Add TOTP Two-Factor to Your Own App: A Developer Guide
A framework-agnostic guide to adding RFC 6238 TOTP two-factor auth: generate a secret, build the otpauth URI, verify codes with a drift window, and stop replay.
Read more →All articles about totp: 8 practical guides and tutorials from our free, privacy-first online tools.
A framework-agnostic guide to adding RFC 6238 TOTP two-factor auth: generate a secret, build the otpauth URI, verify codes with a drift window, and stop replay.
Read more →
Dissect the otpauth:// Key URI a 2FA QR code carries: scheme, totp host, issuer:account label, and the secret, algorithm, digits, and period parameters.
Read more →
How TOTP two-factor codes work: the shared base32 secret, time steps, HMAC, RFC 4226 dynamic truncation, and the drift windows servers use to verify.
Read more →
Lost, stolen or wiped the phone holding your authenticator? Here is how backup codes, cloud sync, saved secrets and account recovery get your 2FA back.
Read more →
Google Authenticator's export QR is a proprietary otpauth-migration blob, not a standard otpauth URI. Learn the reliable re-enrolment route to move accounts.
Read more →
Compare SMS codes, TOTP authenticator apps, and passkeys by threat model: SIM swapping, phishing resistance, origin-binding, and when to use each factor.
Read more →
RFC 6238 defaults to SHA-1, 6 digits, 30 seconds. Learn what happens when a service picks SHA-256 or 8-digit codes and why some apps generate wrong codes.
Read more →
Your TOTP code rejected? The fixes ordered by likelihood: clock skew first, then wrong algorithm, digits, period, mistyped secret, and reused codes.
Read more →