Login flow — mobile + PIN + OTP

COME SPORTS login uses a mobile number and a 6-digit PIN, plus an OTP sent to the registered mobile on first login from a new device. The PIN is set during sign-up; it can be changed at any time from the profile menu.

Login — COME SPORTS
Login

Login.

PIN recovery — the standard flow

If a user forgets the PIN, the recovery flow is: enter mobile → receive OTP → set a new PIN → confirm via a one-time password sent to the registered email. The flow takes under 2 minutes and is fully automated.

Section 01

Account access

Account access lives inside the companion app, not on this editorial site. Open the app and tap the avatar to sign in or create an account.

Login — Account access illustration
Account access.

Lost mobile — the elevated flow

If the user has lost access to the registered mobile, the recovery flow requires access to the registered email plus a one-time KYC verification. The flow takes under 15 minutes and includes a live-photo check to prevent account takeover.

Section 02

Mobile + OTP

Sign-in uses mobile number and a one-time password. No password to remember.

Login — Mobile + OTP illustration
Mobile + OTP.

Lost both — the manual review flow

If the user has lost access to both the registered mobile and the registered email, the recovery flow requires full KYC — PAN, Aadhaar and a live photo. The support team manually verifies identity and resets the credentials within 24 hours.

Section 03

Two-factor

For higher-value withdrawals, a second OTP is sent to your registered mobile.

Login — Two-factor illustration
Two-factor.

Account security — what we do

COME SPORTS protects your account with 256-bit TLS, hashed PIN storage (never stored in plain text), rate-limited OTP delivery, device-fingerprint binding, and a 24-hour cool-down on any credential change. Suspicious activity triggers a temporary lock and an SMS to the registered mobile.

Section 04

Recovery

If you lose access to your registered mobile, the support page lists the recovery process.

Login — Recovery illustration
Recovery.

What to do if your account is compromised

If you suspect your account has been compromised, write to [email protected] from the registered email. The security team will lock the account within 30 minutes and begin a manual review. You will be asked to complete KYC verification before the account is unlocked.

Section 05

Security

Sessions are encrypted with 256-bit TLS. Devices are remembered for 30 days unless you sign out manually.

Login — Security illustration
Security.

What changed recently — last-reviewed timestamp

This page is part of a published editorial calendar with a documented re-verification cadence. During the IPL season (late March to late May), every figure on this page is re-verified weekly. During the off-season, every figure is re-verified monthly. The full audit trail for any published number is accessible by hovering or tapping the small calendar icon beside the sub-heading.

The most recent substantive update to this page is logged at the foot of the page in the "Editorial log" section. If a published figure drifts by more than 10 percent from the underlying data, the page is updated within 24 hours and a timestamped correction note is appended.

Section 06

More from COME SPORTS

Visit the COME SPORTS editorial library for the latest fantasy-cricket guides, picks, points tables and live scoreboards. Every guide is updated after every IPL match.

Login — More from COME SPORTS illustration
More from COME SPORTS.

Related guides — where to read next

Every page on COME SPORTS links to the next page in the editorial chain. The chain starts at the fantasy cricket hub and runs through the IPL-specific hub, the prediction hub, the live scoreboard, the captain guide and the bonus guide. If you want a structured walk-through of the entire site, the fantasy guides blog is the right starting point — it covers the evergreen material in reading order.

The IPL 2026 calendar page lists every match, every venue and every squad update for the current season. The winners hub logs every prediction and every pick so you can audit our calls against the actual results. The responsible play hub documents every in-app tool for deposit limits, session time-outs and self-exclusion.

Section 07

More from COME SPORTS

Visit the COME SPORTS editorial library for the latest fantasy-cricket guides, picks, points tables and live scoreboards. Every guide is updated after every IPL match.

Login — More from COME SPORTS illustration
More from COME SPORTS.

How the editorial team is structured

COME SPORTS is run by a small editorial team of senior cricket analysts, data engineers and a full-time compliance reviewer. The cricket analysts write the guides, run the model audits and produce the captain picks. The data engineers pull the ball-by-ball feed, normalise the data and maintain the form index. The compliance reviewer reads every claim against the current state-level notifications and the latest operator terms.

The team is intentionally small. A smaller team means a tighter editorial pipeline, fewer handoffs and a faster correction cycle. It also means we cannot cover every cricket event globally — we focus on the IPL, the T20 World Cup, the Asia Cup and the bilateral series involving India.

