← All terms

One-Time Password (OTP)

A one-time password is a code valid for a single login or transaction, delivered by SMS, app, or token — stronger than static passwords, but phishable.

A one-time password (OTP) is an authentication code that is valid for a single login attempt or transaction, after which it expires. OTPs are the most common second factor in multi-factor authentication: the familiar six digits that arrive by SMS, appear in an authenticator app, or scroll across a hardware token.

How it works

OTPs come in two main flavors. Time-based codes (TOTP) are generated from a shared secret and the current clock, refreshing every 30 or 60 seconds inside an authenticator app or token — nothing is transmitted, so there is nothing to intercept in transit. Delivered codes, by contrast, are generated server-side and sent to the user over a channel, most often SMS or a voice call. That delivery channel is where the security of the whole scheme is decided: an app-based code lives on a specific device, while an SMS code goes to whoever currently controls the phone number.

Attackers exploit that difference in three ways. SIM swapping moves the victim's number — and every SMS code — onto the attacker's SIM. Real-time phishing pages and adversary-in-the-middle kits simply ask the victim to type the code and relay it to the real site within its validity window. And OTP bots automate the ask entirely, placing convincing robocalls that talk victims into reading codes aloud.

How to defend

Treat OTPs as a hierarchy, not a checkbox. Retire SMS and voice delivery first — they inherit every weakness of the phone number, as our guide to SIM swapping attacks details. App-based TOTP is a solid middle tier for general users, though any code a human can read, a human can be tricked into sharing. For administrators, executives, and finance roles, move to phishing-resistant MFA — FIDO2 keys and passkeys — where there is no code to steal, relay, or read out loud. And train the one rule that covers every variant: no legitimate process ever requires you to tell another person your code.

Related terms

Multi-Factor Authentication (MFA)Multi-factor authentication (MFA) requires two or more independent proofs of identity to log in, so a stolen password alone is not enough for account access.Phishing-Resistant MFAPhishing-resistant MFA is multi-factor authentication that cannot be captured or relayed by a fake login page — in practice, FIDO2 security keys and passkeys bound cryptographically to the legitimate domain.SIM SwappingSIM swapping is an attack where criminals socially engineer a mobile carrier into transferring a victim's phone number to their SIM, hijacking SMS codes and accounts.OTP BotAn OTP bot is an automated calling or texting service criminals use to trick victims into revealing one-time passcodes, defeating SMS and app-based MFA at scale.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo