---
title: "TOTP — Identity Glossary | IDSync"
description: "TOTP is the algorithm behind authenticator-app codes (Google Authenticator, Authy, 1Password) — a 6-digit code that changes every 30 seconds, derived from a…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://idsync.com/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Glossary",
          "item": "https://idsync.com/glossary"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "TOTP",
          "item": "https://idsync.com/glossary/totp"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "DefinedTerm",
      "@id": "https://idsync.com/glossary/totp",
      "name": "TOTP",
      "alternateName": [
        "Time-Based One-Time Password",
        "authenticator app",
        "RFC 6238"
      ],
      "description": "TOTP is the algorithm behind authenticator-app codes (Google Authenticator, Authy, 1Password) — a 6-digit code that changes every 30 seconds, derived from a shared secret and the current time.",
      "url": "https://idsync.com/glossary/totp",
      "inDefinedTermSet": "https://idsync.com/glossary"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Is TOTP good enough in 2026?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "For low-to-medium risk it's acceptable. For admin, financial, or regulated workloads, prefer phishing-resistant factors: passkeys, WebAuthn, hardware keys."
          }
        },
        {
          "@type": "Question",
          "name": "TOTP vs HOTP?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "HOTP (RFC 4226) is counter-based; TOTP is time-based. TOTP is the dominant modern variant."
          }
        }
      ]
    }
  ]
---

[![IDSync — identity software buyer platform](/assets/idsync-logo-BKS89EW4.png)](/)

[Directory](/directory)

[Compare](/compare)

[Resources](/resources)

[Browse tools](/directory)[Run Stack Finder](/stack-finder)

1.  [Home](/)
2.  [Glossary](/glossary)
3.  TOTP 

Multi-Factor Authentication

# TOTP (Time-Based One-Time Password)

TOTP is the algorithm behind authenticator-app codes (Google Authenticator, Authy, 1Password) — a 6-digit code that changes every 30 seconds, derived from a shared secret and the current time.

Last reviewed 3 months ago

Key points

-   Defined in RFC 6238
-   Shared secret + current timestamp → 6-digit code
-   Works offline; no SMS dependency
-   Vulnerable to real-time phishing (attacker-in-the-middle)
-   Acceptable second factor but no longer phishing-resistant by NIST/CISA standards

## What it is

TOTP (Time-Based One-Time Password, RFC 6238) is the algorithm that powers authenticator apps. When you scan a QR code at setup, you're sharing a secret seed; the app combines that seed with the current 30-second time window to produce a 6-digit code.

## How it works

`code = HMAC-SHA1(secret, floor(unixtime / 30))` truncated to 6 digits. Server and client compute the same value independently — no network needed at sign-in time.

## When buyers care

-   Replacing SMS as a second factor (TOTP is stronger than SMS)
-   Adding MFA quickly without rolling out hardware keys
-   Backup factor when passkeys aren't available

## Common misconceptions

-   **TOTP is not phishing-resistant.** An attacker phishing your password can ask for the TOTP in real time and replay it.
-   **TOTP secrets need backup.** Losing the phone without backup locks the user out — plan recovery flows.

## FAQ

### Is TOTP good enough in 2026?

For low-to-medium risk it's acceptable. For admin, financial, or regulated workloads, prefer phishing-resistant factors: passkeys, WebAuthn, hardware keys.

### TOTP vs HOTP?

HOTP (RFC 4226) is counter-based; TOTP is time-based. TOTP is the dominant modern variant.

IDSync provides educational buyer guidance based on publicly available information, editorial review, and user-submitted data. Vendor information should be verified before purchase. [Who we are, our methodology & disclosure policy](/about).

### One identity concept, explained per issue

Get vendor-neutral identity explainers and market updates in your inbox.

Work email\* 

Name

Company

Role (optional)

Interests (optional)

Pick what you want more of.

IAMCIAMSSO/MFAIGA/PAMSCIM/provisioningAI agent identityVendor updatesSecurity incidents

Subscribe

Twice-monthly identity digest. Curated, vendor-neutral. Unsubscribe any time.

### Vendor categories

[mfa](/directory/category/mfa)

### Vendors to evaluate

[okta](/directory/okta)[duo](/directory/duo)[yubico](/directory/yubico)

### Not sure which tool you need?

Run the IAM Stack Finder for a vendor-neutral shortlist tailored to your stack.

[Run the Stack Finder](/stack-finder)

### Explore tools for this topic

Browse vetted vendors in the mfa category.

[Explore tools](/directory/category/mfa)

[![IDSync home](/assets/idsync-logo-BKS89EW4.png)](/)

The buyer-focused platform for identity, access, and authentication software.

#### Platform

-   [Home](/)
-   [IAM Stack Finder](/stack-finder)
-   [Directory](/directory)
-   [Resources](/resources)
-   [State of AI Agent Identity 2026](/reports/state-of-ai-agent-identity-2026)
-   [Buyer Guides](/guides)
-   [Glossary](/glossary)
-   [Newsletter](/newsletter)
-   [Newsletter Archive](/newsletter/archive)

#### Best of guides

-   [All comparisons](/compare)
-   [All vendor alternatives](/alternatives)
-   [Best SSO tools](/compare/best-sso-tools)
-   [Best MFA tools](/compare/best-mfa-tools)
-   [Best PAM tools](/compare/best-pam-tools)
-   [Best IGA tools](/compare/best-iga-tools)
-   [Best CIAM tools](/compare/best-ciam-tools)
-   [Best passwordless auth](/compare/best-passwordless-authentication-tools)
-   [Best identity security](/compare/best-identity-security-tools)
-   [Best machine identity](/compare/best-machine-identity-tools)
-   [Best SaaS access governance](/compare/best-saas-access-governance-tools)
-   [Best developer auth](/compare/best-developer-authentication-tools)
-   [Best for startups](/compare/best-iam-tools-for-startups)
-   [Best for enterprises](/compare/best-iam-tools-for-enterprises)
-   [Best SCIM tools](/compare/best-scim-provisioning-tools)
-   [Best for AI agents](/compare/best-ai-agent-identity-tools)
-   [Best NHI tools](/compare/best-nhi-management-tools)
-   [Okta pricing explained](/guides/okta-pricing)
-   [Auth0 pricing explained](/guides/auth0-pricing)
-   [Okta alternatives](/alternatives/okta)
-   [Auth0 alternatives](/alternatives/auth0)

#### For Vendors

-   [Sponsor](/sponsor)
-   [Badges](/badges)
-   [Submit Product](/submit-product)
-   [Claim Profile](/claim-profile)
-   [Partner](/partner)

#### Company

-   [About & Methodology](/about)
-   [Contact](/contact)
-   [Privacy](/privacy)

Vendor names, logos, and trademarks are the property of their respective owners. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated. Logos are displayed for identification purposes only.

IDSync (idsync.com) is operated by TetraCore, Bowling Green, Ohio. It is not affiliated with the IDSync® Active Directory synchronizer by Identity Syncronizer — [learn more](/about#idsync-disambiguation).

© 2026 IDSync. All rights reserved.

Editorial independence. Sponsored placements are clearly disclosed.