Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Authenticator apps calculate login codes locally from a shared secret and the current time; the service independently calculates the value it expects. The six-digit code is therefore a short-lived output of the TOTP algorithm, not a code sent to your phone at each login. That makes TOTP useful as an extra possession factor, but manually entered codes are not phishing-resistant.

How does an authenticator app generate a TOTP code?

TOTP stands for time-based one-time password. It extends HOTP, the HMAC-based one-time-password algorithm. When you enroll an authenticator, it and the service’s verifier are provisioned with the same secret and compatible settings. The app and verifier then independently use that secret and a time-derived counter to calculate a code.

RFC 6238 defines the counter as T = floor((current Unix time − T0) / X). Unix time counts seconds from the Unix epoch; T0 is the starting time, defaulting to that epoch, and X is the time-step size, defaulting to 30 seconds. These are system parameters established during provisioning, so the defaults are not a guarantee that every service uses identical settings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The counter is fed into HOTP, which computes an HMAC and truncates the result to a short, human-readable value. RFC 6238 describes HMAC-SHA-1 as the HOTP basis and permits TOTP implementations to use HMAC-SHA-256 or HMAC-SHA-512. The algorithm, secret, and output settings must be compatible at both ends; not every app or service necessarily uses the same hash or digit count. See the IETF’s RFC 6238 for the specification.

#1 Best Overall
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

A useful mental model is two copies of a recipe and the same secret ingredient: the app and login service calculate the same result for the same time interval. The app does not receive a freshly generated code from the service each time. The shared secret is the long-lived credential behind the rotating display, so protecting enrollment data such as a setup secret or QR code is important.

Why does the code keep changing, and what does the countdown mean?

The app displays the code for the current time-step counter. When time crosses into the next step, the counter changes and the calculated code changes too. The countdown shows how much of the current step remains; if you open the app just after a step begins, most of the interval remains, while a code viewed near the end may have only a few seconds left.

Rank #2
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

RFC 6238 recommends a 30-second step as a balance between security and usability. A verifier may accept a limited range around the current step to account for clock differences, network delay, and the time it takes to enter the digits. That acceptance window is service-specific. A wider window can accommodate more delay, but it also lengthens the time during which an exposed code may be usable. The RFC recommends bounded tolerance and says no more than one time step should be allowed for network delay; NIST likewise calls for a defined validity lifetime that accounts for expected clock drift, network delay, and claimant entry time.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why might a TOTP code be rejected?

A mismatch can come from clocks that differ, submitting at a time-step boundary, copying a code from the wrong account entry, or an enrollment mismatch involving the secret or algorithm parameters. Standards identify timing and drift as verifier concerns, but the exact error message and recovery flow depend on the service.

Rank #3
Thetis Nano-C FIDO2 Security Key Hardware Passkey Device with USB Type C, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key – Plug-and-stay or carry on a keychain. This USB-C hardware security key offers portable, always-on protection for desktop and mobile use.(Item Size: 0.73 X 0.60 X 0.30 inches)
  • USB-C Hardware Key for All Devices – Works with USB-C ports on PC, Mac, Android, and USB-C iPhones. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key – Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey – Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication – Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
  • Check that your device’s date and time are set automatically.
  • Confirm the account label in the authenticator before copying the digits.
  • Enter the current code promptly. If it is nearly at the end of its interval, wait for a fresh code and try that one.
  • If the issue continues, follow the service’s official recovery or re-enrollment instructions.

These checks may help identify common causes, but no single fix is guaranteed for every provider. Never share or post a setup QR code or secret: someone who obtains it can generate matching codes.

What happens when you change or lose your phone?

There is no universal migration or recovery flow. RFC 6238 does not define provisioning, and providers and authenticator apps differ in how they handle setup, export, migration, and recovery. Follow the account provider’s current instructions and keep its recovery method available.

