What Is TOTP? How Time-Based One-Time Passwords Work

TOTP is the technology behind most authenticator apps. A shared secret key and the current time are combined to produce a 6-digit code that changes every 30 seconds – the code you type as your second factor in 2FA.

Last updated: October 8, 2026

How TOTP works

TOTP stands for Time-based One-Time Password. It is defined in RFC 6238 and builds on the counter-based HOTP algorithm from RFC 4226. The idea is simple: your device and the service share a secret, and both use the clock to calculate the same code.

  1. Shared secret. When you enable 2FA, the service gives you a secret key (see what is a 2FA key). Your authenticator stores it and so does the service.
  2. Time step. Both sides take the current Unix time and divide it into 30-second steps. Everyone in the same 30-second window gets the same step number.
  3. HMAC. The step number is processed together with the secret using an HMAC function (SHA-1 by default).
  4. Truncation. A few bytes of the result are turned into a number and reduced to six digits. That is the code you see.
  5. Comparison. You type the code, the service calculates its own, and access is granted if they match. Many services also accept the neighbouring time step to allow for small clock differences.

No code is sent to your device by the service. Your authenticator calculates it locally, which is why TOTP keeps working without a mobile signal.

Why your device clock matters

Because the code depends on the time, a clock that is a minute or two off produces codes the service does not expect. If a correct key gives rejected codes, switch on automatic date and time on your device and try again.

TOTP vs HOTP

TOTPHOTP
Input besides the secretCurrent time (30-second steps)A counter that increases with each use
StandardRFC 6238RFC 4226
Code lifetimeExpires automatically after the time stepValid until used or until the counter moves on
Typical useAuthenticator apps and online authenticatorsSome older hardware tokens

Standard TOTP settings

Most services use the defaults: SHA-1, 6 digits and a 30-second period. A few use SHA-256 or SHA-512, 8 digits or a different period. 2FA Auth supports the common defaults (SHA-1, 6 digits, 30 seconds). If a QR code asks for different settings, the tool tells you that it is not supported instead of showing a wrong code.

Strengths and limits of TOTP

TOTP in your browser

An online TOTP authenticator performs the same calculation inside a web page. In 2FA Auth the HMAC step uses the browser’s built-in Web Crypto API, so you can generate a TOTP code online from a secret key or QR code without installing anything. Read how this site handles your key before you decide whether it fits your needs.