It’s a 6 digit pin. Doesn’t seem worthwhile to hash. What are the best practices here? I’m not sure
There should never be a need to return a pin to the client. You’ve already texted/emailed it to them. They are going to send it back to you. You will check against your temporary storage, verify/reject, and delete it immediately after.