Two-factor authentication — what's available

COME SPORTS supports two-factor authentication via OTP on the registered mobile number. The OTP is required on first login from a new device and on every credential change. We do not currently support authenticator-app-based 2FA, but it is on the Q4 2026 roadmap.

For high-value accounts — users with large bankrolls or with significant contest history — we recommend using a unique 6-digit PIN that is not reused on any other app, and enabling the device-fingerprint binding in the security settings. The device-fingerprint binding means that only the devices you explicitly register can log in without OTP — all other devices must complete OTP verification.

FAQ

Login — frequently asked.

Is Login free to read?

Yes — every page on COME SPORTS is free to read. The companion app is free to install.

Where do I download the app?

Use the download page to get the iOS, Android or direct APK link.

Is fantasy cricket legal in my state?

Most Indian states allow paid contests. The responsible play hub lists the current eligibility map — verify on app.

Independent of any operator — our editorial stance

COME SPORTS is editorially independent. We do not operate a paid fantasy app ourselves. We do not take a commission on contests entered through any third-party operator. We do not run sponsored editorial in disguise. Where we do accept sponsorship, the post is clearly labelled and reviewed under the same pipeline as every other guide.

Our funding model is straightforward: display advertising plus a flat referral fee paid by partner operators when a reader signs up via a tracked link. The flat fee is the same regardless of whether the reader plays a single contest or every match of the season, which keeps our editorial incentives aligned with the reader's.

Session management — what we track

COME SPORTS tracks every active session and lists them in the security settings. You can view the device, the IP address, the location (city-level only) and the last activity for every active session. You can revoke any session individually, or revoke all sessions except the current one. We send a notification to the registered email whenever a new session is opened from an unfamiliar device.

Session data is retained for 90 days after the session ends, after which it is anonymised and rolled into aggregate analytics. We do not retain session data beyond 90 days for any purpose.

Need more from COME SPORTS?

Browse GuidesContact Editorial

Reading checklist — what to do with this page

The most efficient way to read any COME SPORTS page is in three passes. The first pass is the headline — read the title, the eyebrow and the first paragraph to understand the editorial scope. The second pass is the structure — skim the section headers to build a mental outline of the page. The third pass is the deep read — work through each section in order, following the internal links as you go.

If you are short on time, every page has a one-paragraph executive summary at the top of the section list and a detailed FAQ at the bottom that covers the recurring reader questions. The summary is for the time-poor reader; the FAQ is for the reader who wants to interrogate the page before applying its framework.

Common login problems — quick fixes

The most common login problem is "OTP not received". The fix is usually to wait 60 seconds and tap "Resend OTP", then to check that the mobile network can receive SMS from short codes. If the OTP still doesn't arrive, check that your mobile is not in DND mode and that your SIM has not been recently swapped.

The second most common problem is "PIN doesn't work". The fix is usually to use the PIN recovery flow rather than guessing — three failed PIN attempts in a row triggers a 15-minute lockout. The third most common problem is "Account locked after travel" — this is the geo-fence kicking in. Wait 24 hours and the account will unlock automatically once your new location is registered.

What to do if you suspect account compromise

If you suspect your account has been compromised, write to [email protected] from the registered email. The security team will lock the account within 30 minutes and begin a manual review. You will be asked to complete KYC verification before the account is unlocked.

Signs that your account may be compromised include: unexpected session activity in the security log, unexpected contest entries, unexpected withdrawal requests, unexpected changes to your profile, and unexpected emails from us that you did not initiate.

If you see any of these signs, do not log in from the suspected device and do not respond to any messages from the suspected session. Write to security from a clean device using the registered email and we will guide you through the recovery process.

Login security — best practices for users

The most important login security practice is to use a unique 6-digit PIN that is not reused on any other app. Reusing PINs is the single largest source of account compromise — if a PIN is leaked from another app, the attacker can try the same PIN on COME SPORTS.

The second most important practice is to enable device-fingerprint binding. This means that only the devices you explicitly register can log in without OTP. If an attacker tries to log in from a new device, they must complete OTP verification — and they would also need access to your registered mobile.

The third most important practice is to monitor the security log for unfamiliar sessions. We send an email notification whenever a new session is opened from an unfamiliar device. If you receive a notification for a session you did not initiate, write to [email protected] immediately.