Skip to content
Vol. 1 · Ed. 2026
CyberGlossary
Entry № 850

One-Time Password (OTP)

Reviewed byCybersecurity entrepreneur & security researcher

What is One-Time Password (OTP)?

One-Time Password (OTP)A short numeric code that is valid for only a single login attempt or a brief time window, typically used as a second authentication factor.


A One-Time Password (OTP) is a credential valid for a single use, so a captured code is worthless to an attacker after the moment it is spent. Modern OTPs are computed from a shared secret held by both an authenticator (app or hardware token) and the server. HOTP (RFC 4226) truncates an HMAC-SHA-1 of a monotonically increasing event counter into a 6–8 digit code; TOTP (RFC 6238) replaces the counter with Unix time divided by a step, defaulting to 30 seconds, which is why authenticator apps refresh on that cadence. OCRA (RFC 6287) binds the code to a server challenge or transaction data, and the older S/KEY/OTP scheme (RFC 1760/2289) hash-chained secrets for one-time use.

Delivery over SMS or email is common but weak: SS7 interception, SIM swapping, and mobile malware all expose the code, and NIST SP 800-63B has restricted SMS as an out-of-band channel since 2017.

The core limitation is that any OTP a human can read and retype can be relayed in real time. Adversary-in-the-middle phishing kits such as Evilginx and EvilProxy proxy the login, capture the OTP, and replay it within its validity window. For high-value accounts, prefer phishing-resistant, origin-bound factors — FIDO2/WebAuthn passkeys — which cannot be relayed this way.

flowchart TD
  A[Shared secret provisioned to app and server] --> B{OTP type}
  B -->|HOTP| C[Increment event counter]
  B -->|TOTP| D[Read current time / 30s step]
  C --> E[HMAC-SHA-1 of counter or timestep]
  D --> E
  E --> F[Truncate to 6-8 digit code]
  F --> G[User submits code at login]
  G --> H{Server recomputes and compares within window}
  H -->|Match| I[Second factor accepted]
  H -->|No match| J[Rejected]

● Examples

  1. 01

    A six-digit TOTP code displayed in Google Authenticator every 30 seconds.

  2. 02

    An SMS message containing a one-time code to authorize a bank transfer.

● Frequently asked questions

What is One-Time Password (OTP)?

A short numeric code that is valid for only a single login attempt or a brief time window, typically used as a second authentication factor. It belongs to the Identity & Access category of cybersecurity.

What does One-Time Password (OTP) mean?

A short numeric code that is valid for only a single login attempt or a brief time window, typically used as a second authentication factor.

How do you defend against One-Time Password (OTP)?

Defences for One-Time Password (OTP) typically combine technical controls and operational practices, as detailed in the full definition above.

What are other names for One-Time Password (OTP)?

Common alternative names include: OTP, Single-use password.

● Related terms

● See also