Skip to main content
Authentication

One-Time Password (OTP)

A password that is valid for only a single session or transaction, generated automatically and typically delivered via SMS, email, or an authenticator app.

A one-time password is a credential valid for exactly one authentication session or transaction. OTPs are generated automatically and delivered via SMS, email, voice call, or authenticator app. They expire after a short period or after use.

OTPs address the fundamental weakness of static passwords: if intercepted, a static password can be reused indefinitely. An OTP, once used or expired, is worthless to an attacker. This is why OTPs are widely used as a second factor in 2FA.

However, SMS-based OTPs are vulnerable to SIM swapping and interception. App-based OTPs (TOTP) and hardware security keys provide stronger alternatives. For teams, storing TOTP secrets in a shared password manager enables seamless MFA for shared accounts.

Back to the glossary

Stop sharing passwords in spreadsheets

TeamPassword stores, shares and rotates your team credentials, encrypted end to end.

Trusted by 900+ agencies and small teams worldwide