CITIBANK ONLINE

Secure online banking.

Experience secure online banking with Citibank.

We have enhanced the security authentication for your transactions. Starting April 2022, you may use the Citi Mobile App to authenticate your transactions in Citibank Online or purchases in 3rd party merchant websites. Please note that as of August 04, 2021, you no longer need to use your Citi Mobile® Token for authentication process.

Secure Online Banking

SECURE ONLINE BANKING

We have enhanced the security authentication for your transactions. Starting April 2022, you may use the Citi Mobile App to authenticate your transactions in Citibank Online or purchases in 3rd party merchant websites. Please note that as of August 04, 2021, you no longer need to use your Citi Mobile® Token for authentication process.

What are the new authentication processes?

SMS OTP or One Time-PIN

 

3DSecure Push Notification Authentication

3DSecure Push Notification Authentication is a new method of authenticating your purchases from 3rd party merchant websites, where you would receive a push notification instead of an SMS OTP. Just enable secure authentication on your Citi Mobile® App and allow push notifications to be received by the app. When you use your Citi credit card or Citibank debit card in a merchant website, you will receive a push notification which you need to tap and it will prompt you to authenticate with your biometric or password to complete your purchase.

By using the enhanced authentication process for your Citibank® Online transactions and online retail transactions using your Citi Credit Card or Citibank Debit Mastercard, it creates a more secure and convenient digital banking experience.

 

 

What makes Citi's authentication process secure?

Citi's authentication process secure

Our Citi Mobile® App's security authentication uses updated biometric capabilities (Face ID® / Touch ID® / Fingerprint Authentication).

When you log in with your device using the updated security authentication, the Citi Mobile® App will be able to authenticate you. So, there's no need for you to input an Unlock Code or SMS OTP for certain transactions, because the app has already confirmed you to be the person logged in. This means less steps and less waiting time for a more convenient and seamless mobile banking experience.

 

 

What is an SMS OTP or One Time-PIN?

SMS OTP or One Time-PIN

The SMS One-Time PIN (OTP) is a unique six-digit Personal Identification Number (PIN). It acts as a user authentication tool to protect your online transactions. The SMS OTP is sent to your registered primary mobile number and can only be used once and expires in five (5) minutes.

To ensure that your mobile number is always updated, you may change or update this through the Citi Mobile App or by logging in at www.citibank.com.ph (Services > Profile and Settings > My Contact Details > Update Information). You may also call CitiPhone at 8995 9999.

When traveling abroad, make sure to update your contact details with the mobile number you will be using abroad, so you can receive the SMS OTP when using mobile or online banking abroad. Remember to change it back to your local number upon your return.

 

FAQs for Citibank® Online QR Authentication

 

You will see a QR code when you access certain features and perform select transactions in Citibank® Online.

You can enable secure authentication by logging in to Citi Mobile App and you should be prompted on the screen. Simply follow the instructions and enable it using SMS OTP. Once enabled, you will be able to see the “Scan QR” button in the login screen.

No, once you have enabled secure authentication on your Citi Mobile® App, you will always be asked to authenticate your transactions in Citibank® Online by scanning the QR code displayed.

Yes, if you do not use the Citi Mobile® App and have not enrolled for secure authentication, you will continue to receive SMS OTP to authenticate your Citibank® Online transactions.

A QR code will be displayed on Citibank Online for your transaction if you also have the Citi Mobile® App and have enabled secure authentication. Once you have enabled secure authentication on your Citi Mobile® App, you will see a “Scan QR” button in the login screen. Tap on this to open up the QR scanner and proceed to scan the QR code displayed for your Citibank® Online transaction.

For iOS/Apple users, you may go to your device's "Settings > Citibank PH > Camera Toggle".
For Android users, you may go to your device's "Settings > Apps > Citibank PH > Permissions > Camera Toggle".

Yes, you will be able to use the "Scan QR" option as long as you have the Citi Mobile® App installed on your new smartphone and have enabled secure authentication. Please note that enabling secure authentication on your new smartphone will disable it from the old smartphone.

No, you can only have 1 smartphone enrolled for secure authentication at any given time. The latest smartphone enrolled to secure authentication will be the one recognized by our systems.

Go back to your Citibank® Online transaction and retry the transaction so that it will give a fresh QR code for scanning. Once scanned, you will have 2 minutes to authenticate with your password or biometric before it expires.

Yes, authenticating your Citibank® Online transactions by scanning the displayed QR code is much more secure as this protects your account from fraudsters who use social engineering to get the SMS OTP for a transaction. With QR Authentication, you would need your registered Citi Mobile® App on your mobile phone to scan the QR code displayed for your Citibank® Online transaction to authenticate it.

