Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A time-based one-time password (TOTP) is a short code calculated from a shared secret and the current time. An authenticator app or hardware token generates it, and a verifier checks it using the same secret and time-step settings. The common 30-second interval is the default in the TOTP standard—not a guarantee that every service accepts a code for exactly 30 seconds.

What TOTP means

TOTP stands for Time-Based One-Time Password. It is the time-based version of HOTP, a one-time-password method whose changing input is an event counter. TOTP replaces that event counter with a counter derived from time, so the authenticator and verifier can independently calculate the same code during a time step.

The method is specified in IETF RFC 6238, published in 2011. NIST’s current digital identity guidance is SP 800-63B-4, whose final publication date is July 31, 2025; it supersedes the previous SP 800-63B edition.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How a TOTP code is generated

The authenticator and verifier need the same secret (or a way to derive it) and matching time-step parameters. Each uses the secret with an HMAC calculation and a counter based on Unix time. In RFC 6238’s notation, the counter is T = floor((current Unix time − T0) / X), where X is the step length in seconds and T0 is the starting time.

#1 Best Overall
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • The RFC defaults are X = 30 seconds and T0 = 0, the Unix epoch.
  • With those defaults, the counter is 1 at 59 seconds after the epoch and 2 at 60 seconds.
  • RFC 6238 permits HMAC-SHA-256 or HMAC-SHA-512 alternatives to the HOTP SHA-1 construction. The service and authenticator still need compatible provisioning and parameters; support for every option is not universal.

The code changes when the counter advances. The 30-second default describes the step used to calculate it, not necessarily the full period during which a service will accept it.

How long a TOTP code works

There are two related timings: when the displayed code rolls over and the verifier’s acceptance window. A verifier may allow a bounded range of adjacent time steps to accommodate clock drift, network delay, or the time a person needs to enter the code. As a result, a code can sometimes be accepted beyond the step in which it first appeared, depending on the service’s policy.

Rank #2
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

RFC 6238 advises validators to consider prior steps according to their delay policy and warns that accepting a wider window increases exposure; it recommends no more than one time step for network delay. NIST SP 800-63B-4 says the verifier must set a lifetime that accounts for expected clock drift over the authenticator’s lifetime, network delay, and user entry time. It also requires the verifier to accept a particular OTP only once while it is valid, and calls for rate limiting; rate limiting is required when the authenticator output is less than 64 bits.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where TOTP is used and what it requires

A service enrolls an authenticator by provisioning secret material and the parameters needed to generate matching codes. That authenticator may be a smartphone application or a dedicated hardware device; NIST lists both as examples. The service must support the authenticator’s provisioning format, so a token should not be assumed to work with an account until compatibility is confirmed.

Rank #3
Thetis Nano-C FIDO2 Security Key Hardware Passkey Device with USB Type C, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key – Plug-and-stay or carry on a keychain. This USB-C hardware security key offers portable, always-on protection for desktop and mobile use.(Item Size: 0.73 X 0.60 X 0.30 inches)
  • USB-C Hardware Key for All Devices – Works with USB-C ports on PC, Mac, Android, and USB-C iPhones. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key – Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey – Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication – Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Because the secret is needed to generate and verify codes, it must be protected on both sides. RFC 6238 recommends secure storage and restricted access to secret material, while NIST requires strong protection for verifier-side symmetric keys. Users should also consider how they will protect access to their authenticator and recover access if the device is lost; recovery arrangements depend on the service.

Is TOTP secure against phishing?

No. TOTP can add a possession-based step to sign-in, but it is not phishing-resistant. NIST states, “OTP authentication is not phishing-resistant.” A manually entered code is not bound to the legitimate website or session: someone can trick a user into entering a live code on an impostor site and relay it to the real verifier.

Rank #4
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

A dedicated hardware token does not change that limitation if it produces a code the user types in. NIST identifies cryptographic authentication with channel binding or verifier-name binding as phishing-resistant approaches; WebAuthn is an example of verifier-name binding. TOTP can still be useful, but its short lifetime should not be confused with protection against credential relay or every form of account takeover.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Software app or hardware token?

Both forms can generate TOTP codes, and both remain OTP methods. The better fit depends on service support and how you plan to access, protect, and recover the enrolled secret.

Best Value
Sale
Thetis Pro-A FIDO2 Security Key Passkey Device with USB A & NFC, TOTP/HOTP Authenticator APP, FIDO 2.0 Two Factor Authentication 2FA MFA, Works with Windows/macOS/Linux/Gmail/Facebook/Dropbox/GitHub
  • FIDO2/Passkey Authentication – Secure, passwordless login with supported platforms. Check if your intended service supports hardware keys before purchase. Works with Gmail, Facebook, GitHub, Dropbox, and more.
  • Enhanced Multi-Factor Authentication (MFA): Strengthen account security using either FIDO2.0 authentication or TOTP/HOTP codes, providing flexible options for added protection.
  • Universal Connectivity: Features USB-A and NFC compatibility, making it easy to use across various devices including PCs, Macs, iPhones, and Android phones for seamless integration.
  • Durable & Portable Design: Built with a 360° rotating metal cover for extra durability. Compact and lightweight, it easily attaches to a keychain for on-the-go convenience. No batteries or network required, ensuring dependable use anywhere.
  • FIDO Certified & Business-Ready: Certified for FIDO standards and supported by a range of management software suites, ideal for both individual users and enterprise deployment.
Authenticator form What to check Security limitation
Software TOTP application Whether the service supports its provisioning format, how the secret is protected, and how access can be recovered if the device is unavailable. The code is still manually entered and is not phishing-resistant.
Hardware TOTP device Whether the service supports the token’s provisioning format, how the secret is protected, and what recovery option is available if the device is lost. A dedicated device does not bind a manually entered code to the legitimate site or session.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.