One-Time Password (OTP)
What is One-Time Password (OTP)?
One-Time Password (OTP)A short numeric code that is valid for only a single login attempt or a brief time window, typically used as a second authentication factor.
A One-Time Password (OTP) is a credential valid for a single use, so a captured code is worthless to an attacker after the moment it is spent. Modern OTPs are computed from a shared secret held by both an authenticator (app or hardware token) and the server. HOTP (RFC 4226) truncates an HMAC-SHA-1 of a monotonically increasing event counter into a 6–8 digit code; TOTP (RFC 6238) replaces the counter with Unix time divided by a step, defaulting to 30 seconds, which is why authenticator apps refresh on that cadence. OCRA (RFC 6287) binds the code to a server challenge or transaction data, and the older S/KEY/OTP scheme (RFC 1760/2289) hash-chained secrets for one-time use.
Delivery over SMS or email is common but weak: SS7 interception, SIM swapping, and mobile malware all expose the code, and NIST SP 800-63B has restricted SMS as an out-of-band channel since 2017.
The core limitation is that any OTP a human can read and retype can be relayed in real time. Adversary-in-the-middle phishing kits such as Evilginx and EvilProxy proxy the login, capture the OTP, and replay it within its validity window. For high-value accounts, prefer phishing-resistant, origin-bound factors — FIDO2/WebAuthn passkeys — which cannot be relayed this way.
flowchart TD
A[Shared secret provisioned to app and server] --> B{OTP type}
B -->|HOTP| C[Increment event counter]
B -->|TOTP| D[Read current time / 30s step]
C --> E[HMAC-SHA-1 of counter or timestep]
D --> E
E --> F[Truncate to 6-8 digit code]
F --> G[User submits code at login]
G --> H{Server recomputes and compares within window}
H -->|Match| I[Second factor accepted]
H -->|No match| J[Rejected]● Examples
- 01
A six-digit TOTP code displayed in Google Authenticator every 30 seconds.
- 02
An SMS message containing a one-time code to authorize a bank transfer.
● Frequently asked questions
What is One-Time Password (OTP)?
A short numeric code that is valid for only a single login attempt or a brief time window, typically used as a second authentication factor. It belongs to the Identity & Access category of cybersecurity.
What does One-Time Password (OTP) mean?
A short numeric code that is valid for only a single login attempt or a brief time window, typically used as a second authentication factor.
How do you defend against One-Time Password (OTP)?
Defences for One-Time Password (OTP) typically combine technical controls and operational practices, as detailed in the full definition above.
What are other names for One-Time Password (OTP)?
Common alternative names include: OTP, Single-use password.