
The Citi One-Time PIN (OTP) is a unique, randomly generated, single use six digit PIN which can be generated via the Citi Mobile® App, or sent as an SMS to your mobile phone. You'll need to enter this any time you want to perform certain online transactions or actions via Citi Online. The OTP provides a stronger, smarter method for authenticating your online transactions for your peace of mind.
How does the Citi OTP work?
When you need to perform an online transaction or action, you will be required to enter an OTP as a second level of authentication to confirm that the transaction is authorised by you. This OTP will be sent to your mobile phone via SMS. You will only need one OTP per session.
You will automatically be enrolled in the OTP system when you open an account with us. This is to ensure all customers are using stronger authentication to transact online.
Benefits of OTP
- Smarter, more advanced security system to protect you and your money online
- Provides a stronger method for authenticating your online transactions
- Acts as an extra level of protection should your Card Number and PIN be compromised
- It's totally free, secure and easy to use.
How does OTP work?
When you need to perform an online transaction or online query you will be required to enter an OTP as a second level of authentication to confirm that the transaction is authorised by you.
This OTP will be delivered to you via SMS, or can be generated via the Citi Mobile® App. You will only need one OTP per session.
Updating your mobile number
You can update your mobile number via the Citi Mobile® App or Citi Online. To update to an overseas number, please update via Citi Online.
Managing your accounts online using the SMS OTP
Log in to Citi Online using your User ID and Password. Then when you perform an online transaction, you will be sent an OTP via SMS to enter before proceeding. You will only be required to enter one One-Time PIN per session.
An OTP will be required for any transaction that could potentially compromise your security or privacy as our customer.
Please note if you enter an incorrect OTP 3 times, your account will be locked and you will need to reset your password.
Receiving an OTP overseas
There are several ways you can receive an OTP while overseas.
Receive an OTP via the Citi Mobile® App
When you are travelling overseas you may not be able to get an OTP sent to your phone. Instead, you can also get an OTP sent via the Citi Mobile® App without internet connection or network coverage.
To receive an OTP via the Citi Mobile® App you will need to activate the Citi Mobile® Token and set up your 4-digit passcode.
- Tap the ‘Profile and Settings’ icon on the top left of the screen
- Go to ‘Security & app’ in ‘Settings’
- Select ‘Manage Citi Mobile® Token
- Tap ‘Create Unlock Code’
- Create your 4-digit Unlock Code. Re-enter it to confirm
- You will be able to receive the OTP via the Citi Mobile® App
Receive an OTP via SMS
To receive an OTP to your mobile phone you will need to activate global roaming before travelling. The SMS OTP has been optimised for international delivery and is still delivered instantly.
Lost your phone?
If you lose or have your phone stolen and it is no longer accessible to you to receive or generate an OTP, please do one of the following:
If using the SMS OTP Solution:
If you want to stop your phone receiving an SMS OTP, please contact your network provider and put a block on your number until you have a replacement phone.
If you are worried about access to your Citi Online accounts, please call us on 13 24 84 or +61 2 8225 0615 if calling from overseas, and we can put a block on your Citi Online access (this block will apply to Citi Online access on all devices).
When you replace your phone, give us another call and we will unblock your Citi Online access.
If using Citi Mobile® Token:
If you have a replacement device available, simply download the Citi Mobile® App onto the device and activate the Citi Mobile® Token.
Once you have activated the Citi Mobile® Token on a new device, the Citi Mobile® Token on the previous (lost) device will automatically be deactivated as you can only activate the Citi Mobile® Token on one device.
If you do not have a replacement device available, you should disable your Citi Mobile® Token using your Citi Online account:
- Log in to Citi Online
- Select ‘Services’ from the top navigation
- Select ‘My Profile’
- Click ’My Profile’ from the navigation on the left
- Click ‘Deactivate Citi Mobile® Token and follow the prompts
Common reasons you may not be able to receive an OTP on your mobile phone
Traveling overseas
To receive an SMS OTP when you’re overseas, make sure you have roaming turned on and you are in an area with good reception or network coverage.
Reception or network availability
Make sure your mobile phone has reception or network coverage to ensure your OTP can be delivered to your mobile phone.
Changes to mobile network provider
If you’ve recently moved your phone number to a different network, this may affect OTP delivery for a few days.
Mobile phone device issues
Sometimes you may not get an OTP because of an issue with your mobile device. Try restarting your phone or putting your SIM card in another phone to get the OTP. If you’re still unable to receive an OTP to your mobile phone, you can call us on 13 24 84 (+61 2 8225 0615 if calling from overseas).
Received an OTP when you weren’t expecting it?
There might be a few reasons why you receive an OTP unexpectedly. You can see the examples of OTP messages you might receive and what they mean below.
OTP message | What it means |
Your SMS code from Citi is XXX | You may receive this if you recently made a 3D secure purchase online. If you are concerned about fraudulent activity on your account please get in touch with us on 1300 550 216. |
XXXXXX is your One-Time PIN for Citi Online. It will expire in 5 minutes. Do not share this code over the phone. If you did not request this code call 1300 550 216. | This OTP is usually sent when you are trying to log in to Citi Online. If you haven’t tried to log in to Citi Online, it could be that your accounting software is attempting to log in to Citi Online on your behalf. If you believe that’s not the case, there is a chance your User ID or Password have been compromised and you should get in touch with us urgently on 1300 550 216. |
Just a courtesy reminder, that your next payment due is approaching… | This may be an OTP sent by us to as a reminder of your upcoming payment. You can opt out of receiving these types of notifications by calling us on 13 24 84. |
Related
Frequently Asked Questions
-
What is the Citi OTP?
-
How does the Citi OTP work?
-
Do I have to enter a Citi OTP for every transaction or every session?
-
What transactions will I need an OTP for?
-
Why is there a need for the Citi OTP?
-
Can I still manage my account online if I don't have access to my mobile phone?
-
Do I have to pay for the Citi OTP?
-
What if I don't receive an OTP?
-
How long does it take to receive an OTP to my mobile phone?
-
How long is the Citi OTP valid for?
-
What happens if I enter an incorrect OTP?
-
Will the sign on process to Citi Online change? Will I need the Citi OTP to sign on to Citi Online?
-
Can I receive the Citi OTP to an overseas mobile number?
-
What format does an international mobile number need to be in to receive the OTP?
-
Can I receive an OTP when I'm travelling overseas?
-
Can I receive a Citi OTP if I have call forwarding activated for my mobile phone?
-
Do I have to enrol for Citi OTP?
-
I have recently updated my mobile phone number. When can I start receiving The Citi OTP?
-
Can I register a second mobile phone number?
-
Will I need to enter the Citi OTP when managing my account via the Citi Mobile® App?
-
What is the OTP mobile app feature?
-
What is the difference between an OTP SMS and the OAC SMS?
-
Can I use the OTP generated using the Citi Mobile® App for telephone services?
Hard Token FAQs
Hard Token FAQs
-
What is a hard token?
-
Can I use my hard token to generate an OTP for use on my Mobile or Tablet device?
-
How does a hard token work?
-
How long does it take to receive a hard token?
-
Do I need to activate the hard token once received?
-
What if I have lost my token?
-
Do I need mobile or internet reception to generate OTP from hard token?
-
Can I share my hard token with others?
-
Do I need to return a damaged hard token when I receive a replacement?
-
Can I have more than one hard token for my Citi Online?
-
How secure should I keep my hard token?
-
How can I collect a hard token?
-
How long do the hard token batteries last for?