Home Sign in

Account sign-in and recovery

How to sign in on a licensed rummy platform, recover a locked account, and protect your account with two-factor authentication.

Last updated
03 Aug 2026
Reading time
5 min
Author
Jeetwin desk
A phone showing a one-time password entry screen
Account access

How to sign in safely and recover a locked account

Account access on a licensed rummy platform is a one-step process once your account is verified. The platform will send an OTP to your registered mobile number or email. Enter the OTP and you are in the lobby.

Sign in steps

  1. Open the platform URL or app.
  2. Enter your registered mobile number or email.
  3. Enter the OTP sent to your registered contact.
  4. Complete the lobby if you have set safer-play controls.

Recovering a locked account

Accounts lock for three common reasons: too many failed OTP attempts, a suspicious login from a new device, or a self-exclusion period. The recovery process depends on the reason.

Too many failed OTP attempts. Wait 15 minutes and try again. The platform will reset the OTP counter automatically.

Suspicious login from a new device. The platform will send an additional verification email. Confirm the login from the email link. If you did not initiate the login, change your password immediately.

Self-exclusion period. The account remains locked until the exclusion period ends. Contact support if you have a genuine reason to lift the exclusion early — the platform will require a 24-hour cooling-off before lifting.

Tip — never share your OTP

A licensed platform will never ask for your OTP. If a support agent asks for your OTP, refuse and report the user. The platform will never call you to ask for your OTP.

Logging in from a new device

Most platforms remember a device for 30 days. After 30 days, the platform will ask for additional verification. This is normal. If the verification email does not arrive, check your spam folder and confirm your registered email is correct.

The desk recommends enabling two-factor authentication if the platform offers it. Two-factor codes are sent to your registered mobile number, and the code refreshes every 30 seconds.

Two-factor authentication

Why the desk recommends two-factor authentication

Two-factor authentication adds a second step to the sign-in flow. The first step is the OTP sent to the registered mobile number. The second step is a one-time code from an authenticator app or a hardware key. The second step is required even if the OTP is intercepted.

The desk recommends two-factor authentication because the OTP can be intercepted. SIM-swap attacks, phishing attacks, and SS7 protocol attacks can all intercept the OTP. The second factor — a code from an authenticator app or a hardware key — is not vulnerable to the same attacks.

The desk's preferred second factor is a hardware key. A hardware key is a small USB or NFC device that generates a one-time code when tapped. The hardware key is not vulnerable to phishing, SIM-swap, or SS7 attacks. The hardware key is the strongest form of two-factor authentication available to a consumer.

If a hardware key is not available, the desk recommends an authenticator app. An authenticator app generates a one-time code every 30 seconds. The authenticator app is not vulnerable to SIM-swap or SS7 attacks. The authenticator app is vulnerable to phishing — a phishing site can capture the code in real time — but the window is short.

The desk does not recommend SMS-based two-factor authentication as a second factor. SMS is the same channel as the OTP. If the OTP is intercepted, the SMS-based second factor is also intercepted. SMS-based two-factor authentication is no stronger than single-factor authentication.

The platform's login is rate-limited. The platform allows 5 failed OTP attempts before locking the OTP flow. The lock is for 15 minutes. The lock is for the player's protection — the lock prevents brute-force attacks.

The platform's login is device-aware. The platform remembers the device for 30 days. The platform sends a verification email if the player logs in from a new device. The verification email is a one-time link. The link is valid for 1 hour.

The platform's login is session-managed. The session expires after 30 days of inactivity. The session expires after 90 days of activity. The expiration is for the player's protection. The expiration reduces the window for a stolen session.

The platform's login is accessible. The platform supports screen readers. The platform supports keyboard navigation. The platform supports high-contrast mode. The platform's accessibility is documented in the platform's accessibility statement.

The platform's login is audited. The platform logs every login attempt. The log includes the timestamp, the IP address, the user agent, and the result. The player can request the log via the privacy request process.

The desk's coverage is built on three principles. The first principle is editorial — does the piece serve a reader who is making a real decision. The second principle is compliance — does the piece satisfy the relevant Indian laws on responsible editorial coverage. The third principle is craft — does the piece read like a professional magazine article.

The desk's editorial team reviews every piece before publication. The review includes a fact-check pass, a source-verification pass, and a craft pass. The review is documented in the editorial principles section. The desk publishes the corrections on the affected page when a piece is updated.

The desk's recommended reading list is in the editorial index section. The list is curated by the desk. The list is updated quarterly. The list is the desk's view on the most useful pieces for the reader who is new to rummy or who wants to deepen the reader's understanding.

FAQ

Questions readers ask the desk

How do I sign in?

Enter your registered mobile number or email, then enter the OTP sent to your registered contact. Most platforms also support a password-based login as a backup once your account is verified.

I did not receive the OTP. What should I do?

Wait 60 seconds. Check your spam folder for emails. Confirm the registered mobile number is correct. If the OTP still does not arrive, contact support.

My account is locked. How do I recover it?

Wait 15 minutes if the lock is due to too many failed OTP attempts. Confirm the login from the verification email if the lock is due to a new device. Contact support for self-exclusion lifts.

Should I share my OTP with a support agent?

No. A licensed platform will never ask for your OTP. If a support agent asks for your OTP, refuse and report the user.

How do I enable two-factor authentication?

Most platforms offer two-factor authentication in the account settings. Enable it and store the recovery codes in a password manager.

Set the cap before you open the lobby

If you read one page on this site before you sign in, read the safer-play controls. Then set a spend cap. Then come back and pick the format you want to learn.