What Is TOTP? How Time-Based One-Time Passwords Work
TOTP is the technology behind most authenticator apps. A shared secret key and the current time are combined to produce a 6-digit code that changes every 30 seconds – the code you type as your second factor in 2FA.
How TOTP works
TOTP stands for Time-based One-Time Password. It is defined in RFC 6238 and builds on the counter-based HOTP algorithm from RFC 4226. The idea is simple: your device and the service share a secret, and both use the clock to calculate the same code.
- Shared secret. When you enable 2FA, the service gives you a secret key (see what is a 2FA key). Your authenticator stores it and so does the service.
- Time step. Both sides take the current Unix time and divide it into 30-second steps. Everyone in the same 30-second window gets the same step number.
- HMAC. The step number is processed together with the secret using an HMAC function (SHA-1 by default).
- Truncation. A few bytes of the result are turned into a number and reduced to six digits. That is the code you see.
- Comparison. You type the code, the service calculates its own, and access is granted if they match. Many services also accept the neighbouring time step to allow for small clock differences.
No code is sent to your device by the service. Your authenticator calculates it locally, which is why TOTP keeps working without a mobile signal.
Why your device clock matters
Because the code depends on the time, a clock that is a minute or two off produces codes the service does not expect. If a correct key gives rejected codes, switch on automatic date and time on your device and try again.
TOTP vs HOTP
| TOTP | HOTP | |
|---|---|---|
| Input besides the secret | Current time (30-second steps) | A counter that increases with each use |
| Standard | RFC 6238 | RFC 4226 |
| Code lifetime | Expires automatically after the time step | Valid until used or until the counter moves on |
| Typical use | Authenticator apps and online authenticators | Some older hardware tokens |
Standard TOTP settings
Most services use the defaults: SHA-1, 6 digits and a 30-second period. A few use SHA-256 or SHA-512, 8 digits or a different period. 2FA Auth supports the common defaults (SHA-1, 6 digits, 30 seconds). If a QR code asks for different settings, the tool tells you that it is not supported instead of showing a wrong code.
Strengths and limits of TOTP
- Stronger than SMS codes because there is no message to intercept and no phone number to hijack.
- Works offline after the secret has been added.
- Still phishable. A fake website can ask for your current code and use it straight away. Hardware security keys resist this better.
- The secret is the weak point. Anyone who obtains it can generate your codes, so store it carefully.
TOTP in your browser
An online TOTP authenticator performs the same calculation inside a web page. In 2FA Auth the HMAC step uses the browser’s built-in Web Crypto API, so you can generate a TOTP code online from a secret key or QR code without installing anything. Read how this site handles your key before you decide whether it fits your needs.