BestCard

All posts

Credit Card PIN vs OTP: When Each One Is Actually Required

11 February 2026 · BestCard Editorial Team

Card BasicsSecurity
A cardholder entering a PIN at a card machine next to a phone showing an OTP prompt

Cardholders get confused at the counter more often than you'd expect — tap a card, get waved through, then get asked for a PIN two transactions later on an identical amount. The confusion is reasonable, because India doesn't use one authentication rule for credit cards; it uses three, and which one applies depends on the channel the transaction runs through, not just the rupee value.

The three authentication paths

Every credit card transaction in India falls into one of three buckets: PIN-based, OTP-based, or no second factor at all. None of these is optional or bank-specific — they're set by RBI's authentication framework and enforced at the network level (Visa, Mastercard, RuPay), so your experience is broadly the same regardless of which bank issued your card.

Card PIN is required at physical points of authentication where the card itself is presented and dipped or swiped — ATMs and most POS terminals asking for chip-and-PIN. This is "something you have" (the physical card) plus "something you know" (the PIN), and it's the oldest of the three mechanisms still in active use.

OTP is the default second factor for card-not-present transactions — anything where you're typing in the card number, expiry, and CVV rather than presenting the physical card. Online checkout, app-based payments, and phone/IVR transactions where the merchant collects your number all fall here. The OTP goes to your registered mobile number and has to be entered within a short window, usually a few minutes.

No second factor applies to a narrow, specifically carved-out category: contactless tap-and-go transactions below a threshold RBI has set (currently ₹5,000 per transaction, with issuers free to set it lower). Tap your card or phone on a contactless terminal for a sub-limit purchase and you're not asked for anything else, because the physical proximity of the tap plus the network's underlying encryption is treated as sufficient authentication for low-value spends.

Why the channel decides, not the amount

The logic is about where fraud risk actually concentrates. A card-present PIN transaction proves you have the physical card in hand, which rules out a huge share of remote fraud by itself — so it doesn't also need an OTP. A card-not-present transaction proves nothing about possession, since anyone with the card number can attempt it, which is exactly why OTP exists to close that gap. Contactless below the threshold accepts a small amount of residual risk in exchange for speed, on the theory that a lost or stolen card can only bleed a capped amount before the owner notices and blocks it.

This is also why the same ₹2,000 purchase can ask for a PIN, an OTP, or nothing depending entirely on how you pay — dip the chip and you get a PIN prompt, type the card details into a website and you get an OTP, tap contactless and you get neither. The amount is identical; the channel isn't.

Where this gets tightened further

Recurring payments and saved-card checkouts add another layer on top of this framework — the first time you set up an auto-debit or save a card on a new device, you'll typically see an e-mandate confirmation or an extra device-verification step even for a transaction that would otherwise skip OTP. That's a separate tightening RBI introduced specifically to stop subscriptions from silently renewing without any live authentication. For more on how this layer has evolved, see our breakdown of new 2FA rules for online credit card payments.

International transactions complicate this further, since not every country enforces India's 2FA rules on the merchant side — a US or UK site may process a card-not-present transaction with only CVV and no OTP at all, which is one reason secure online credit card payment habits matter even more while traveling.

What to actually do with this

Keep your registered mobile number current with your issuer — a stale number is the single most common reason OTPs silently fail and a legitimate transaction gets stuck. Set or reset your card PIN as soon as a new card arrives rather than waiting until an ATM visit forces the issue; a card with no PIN set can't be used at ATMs or PIN-requiring POS terminals at all. And treat the contactless no-authentication limit as a feature to use deliberately for small, fast purchases, not a workaround to disable — if you'd rather every tap require a PIN regardless of amount, most issuers let you lower or turn off the contactless limit from the app.

Where to go from here

For the fraud-prevention layer sitting on top of all three authentication paths, read credit card fraud protection tips. If you're comparing how contactless limits work day to day, tap to pay and NFC credit cards explained covers the mechanics in more depth, and RBI's new credit card rules for 2026 rounds up the other regulatory changes worth knowing about.