How TOTP 6-digit codes actually work
TOTP stands for time-based one-time password. When you add an account, the service and your app agree on one shared secret. From then on, both sides mix that secret with the current time to produce the same 6-digit number — no network needed.
What that means in practice
- The code changes about every 30 seconds, so an intercepted one is useless almost immediately.
- Nothing is sent to your phone, so there's no message for an attacker to redirect.
- It works with no signal and no internet, because it's just maths on your device.
- Your device's clock has to be right — that's the one thing that breaks it.
Why it beats SMS
SMS codes travel over the phone network, where they can be intercepted or redirected with a SIM-swap attack. A TOTP code never leaves your device, which removes that whole category of attack.
FAQ
- Is TOTP the same as an authenticator app?
- TOTP is the standard; an authenticator app is what implements it. That's why accounts you add work in any TOTP app.
- What's stronger than TOTP?
- A hardware security key (WebAuthn/U2F) resists phishing even better. Where a service offers both, a security key is the strongest choice and TOTP is an excellent second.
Keep your 2FA codes in one secure place
Authenticator App - Novaz generates your codes offline, backs them up encrypted to your own iCloud, and locks behind Face ID — free and ad-free.
Download on the App StoreRelated guides
Set up 2FA on your accounts
Step-by-step guides for the services people secure first.
- How to enable 2FA for your Google account
- How to enable 2FA for your Microsoft account
- How to enable 2FA for your Facebook account
- How to enable 2FA for your Instagram account
- How to enable 2FA for your GitHub account
- How to enable 2FA for your Amazon account
Browse all setup guides or check whether a service supports 2FA.