Join 5,000+ subscribers getting weekly tips on web development, mobile apps, and AI solutions.
A one-time code computed from a shared secret and a counter that increases each time a code is used.
HOTP is defined in RFC 4226 and is the basis for TOTP. Instead of time, it uses a counter that both sides increment after each use. The HMAC of the counter, cut down to a few digits, is the code. Because the counter can drift, for example when a hardware token's button is pressed without the code being used, servers usually accept a small look-ahead window, and apps can resynchronise by searching a few counter values ahead.
Our expert team can help you leverage HOTP (HMAC-Based One-Time Password) in your project.
Get Free Consultation