Login flow — mobile + PIN + OTP
COME SPORTS login uses a mobile number and a 6-digit PIN, plus an OTP sent to the registered mobile on first login from a new device. The PIN is set during sign-up; it can be changed at any time from the profile menu.

Login.
PIN recovery — the standard flow
If a user forgets the PIN, the recovery flow is: enter mobile → receive OTP → set a new PIN → confirm via a one-time password sent to the registered email. The flow takes under 2 minutes and is fully automated.
Account access
Account access lives inside the companion app, not on this editorial site. Open the app and tap the avatar to sign in or create an account.

Lost mobile — the elevated flow
If the user has lost access to the registered mobile, the recovery flow requires access to the registered email plus a one-time KYC verification. The flow takes under 15 minutes and includes a live-photo check to prevent account takeover.
Mobile + OTP
Sign-in uses mobile number and a one-time password. No password to remember.

Lost both — the manual review flow
If the user has lost access to both the registered mobile and the registered email, the recovery flow requires full KYC — PAN, Aadhaar and a live photo. The support team manually verifies identity and resets the credentials within 24 hours.
Two-factor
For higher-value withdrawals, a second OTP is sent to your registered mobile.

Account security — what we do
COME SPORTS protects your account with 256-bit TLS, hashed PIN storage (never stored in plain text), rate-limited OTP delivery, device-fingerprint binding, and a 24-hour cool-down on any credential change. Suspicious activity triggers a temporary lock and an SMS to the registered mobile.
Recovery
If you lose access to your registered mobile, the support page lists the recovery process.

What to do if your account is compromised
If you suspect your account has been compromised, write to [email protected] from the registered email. The security team will lock the account within 30 minutes and begin a manual review. You will be asked to complete KYC verification before the account is unlocked.
Security
Sessions are encrypted with 256-bit TLS. Devices are remembered for 30 days unless you sign out manually.

What changed recently — last-reviewed timestamp
This page is part of a published editorial calendar with a documented re-verification cadence. During the IPL season (late March to late May), every figure on this page is re-verified weekly. During the off-season, every figure is re-verified monthly. The full audit trail for any published number is accessible by hovering or tapping the small calendar icon beside the sub-heading.
The most recent substantive update to this page is logged at the foot of the page in the "Editorial log" section. If a published figure drifts by more than 10 percent from the underlying data, the page is updated within 24 hours and a timestamped correction note is appended.
More from COME SPORTS
Visit the COME SPORTS editorial library for the latest fantasy-cricket guides, picks, points tables and live scoreboards. Every guide is updated after every IPL match.

Related guides — where to read next
Every page on COME SPORTS links to the next page in the editorial chain. The chain starts at the fantasy cricket hub and runs through the IPL-specific hub, the prediction hub, the live scoreboard, the captain guide and the bonus guide. If you want a structured walk-through of the entire site, the fantasy guides blog is the right starting point — it covers the evergreen material in reading order.
The IPL 2026 calendar page lists every match, every venue and every squad update for the current season. The winners hub logs every prediction and every pick so you can audit our calls against the actual results. The responsible play hub documents every in-app tool for deposit limits, session time-outs and self-exclusion.
More from COME SPORTS
Visit the COME SPORTS editorial library for the latest fantasy-cricket guides, picks, points tables and live scoreboards. Every guide is updated after every IPL match.