QR authentication gives you the convenience of not having to wait for an SMS OTP. Receiving an SMS OTP is dependent on your network signal and the SMS can sometimes arrive late to your device. If the SMS OTP arrives beyond 5 minutes after you have been prompted, it will expire and you would have to request for another OTP. For QR authentication, you would just need to connect to your Wi-Fi network or data plan, open your Citi Mobile® App, scan the QR code using the built in QR scanner of the app, then authenticate with password or biometric.

FAQs for Citibank® Online QR Authentication

 

You will see a QR code when you access certain features and perform select transactions in Citibank® Online.

You can enable secure authentication by logging in to Citi Mobile App and you should be prompted on the screen. Simply follow the instructions and enable it using SMS OTP. Once enabled, you will be able to see the “Scan QR” button in the login screen.

No, once you have enabled secure authentication on your Citi Mobile® App, you will always be asked to authenticate your transactions in Citibank® Online by scanning the QR code displayed.

Yes, if you do not use the Citi Mobile® App and have not enrolled for secure authentication, you will continue to receive SMS OTP to authenticate your Citibank® Online transactions.

A QR code will be displayed on Citibank Online for your transaction if you also have the Citi Mobile® App and have enabled secure authentication. Once you have enabled secure authentication on your Citi Mobile® App, you will see a “Scan QR” button in the login screen. Tap on this to open up the QR scanner and proceed to scan the QR code displayed for your Citibank® Online transaction.

For iOS/Apple users, you may go to your device’s “Settings > Citibank PH > Camera Toggle”.

For Android users, you may go to your device’s “Settings > Apps > Citibank PH > Permissions > Camera Toggle”.

Yes, you will be able to use the “Scan QR” option as long as you have the Citi Mobile® App installed on your new smartphone and have enabled secure authentication. Please note that enabling secure authentication on your new smartphone will disable it from the old smartphone.

No, you can only have 1 smartphone enrolled for secure authentication at any given time. The latest smartphone enrolled to secure authentication will be the one recognized by our systems.

Go back to your Citibank® Online transaction and retry the transaction so that it will give a fresh QR code for scanning. Once scanned, you will have 2 minutes to authenticate with your password or biometric before it expires.

Yes, authenticating your Citibank® Online transactions by scanning the displayed QR code is much more secure as this protects your account from fraudsters who use social engineering to get the SMS OTP for a transaction. With QR Authentication, you would need your registered Citi Mobile® App on your mobile phone to scan the QR code displayed for your Citibank® Online transaction to authenticate it.

QR authentication gives you the convenience of not having to wait for an SMS OTP. Receiving an SMS OTP is dependent on your network signal and the SMS can sometimes arrive late to your device. If the SMS OTP arrives beyond 5 minutes after you have been prompted, it will expire and you would have to request for another OTP. For QR authentication, you would just need to connect to your Wi-Fi network or data plan, open your Citi Mobile® App, scan the QR code using the built in QR scanner of the app, then authenticate with password or biometric.

FAQs for 3DSecure Push Notification Authentication

 

You would need to have the Citi Mobile® App installed on your smartphone, enable secure authentication, and allow push notifications to be received by the app.

  1. Enabling secure authentication:

    1. Login to your Citi Mobile® App. If secure authentication is not yet enabled, it will show a prompt to enable it.
    2. Tap on 'Continue' to authenticate via SMS OTP.
    3. Enter the received SMS OTP in the input field and tap on next.
    4. It should now display a success screen signifying that it is now enabled.
  2. Allowing push notification to be received by the app:

    1. For iOS/Apple users, you may go to your device's "Settings > Citibank PH > Notifications > Allow Notifications Toggle".
    2. For Android users, you may go to your device's "Settings > Apps > Citibank PH > Notifications > Notifications Toggle".

Yes, this applies to purchases on merchant websites using your Citi credit card or Citibank debit card.

For you to receive a push notification for your merchant transaction, you would need to have the Citi Mobile® App installed on your smartphone and enable both secure authentication and push notifications.

You may give permission to allow push notifications to be received by your Citi Mobile® App by following the below:

For iOS/Apple users, you may go to your device’s “Settings > Citibank PH > Notifications > Allow Notifications Toggle”.

For Android users, you may go to your device’s “Settings > Apps > Citibank PH > Notifications > Notifications Toggle”.

If the request is not yet expired, you may bring up the authentication request again by tapping on "Authorize Transactions" on the login screen of your Citi Mobile® App.

