Skip to main content
Authentication

HOTP (HMAC-based One-Time Password)

A one-time password algorithm based on a counter value rather than time, generating a new code each time the counter increments. A precursor to TOTP.

HOTP generates one-time passwords using a shared secret key and a counter value. Each time a password is generated, the counter increments. The algorithm uses HMAC-SHA1 to produce a numeric code (typically 6 digits) from the combination of the secret and counter.

Unlike TOTP (which is time-based), HOTP codes don’t expire automatically: they remain valid until used or until the counter advances. This makes HOTP suitable for hardware tokens that generate codes on button press.

The main disadvantage is synchronization: if the counter on the token gets out of sync with the server, codes won’t match. TOTP largely replaced HOTP for software authenticators because time-based codes are self-expiring and don’t require counter synchronization.

Back to the glossary

Stop sharing passwords in spreadsheets

TeamPassword stores, shares and rotates your team credentials, encrypted end to end.

Trusted by 900+ agencies and small teams worldwide