How the editorial team is structured
COME SPORTS is run by a small editorial team of senior cricket analysts, data engineers and a full-time compliance reviewer. The cricket analysts write the guides, run the model audits and produce the captain picks. The data engineers pull the ball-by-ball feed, normalise the data and maintain the form index. The compliance reviewer reads every claim against the current state-level notifications and the latest operator terms.
The team is intentionally small. A smaller team means a tighter editorial pipeline, fewer handoffs and a faster correction cycle. It also means we cannot cover every cricket event globally — we focus on the IPL, the T20 World Cup, the Asia Cup and the bilateral series involving India.
Two-factor authentication — what's available
COME SPORTS supports two-factor authentication via OTP on the registered mobile number. The OTP is required on first login from a new device and on every credential change. We do not currently support authenticator-app-based 2FA, but it is on the Q4 2026 roadmap.
For high-value accounts — users with large bankrolls or with significant contest history — we recommend using a unique 6-digit PIN that is not reused on any other app, and enabling the device-fingerprint binding in the security settings. The device-fingerprint binding means that only the devices you explicitly register can log in without OTP — all other devices must complete OTP verification.
Login — frequently asked.
Is Login free to read?
Yes — every page on COME SPORTS is free to read. The companion app is free to install.
Where do I download the app?
Use the download page to get the iOS, Android or direct APK link.
Is fantasy cricket legal in my state?
Most Indian states allow paid contests. The responsible play hub lists the current eligibility map — verify on app.
Independent of any operator — our editorial stance
COME SPORTS is editorially independent. We do not operate a paid fantasy app ourselves. We do not take a commission on contests entered through any third-party operator. We do not run sponsored editorial in disguise. Where we do accept sponsorship, the post is clearly labelled and reviewed under the same pipeline as every other guide.
Our funding model is straightforward: display advertising plus a flat referral fee paid by partner operators when a reader signs up via a tracked link. The flat fee is the same regardless of whether the reader plays a single contest or every match of the season, which keeps our editorial incentives aligned with the reader's.
Session management — what we track
COME SPORTS tracks every active session and lists them in the security settings. You can view the device, the IP address, the location (city-level only) and the last activity for every active session. You can revoke any session individually, or revoke all sessions except the current one. We send a notification to the registered email whenever a new session is opened from an unfamiliar device.
Session data is retained for 90 days after the session ends, after which it is anonymised and rolled into aggregate analytics. We do not retain session data beyond 90 days for any purpose.
Need more from COME SPORTS?
Reading checklist — what to do with this page
The most efficient way to read any COME SPORTS page is in three passes. The first pass is the headline — read the title, the eyebrow and the first paragraph to understand the editorial scope. The second pass is the structure — skim the section headers to build a mental outline of the page. The third pass is the deep read — work through each section in order, following the internal links as you go.
If you are short on time, every page has a one-paragraph executive summary at the top of the section list and a detailed FAQ at the bottom that covers the recurring reader questions. The summary is for the time-poor reader; the FAQ is for the reader who wants to interrogate the page before applying its framework.
Common login problems — quick fixes
The most common login problem is "OTP not received". The fix is usually to wait 60 seconds and tap "Resend OTP", then to check that the mobile network can receive SMS from short codes. If the OTP still doesn't arrive, check that your mobile is not in DND mode and that your SIM has not been recently swapped.
The second most common problem is "PIN doesn't work". The fix is usually to use the PIN recovery flow rather than guessing — three failed PIN attempts in a row triggers a 15-minute lockout. The third most common problem is "Account locked after travel" — this is the geo-fence kicking in. Wait 24 hours and the account will unlock automatically once your new location is registered.
What to do if you suspect account compromise
If you suspect your account has been compromised, write to [email protected] from the registered email. The security team will lock the account within 30 minutes and begin a manual review. You will be asked to complete KYC verification before the account is unlocked.
Signs that your account may be compromised include: unexpected session activity in the security log, unexpected contest entries, unexpected withdrawal requests, unexpected changes to your profile, and unexpected emails from us that you did not initiate.
If you see any of these signs, do not log in from the suspected device and do not respond to any messages from the suspected session. Write to security from a clean device using the registered email and we will guide you through the recovery process.
Login security — best practices for users
The most important login security practice is to use a unique 6-digit PIN that is not reused on any other app. Reusing PINs is the single largest source of account compromise — if a PIN is leaked from another app, the attacker can try the same PIN on COME SPORTS.
The second most important practice is to enable device-fingerprint binding. This means that only the devices you explicitly register can log in without OTP. If an attacker tries to log in from a new device, they must complete OTP verification — and they would also need access to your registered mobile.
The third most important practice is to monitor the security log for unfamiliar sessions. We send an email notification whenever a new session is opened from an unfamiliar device. If you receive a notification for a session you did not initiate, write to [email protected] immediately.





