DataJive

What Is a One-Time Password (OTP) and How Does It Work?

By DataJive Editorial Team · Updated Oct 4, 2026 · 1 min read
What Is a One-Time Password (OTP) and How Does It Work?

A one-time password is a code that works once and expires quickly. You meet them in banking apps, login checks and verification messages.

Types of OTP

  • SMS codes: sent to your phone.
  • TOTP: time-based codes generated by an app every 30 seconds.
  • HOTP: counter-based codes, often in hardware tokens.
  • Email codes: sent to your inbox.

How TOTP works

Your phone and the website share a secret key during setup. Each side combines the key with the current time to calculate the same code, so nothing needs to be sent when you sign in.

Where OTPs fail

They can be phished. If a fake site asks for your code and passes it on in real time, the attacker can log in. SMS adds the risk of SIM swapping and interception.

Safe use

Never share a code with anyone who contacts you. Real support teams do not ask for it. Prefer passkeys or hardware keys when available.

Key takeaway: OTPs are a good second factor but not phishing-proof. Never read a code to someone who called or messaged you.

DJ
DataJive Editorial Team
We research and test security and privacy tools, and explain them in plain language. Content is for information only.

Related guides