About
About Flow2FA
Flow2FA is a business-to-business OTP delivery and verification service. It accepts authentication traffic through a documented REST API or SMPP v3.4, routes messages through Flow2FA-supplied paths, customer-owned providers, or both, and returns the verification result to the customer application.
Flow2FA is operated by Flowstates Inc, a company registered in the United States. The service is sold to businesses; it is not a consumer authenticator app.
Company facts
- Product
- Flow2FA
- Legal operator
- Flowstates Inc
- Registered address
- 330 Madison Avenue, 27th Floor, New York, NY 10017, United States
- State registration number (SR)
- 20223077628
- EIN
- 88-3465626
- Legal contact
- legal@flowstates.net
- Product enquiries
- Via the contact page on this site
- Category
- B2B OTP delivery and verification service (2FA delivery layer)
The same entity details appear in the Terms of Use and Privacy Policy.
What Flow2FA does
- Generates one-time passcodes to the length, format and lifetime configured for the account.
- Delivers codes across the channels configured for the account.
- Applies configured retry and fallback rules when a channel does not confirm delivery.
- Validates the code a user entered and returns the result to the customer application.
- Records delivery attempts, resends, statuses and verification outcomes.
What Flow2FA does not do
- Act as an identity provider, user directory or session issuer.
- Perform identity proofing or KYC, or establish who a person is.
- Score risk or make fraud decisions.
- Replace passkeys or other phishing-resistant authenticators.
- Replace payment-network controls such as 3-D Secure.
- Guarantee message delivery, or treat a delivery receipt as a completed verification.
How customers connect
Authentication traffic reaches Flow2FA through the documented REST API or an SMPP v3.4 bind. On REST, /otp/generate returns an otpId that the customer application stores on its own record and later passes to /otp/validate with the code the user entered.
On SMPP, an existing submit path can often be retained, with identifiers and operational correlation staying in the customer messaging platform, subject to the integration design. Full detail is in the API reference.
How messages are delivered
Delivery can run over Flow2FA-supplied routes, customer-owned providers and SMPP binds, or a combination of both. Channel and route ordering is configured from customer policy, observed performance per market and existing commercial arrangements.
Channel availability depends on the setup configured for each account. The current public REST reference documents SMS and email channel values, while configured Flow2FA setups may also include WhatsApp.
Privacy, data protection and security review
The terms on which personal data is handled for this website and the Flow2FA platform are set out in the Privacy Policy.
Data-processing roles, the current contractual terms, any data processing agreement, security evidence and the technical and organisational measures that apply to a specific configuration are confirmed during contracting or security review. If you need those documents, request them through contact or from legal@flowstates.net.
No security or compliance certification is claimed on this page. Flow2FA does not assert certification, third-party conformity assessment or an independently audited information security management system.
Where to next
Read the OTP API overview, browse the use cases, work through the buyer guide, or check the API reference.