Home / 2FA guides

2FA & TOTP GUIDE · OCTOBER 2026

Why Do TOTP Codes Change Every 30 Seconds?

Learn TOTP 30 seconds, how TOTP authentication works, common configuration issues, privacy considerations, and when to use the ToolNivo 2FA Code Generator.

IN THIS GUIDECore conceptHow it worksSettings that must matchCommon mistakes to avoidSecurity and recovery
Open 2FA Code Generator

Core concept

TOTP converts current time into a moving counter. When the configured time step changes, the input changes and a new one-time password is calculated.

How it works

RFC 6238 recommends a default 30-second time step, which explains the familiar authenticator countdown. Systems can configure another period.

Settings that must match

The countdown does not begin when you paste a secret. Correctly configured authenticators follow the same clock-based windows.

Common mistakes to avoid

Clock drift can make a verifier and authenticator use different time windows. Correct automatic device time is an important troubleshooting step.

Security and recovery

Use the period configured by the account provider together with the correct secret, algorithm and digit count.

Standards note: Technical explanations follow RFC 6238 and, where relevant, RFC 4226. Always follow your account provider's configuration and recovery instructions.

Frequently asked questions

Can a TOTP generator bypass 2FA?

No. It needs the correct shared secret and matching settings.

Does TOTP depend on the device clock?

Yes. TOTP uses time as part of its moving factor, so significant clock disagreement can cause rejection.

Should I share my TOTP secret?

No. Treat the shared secret as sensitive authentication material.

Open 2FA Code Generator