Why is there no login form on the desk?
Login happens inside the official FanCode web app. We do not host sign-in forms on the editorial desk to keep your credentials clear of the editorial surface.
Sign in to the FanCode web app via the official login page. Verified against the operator's authentication protocol. 18+ only.
The FanCode web login at fancodein.com is the official entry point. We do not host a sign-in form on this desk — sign in happens inside the official FanCode web app, secured by the operator's authentication protocol. Use a unique password and a working mobile number for two-factor verification.
| Symptom | Cause | Fix |
|---|---|---|
| OTP not received | Network delay / DND filter | Wait 60s · tap resend · verify network signal |
| Wrong password | Auto-fill / stored credential mismatch | Reset via in-app recovery · use unique password |
| Account locked | Multiple failed attempts | Wait 30 minutes · reset via OTP · contact in-app support |
| Restricted state | Andhra Pradesh · Assam · Odisha · Sikkim · Telangana · Nagaland | Cannot be onboarded by the operator — state-level regime restricts paid fantasy entry |
Login happens inside the official FanCode web app. We do not host sign-in forms on the editorial desk to keep your credentials clear of the editorial surface.
Six states currently restrict paid fantasy entry. If you are reading from one of them, the editorial coverage still applies but the contest register is not available to you.
Use the in-app recovery flow — it requests an OTP to your registered mobile and walks you through a password reset.
No. The editorial desk has no access to your wallet or account credentials. For issues, use the in-app support tab.
Two-factor verification (the OTP step) is the operator's primary defense against credential compromise. Even if your password leaks through a third-party breach, the OTP gates the new-device sign-in. The desk recommends enabling two-factor on the registered mobile number, not a secondary email — mobile OTP is harder to redirect than email OTP.
Sign out of inactive devices, especially shared devices. The operator's in-app session-management screen lists every active session with the device model and last-active timestamp. Revoke any session that you don't recognise. The desk flags this as a routine hygiene step, not an emergency measure.
The desk has no access to your account credentials, OTP verification, or session state. We don't see whether your login attempt succeeded. For login issues — wrong password, OTP not received, account locked — the operator is the only path forward. The in-app Help & Support tab is the fastest route.
Where the operator sends you a notice of unusual sign-in activity, take it seriously. Read the device model and IP region. If the activity isn't yours, change your password immediately and revoke the session.
The desk's editorial posture on account security: use a unique password, enable two-factor verification (the OTP step), and review active sessions periodically under "Manage Sessions" inside the in-app Profile. The operator publishes these as routine hygiene; the desk's reading matches the operator's posture.
The desk does not recommend using the same password across multiple services. A breach on one service exposes every other service where the same password is used. Use a password manager for unique passwords; the operator's app does not require a password in the strictest sense — sign-up is by OTP — but the web app uses a password for the second-factor layer.
If you receive a "unusual sign-in activity" notice from the operator, read it carefully. Check the device model and the IP region. If the activity isn't yours, change your password immediately and revoke the session from the in-app Profile. The operator's customer-care team will not ask for your password by phone or email — any message asking for the credential is a phishing attempt.
Where the operator publishes a security advisory (e.g. a third-party library vulnerability disclosed and patched), the desk adds the advisory to the editorial coverage. Where the desk cannot verify the operator's claim, the desk says so explicitly. The desk does not publish claims it cannot verify.