Time-Based One-Time Password

Also known as:TOTP

Time-Based One-Time Password: One-time password generated from a secretSecretSensitive authentication material such as a password, token, API key, or private key. and the current time interval. This term is relevant for the assessment and design of modern security architecturesSecurity ArchitectureThe structured design of security controls, trust boundaries, data flows, and operational responsibilities. and should be applied within the specific technical and organizational context.

How it works and where it fits

Time-Based One-Time Password separates the subject, digital identity, authentication factor, and authorization decision. Authentication establishes who or what is presenting an identity; authorization then determines which action is permitted in the current context. Session state, device trust, request origin, and risk signals can further influence that decision.

Practical security relevance

Effective implementation requires a controlled identity lifecycle from creation through role and entitlement changes to suspension and removal. Strong authentication, least privilege, periodic recertification, and traceable logs are central. Controls must also identify abuse of legitimate accounts, because valid credentials alone do not prove that an action is legitimate.

  • One-Time PasswordOne-Time PasswordPassword valid for only a single use or a short period.: Password valid for only a single use or a short period.
  • Multi-Factor AuthenticationMulti-Factor AuthenticationRequires at least two independent factors for identity verification.: Requires at least two independent factors for identity verification.
  • AuthenticationAuthenticationVerification of the claimed identity of a user or system.: Verification of the claimed identity of a user or system.
  • Replay AttackReplay AttackRetransmission of valid messages or tokens for unauthorized reuse.: Retransmission of valid messages or tokens for unauthorized reuse.