Join 5,000+ subscribers getting weekly tips on web development, mobile apps, and AI solutions.
A short code, usually 6 digits, that an authenticator app computes from a shared secret and the current time and that changes every 30 seconds.
TOTP is defined in RFC 6238. At setup the service and your authenticator app share a secret. Both then compute the same code independently: they divide the current time into steps (30 seconds is typical), run an HMAC of the step number with the secret, and cut the result down to a few digits. Because the code is computed on your device, it works offline and never travels over the phone network, which avoids SMS interception and SIM-swap attacks. It is still a shared secret, so it does not stop a fake sign-in page from passing your code to the real site in real time.
Our expert team can help you leverage TOTP (Time-Based One-Time Password) in your project.
Get Free Consultation