Home / 2FA guides

2FA & TOTP GUIDE · OCTOBER 2026

RFC 6238 Explained: How TOTP Authentication Works

Learn RFC 6238 TOTP, how TOTP authentication works, common configuration issues, privacy considerations, and when to use the ToolNivo 2FA Code Generator.

IN THIS GUIDECore conceptHow it worksSettings that must matchCommon mistakes to avoidSecurity and recovery
Open 2FA Code Generator

Core concept

RFC 6238 defines the Time-Based One-Time Password algorithm and specifies HOTP as a key building block.

How it works

The prover and verifier need the same secret, or knowledge of a transformation that produces a shared secret. Secrets should be protected against unauthorized access.

Settings that must match

Both sides must use the same time-step value. RFC 6238 recommends a default 30-second step and discusses clock synchronization.

Common mistakes to avoid

RFC 6238 includes test vectors for HMAC-SHA-1, HMAC-SHA-256 and HMAC-SHA-512. The configured algorithm must match on both sides.

Security and recovery

The standard explains generation and validation mechanics; secure enrollment, storage, phishing resistance and recovery need additional controls.

Standards note: Technical explanations follow RFC 6238 and, where relevant, RFC 4226. Always follow your account provider's configuration and recovery instructions.

Frequently asked questions

Can a TOTP generator bypass 2FA?

No. It needs the correct shared secret and matching settings.

Does TOTP depend on the device clock?

Yes. TOTP uses time as part of its moving factor, so significant clock disagreement can cause rejection.

Should I share my TOTP secret?

No. Treat the shared secret as sensitive authentication material.

Open 2FA Code Generator