Rank #4
SecuX PUFido USB-C Security Key with PUF Technology, FIDO2/U2F Certified, Hardware-Rooted Unclonable Security for Passwordless Login and 2FA Authentication
  • A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
  • FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
  • Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
  • Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
  • Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.

NIST SP 800-63B-4 advises rebinding a software OTP application to the subscriber account on a replacement device and invalidating the old binding, or using an eligible sync fabric that meets the guidance’s requirements. NIST published SP 800-63B-4 in July 2025, superseding the prior edition; its current guidance is available from the NIST Digital Identity Guidelines.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Are authenticator app codes safe?

TOTP can add a possession factor alongside a password. NIST classifies OTP authenticators as “something you have.” The method has important limits, however: the verifier also needs the symmetric secret to calculate expected codes, and the short numeric output can be guessed. NIST calls for rate limiting when an output is under 64 bits. Verifiers should also accept a code only once while it is valid, to limit replay after successful use.

Best Value
Sale
Thetis Pro-A FIDO2 Security Key Passkey Device with USB A & NFC, TOTP/HOTP Authenticator APP, FIDO 2.0 Two Factor Authentication 2FA MFA, Works with Windows/macOS/Linux/Gmail/Facebook/Dropbox/GitHub
  • FIDO2/Passkey Authentication – Secure, passwordless login with supported platforms. Check if your intended service supports hardware keys before purchase. Works with Gmail, Facebook, GitHub, Dropbox, and more.
  • Enhanced Multi-Factor Authentication (MFA): Strengthen account security using either FIDO2.0 authentication or TOTP/HOTP codes, providing flexible options for added protection.
  • Universal Connectivity: Features USB-A and NFC compatibility, making it easy to use across various devices including PCs, Macs, iPhones, and Android phones for seamless integration.
  • Durable & Portable Design: Built with a 360° rotating metal cover for extra durability. Compact and lightweight, it easily attaches to a keychain for on-the-go convenience. No batteries or network required, ensuring dependable use anywhere.
  • FIDO Certified & Business-Ready: Certified for FIDO standards and supported by a range of management software suites, ideal for both individual users and enterprise deployment.

Why TOTP does not stop phishing

A fake login site can ask you for a current code and relay it to the real service before it expires. The code is not bound to the particular site or login session where you entered it. NIST SP 800-63B-4 states: “Authenticators that involve the manual entry of an authenticator output (e.g., out-of-band and OTP authenticators) SHALL NOT be considered phishing-resistant because the manual entry does not bind the authenticator output to the specific session being authenticated.”

If phishing resistance matters, consider passkeys or security keys using WebAuthn/FIDO2. NIST describes verifier-name binding as a phishing-resistant method and cites WebAuthn as an example. At AAL2, NIST requires verifiers to offer at least one phishing-resistant option. Availability and setup differ by service, so compare supported sites, portability, recovery, and how each method binds authentication to the genuine site rather than assuming every configuration works everywhere.

How do TOTP apps, hardware tokens, and passkeys differ?

Method How you authenticate Phishing resistance Setup and compatibility
TOTP smartphone app The app calculates a time-based code that you copy into the login page. Not phishing-resistant: manual entry does not bind the code to the login session. Requires enrollment with the service and protection of the shared secret. Provider support varies.
TOTP hardware token A dedicated device generates a time-based code for manual entry. Not phishing-resistant for the same manual-entry reason. NIST lists this as an OTP authenticator example. Check that the specific token is compatible with the account service.
Passkey or security key using WebAuthn/FIDO2 Authentication uses verifier-name binding rather than asking you to relay a short OTP. Can provide phishing resistance through binding to the genuine verifier. Supported services, setup, portability, and recovery vary; confirm the account’s options.

NIST’s implementation resources list both a TOTP smartphone app and a TOTP hardware device as single-factor OTP examples. A hardware token is therefore a real alternative if you prefer a dedicated device, but compatibility with a particular website must be checked directly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.