Yes, on the merchant site, there will be a link there to request for an SMS OTP instead.

If you received a push notification for a merchant transaction but did not do any transaction or the details displayed in the prompt are incorrect, please proceed to lock your Citi credit card in the manage card screen of the Citi Mobile® App to avoid further transactions and immediately call CitiPhone at 8995-9999 to report the concern.

Online Banking SMS OTP FAQ

 

The SMS OTP will only be sent to the primary mobile number in our system. If you wish to change or update your primary mobile number, you may do so through Citibank Online (Services > Profile & Settings > My Profile > Update Profile and Contact Details > Update Information) or the Citi Mobile® App (Profile & Settings > Personal Information > Edit).

For online transactions that require an OTP, an SMS One-Time PIN (OTP) pop up-screen will appear where you will have to input your OTP. The last-4 digits of your registered mobile number will be reflected in the SMS OTP screen. If the last-4 digits of your mobile number are not the same as what are reflected on the screen, this means that your mobile number is not updated in our records.

If you wish to change or update your primary mobile number, you may do so through Citibank Online (Services > Profile & Settings > My Profile > Update Profile and Contact Details > Update Information) or the Citi Mobile® App (Profile & Settings > Personal Information > Edit).

If you are prompted to enter an SMS One-Time PIN (OTP), please check the pop up-screen if it displays the last-4 digits of your mobile number. The SMS OTP will only be sent to the primary mobile number registered in our system. If you wish to change or update your primary mobile number, you may do so through Citibank Online (Services > Profile & Settings > My Profile > Update Profile and Contact Details > Update Information) or the Citi Mobile® App (Profile & Settings > Personal Information > Edit).

If you are unable to receive the SMS OTP despite the pop-up screen showing the last-4 digits of your registered mobile number, then there may be an issue with your mobile service provider. Please restart your mobile phone or place it on airplane mode (if available) for 5-10 seconds to reset your cellular network connection. If the issue persists, please Contact Us.

Yes, the SMS OTP is usually free of charge except for cases wherein incoming SMS charges are imposed by your mobile service provider for international roaming.

Yes. The SMS OTP will be sent to your registered mobile number on record with us.

The SMS OTP will be required only for certain transactions on the Citi Mobile® App. We have updated the Citi Mobile® App's security authentication, to provide you with a more convenient and seamless mobile banking experience.

If you haven't updated to the latest security authentication, log in to your Citi Mobile® App now.

Upon successful update of your primary mobile number in our system, your SMS OTP will already be sent to your new mobile number.

Citi Secure Authentication Platform FAQs

 

We have updated the Citi Mobile App security authentication to provide you with a more convenient and seamless mobile banking experience. This will enable you to perform multiple authentications without the need for Unlock Codes or SMS OTPs for certain transactions. This in effect replaces the function of the Citi Mobile Token feature in your app.

After updating to the new version of the Citi Mobile® App, you will no longer be able to use the Citi Mobile Token, and will instead receive SMS OTPs to authenticate certain transactions.

When you log in with your device using the updated security authentication, the Citi Mobile® App will be able to recognize and authenticate you. So, there's no need for you to input an Unlock Code or SMS OTP for certain transactions, because the app has already confirmed you to be the person logged in. This means less steps, less waiting time, and faster processing of your banking transactions.

Yes, you will still be able to access the Citi Mobile® App (i.e. account summary) and you will continue to receive SMS OTPs to authenticate your transactions. Please note that certain transactions will be unavailable until you update to the security authentication.

You will still be able to benefit from the updated security authentication. However, to ensure a seamless customer experience, it is recommended to enable biometric login to update to the new security authentication feature.

No, you will not be affected by the updated security authentication feature. You will continue to receive SMS OTPs (One-Time PINs) for your transactions.

However, upon updating your security authentication, you will no longer be able to generate an OTP for your Citibank Online.

After registration, you will receive an email and SMS confirmation that you have successfully updated the app with the new security feature.

There may be an issue with your telco provider. Please try to restart your device or reset the airplane mode setting, if applicable. If the issue still persists, please call CitiPhone at +63 2 8995 9999 from 8AM to 9PM daily for further assistance.

Regardless of your location, you will be able to update your Citi Mobile App security feature so long as you are able to receive the SMS OTP confirmation. Make sure to update your contact details with the mobile number you will be using abroad, so you can receive the SMS OTP. Once you have updated to the new security feature, you will no longer be able to use your Citi Mobile® Token.

Proud Member of Bancnet

Member of the Philippine Deposit Insurance Corporation. Maximum deposit insurance for each depositor is P500,000. Subject to PDIC terms.