Which authentication protocol uses time-synchronized one-time passwords, often in six-digit form?

The story behind the answer

The authentication protocol that uses time-synchronized one-time passwords, often in six-digit form, is TOTP.

TOTP stands for time-based one-time password. It generates a short code from a shared secret and the current time, allowing a service and an authenticator app to calculate the same value independently. Codes commonly change every 30 seconds, though the exact period is determined by the implementation.

The method is specified in RFC 6238 and builds on HMAC-based one-time passwords, or HOTP. Authenticator applications often create TOTP codes after a secret is enrolled through a QR code. Because the code is based on a secret stored by both sides, protecting the enrollment secret is important.

TOTP is a form of multi-factor authentication when used alongside a password, but it is not phishing-resistant. A criminal can sometimes trick a user into entering a current code into a fake site. Hardware security keys using public-key cryptography provide stronger resistance to that type of attack.

Source: Wikipedia · fact-checked Sept. 2026

Add question to a list

Choose a list to keep this question in: