How authenticator codes (TOTP) work and how to use them
TOTP codes are the six-digit numbers in authenticator apps. See how they are generated, why they work offline, their limits and how to back them up safely.
Login securityPublished
Authenticator apps show a six-digit code that changes every 30 seconds. That code is a TOTP, a time-based one-time password. The app and the service share a secret key set up once, and each side calculates the same code from that secret and the current time. If your code matches, the service lets you in. No network connection between your phone and the service is needed, and no phone number is involved.
TOTP is defined in an open standard, RFC 6238 of the IETF, which is why one app can work with thousands of services. It is one of the options described in our overview of two-factor authentication.
How it works, step by step
- Set-up. The service shows a QR code (or a text key). It contains a secret, a long random value.
- Scan. Your authenticator app scans the QR code and stores the secret. The service also keeps a copy of it.
- Calculation. Every 30 seconds, both sides run the secret and the current time through a cryptographic function and shorten the result to six digits.
- Login. You type the number the app shows. The service computes its own and compares. Because the code only lives for a short time, an old one is useless.
Servers usually accept the code just before and after the current one, to cope with small clock differences. If codes are rejected, check that your phone’s time is set automatically.
What TOTP protects against
- Stolen or reused passwords. An attacker with your password still needs the code.
- Interception of messages. A TOTP code is never sent, so it cannot be intercepted on the way as an SMS can.
- SIM swapping. There is no phone number to hijack. See SIM swapping for why that matters.
The BSI counts authenticator apps among the better options, ahead of codes sent by text message.
What TOTP does not protect against
- Phishing. If you enter a code on a convincing fake page, the attacker can pass it to the real service within seconds. This is a real-time attack, and it works because a code is not tied to the website. Passkeys and hardware keys are.
- Malware on your phone. An infected device can see codes or approve logins.
- Server-side leaks. The service holds the shared secret, so a breach there can affect TOTP, though it is rare.
- Careless backups. A screenshot of the QR code is a copy of your secret.
None of this is a reason to avoid TOTP. It is a large step up from a password alone, and it is available almost everywhere.
The secret behind the QR code
The QR code you scan contains a web-style address that starts with “otpauth://”. It carries the secret key, the account name and the issuer, and sometimes settings such as the number of digits and the time step. Most services use six digits, 30 seconds and the SHA-1 algorithm by default, because that is what almost every app supports. The text key shown next to the QR code is the same secret in readable form (typically in Base32). Anyone who sees it can generate your codes, so treat it like a password: do not photograph it, paste it into chats or leave it in screenshots.
A related older method, HOTP (RFC 4226), uses a counter instead of the clock and is mainly found in some hardware tokens. TOTP simply swaps the counter for the current time.
Choosing an authenticator app
Look for these qualities:
- Backup and transfer that is encrypted, so a lost phone does not lock you out.
- Open source or published audits, where available, and a clear privacy policy.
- App lock with biometrics or a PIN.
- No account required, or an account with end-to-end encrypted sync.
Our comparison of authenticator apps looks at this in detail. Some password managers also generate TOTP codes. That is convenient, but it puts password and second factor in the same place, which weakens the benefit. If you do this, protect the vault with a passkey or hardware key.
Backing up your codes
- Save the backup codes every service gives you, and keep them offline.
- Back up the app using its encrypted export or sync, if it offers one, and protect that backup with a strong passphrase.
- Register a second method where possible, such as a hardware key or passkey.
- When you change phones, transfer the codes before wiping the old device. Never give up the old phone until every account works on the new one.
What to do if a code does not work
- Check the clock on your phone and set it to automatic.
- Make sure you are using the code for the right account. Many apps list several.
- Wait for the next code and try again.
- If nothing works, use a backup code or the service’s account recovery.
Where TOTP fits
TOTP is a solid everyday second factor. Use it where a stronger method is not available, and prefer a passkey or a security key for your most important accounts. A good mix is a hardware key or passkey for email and your platform account, and TOTP for the rest.
In short
- A TOTP code is calculated from a shared secret and the time, so it works offline.
- It is stronger than SMS but can still be phished.
- Back up the secret or the app, and keep backup codes offline.
- Use a passkey or hardware key where you can, and TOTP for the rest.
Frequently asked questions
What does TOTP stand for?
Time-based One-Time Password. It is an open standard described in RFC 6238, built on the earlier HOTP method (RFC 4226). Any compatible authenticator app can generate codes for any service that supports the standard.
Do authenticator apps need an internet connection?
No. The code is calculated on your device from the stored secret and the clock. The device only needs a correct time, which is why a wrong system clock is a common reason for rejected codes.
Can I use the same app for all my accounts?
Yes. One authenticator app can hold codes for many accounts. Make sure you have a secure backup of that app, because losing it without a backup can lock you out.
Is an authenticator app safer than SMS?
Generally yes. There is no phone number to hijack through SIM swapping and no message to intercept. Both methods, however, can be phished by a fake site that asks you for the code.
What if my phone breaks?
Use the backup codes you saved when you set up the account, or restore the app from its encrypted backup or export. Without either, you need to go through the service's account recovery.
More in Login security
Account recovery: how to plan it before you need it
Locked out of Google, Apple or your email? Set up recovery options, backup codes and a trusted contact now, and test them, so a lost phone is an annoyance.
Account security for the whole family: a practical guide
Keep a household safe online: a shared password manager, 2FA for everyone, child accounts, help for parents and a simple plan if someone loses access.
Data breach: what to do now, step by step
Your email was in a breach? Check Have I Been Pwned or the HPI Identity Leak Checker, change the right passwords, switch on 2FA and watch for follow-up scams.
Fingerprint and face login: how safe is biometrics?
Fingerprint and face unlock are convenient and, used on your own device, quite safe. Learn how they work, where they fall short and how to set them up sensibly.
Hardware security keys explained: how they work
A hardware security key is a small device that proves it is you. Learn how FIDO2 keys work, what to look for, how to set one up and why you need a spare.
How password managers work and why they are safe
A password manager keeps your logins in an encrypted vault that only your master password opens. How it works, the real risks and how to start in an afternoon.