TOTP (Time-Based One-Time Password)
A temporary code generated by an authenticator app (e.g. Google Authenticator) that changes every 30 seconds, used as a second factor in 2FA.
TOTP generates one-time passwords using a shared secret key and the current time. The algorithm divides time into 30-second windows and uses HMAC-SHA1 to produce a 6-digit code from the combination of the secret and the current time window.
Because both the authenticator app and the server know the shared secret and the current time, they independently generate the same code. The code is valid only during its 30-second window, making intercepted codes useless after expiration.
TOTP is the most widely used second factor in 2FA. Team password managers can store TOTP secrets alongside credentials, enabling team members to generate codes for shared accounts without passing codes via insecure channels.
Related reading
Stop sharing passwords in spreadsheets
TeamPassword stores, shares and rotates your team credentials, encrypted end to end.
Trusted by 900+ agencies and small teams worldwide