- Home
- |
- Ways to Bank
- |
- Online and Mobile Services
- |
- Citi Mobile® Token
<IMPORTANT NOTICE> Citi Mobile Token authentication service will be discontinued by 2024 second quarter
To further enhance digital banking’s safety, you will make more secure authentication with Citi Mobile® App Enhanced Security Function. Tap here to learn more.
At Citibank, we are committed to making Citibank Online a secure banking environment for you. Additional authentication is required for designated online transactions where a higher level of security is needed.
A built-in security token, Citi Mobile® Token, replacing other methods like physical Security Device or One-Time Password (OTP) via SMS, lets you generate an OTP for authenticating designated transactions via Citi Mobile® App anytime, anywhere.

Secure
Protected by a 6-digit Unlock Code chosen by you, and restricted to one mobile device of your choice.
Instant
Direct generation of an OTP, without the need to wait for a SMS anymore.
Convenient
Generate an OTP anytime without a physical Security Device or network connection.Examples of transactions requiring OTP
- Payments & Transfers
- Enroll/View e-Statement
- Stock Trading
Physical Security Device
![]() |
Please note that we no longer accept any new request or replacement request for customers holding physical security device. We recommend customers to download Citi Mobile® App and enable Citi Mobile® Token to enjoy a more convenient experience. To activate your physical security device, please log on to Citibank Online, select "My Profile" > "Security Device Activation" .
|
![]() |
Physical Security Device : Press the green button on the device |
![]() |
Physical Security Device : Click here to view the steps |
One-Time Password (OTP)
Second-level authentication is required for certain online transactions. You will be asked to input OTP when performing these transactions. The OTP can be generated by the Citi Mobile® Token or a Security Device, OR can be received from your registered mobile number via SMS.
Transaction Signing is a more sophisticated authentication process for designated online transactions that require stronger protection. You will need to perform transaction signing using the Citi Mobile® Token or a Security Device in order to add a new payee (local payee or overseas payee).
This is for your added security protection. The One-Time Password and Transaction Signing serve as additional information on top of Card Number and PIN for authentication.
Your Citibank Online User ID and Password remains unchanged. You do not need a One-Time Password to login to Citibank Online.
One-Time Password applies to both session level (require once per logon session) and transaction level (require for certain transaction in the same logon session). Online transactions that require a One-Time Password are those that require a higher level of security. Examples of transactions requiring second-level authentication:
- • Payments and transfers
- • Enroll/view e-Statements
No, you only need to perform transaction signing for Adding a New Payee (Local Payee or Overseas Payee).
You will need to perform transaction signing using a Citi Mobile® Token or Security Device in order to add a new payee (local payee or overseas payee). During the process of transaction signing, you will enter a Challenge Code, which will be displayed on Citibank Online when you perform the transaction, into the Citi Mobile® Token or the Security Device to generate a Transaction Authorization Code (TAC) to authorize the transaction.
Credit card only clients will have the option to add a new Merchant payee using the authentication process of Online Authorization Code (OAC) sent to your registered mobile number via SMS. Hence it is not necessary to request for a Security Device.
Physical Security Device
Your physical security device is a personalized device. when a higher level of security is required, you can generate a 6-digit One-Time Password that works with your account only or complete a Transaction Signing with the physical security device to enhance online banking security.
Please activate your physical security device at Citibank Online before use. Logon to Citibank Online, select "My Profile" > "Security Device Activation"
No. The physical security device is free of charge.
If you lose your physical security device, please call CitiPhone Banking (852) 2860 0333.
If physical security device is damaged, we recommend you to download Citi Mobile® App and enable Citi Mobile® Token to enjoy a more convenient experience.
The physical security device sent to you has been assigned to your profile, and you will have to activate it in Citibank Online before use. This will prevent others from using your physical security device during delivery.
DOs | DON'Ts |
Keep your physical security device in a safe and secured place at all times. | Allow anyone to use or obtain your physical security device. |
Store your physical security device in a dry and cool environment, away from water or extremely high temperatures. | Leave your physical security device unattended or exposed with the One-Time Password displayed on the screen. |
Personalize your physical security device so that it is recognizable by you. | Reveal your physical security device serial number or One-Time Password to anyone. |
If you lose your physical security device, please call CitiPhone Banking (852) 2860 0333. If physical security device is damaged, we recommend you to download Citi Mobile® App and enable Citi Mobile® Token to enjoy a more convenient experience. |
Drop your physical security device from great heights, step on it, or attempt to dismantle it. |
Inform us when the message "BATT" appears on your physical security device. This indicates that the battery is running low. | Label your physical security device with your name, passport number or any other information that may identify you as the owner of the Security Device. |
One-Time Password (OTP) SMS
Yes, the One-Time Password (OTP) SMS can be sent to both Hong Kong and overseas mobile phone numbers.
Please click here to download an application form to update your mobile number. After successful update, the OTP will be sent to the new mobile phone number.
|
Download Citi Mobile® App and enable Citi Mobile® Token today. ![]() ![]() Click here to learn more about Citi Mobile® |