Step 1: Open official login route
Use only the current official URL and verify secure connection context.
Open official route, complete OTP once, and avoid repeated rapid retries.
Use only the current official URL and verify secure connection context.
Wait full OTP cycle, retry once, and avoid rapid repeated requests.
Confirm expected device notices before entering extended sessions.