One-Time Passwords
activeHOTP (RFC 4226) and TOTP (RFC 6238) one-time passwords — generate counter- and time-based codes, verify a code within a drift window, and build otpauth:// provisioning URIs.
- Transactions · 30d
- 0
- Volume · 30d
- $0.00
- Unique buyers · 30d
- 0
- Uptime · 30d
- 100.0%
- Latency p50
- 187ms
- Reported calls · 30d
- 5
Endpoints (4 live)
POST/v1/verify— Verify a submitted TOTP code against a base32 secret, scanning ±window time steps (default ±1) to tolerate clock drift. Returns valid plus the matching step offset (delta). A code that does not match is a successful result with valid=false — not an error. (0.004 USDC on Base)POST/v1/totp— Generate an RFC 6238 time-based one-time password from a base32 secret. Uses the current time by default, or an explicit unix timestamp (seconds); configurable period (default 30s), digits (default 6) and algorithm (default SHA1). Also returns the counter and seconds remaining in the window. (0.004 USDC on Base)POST/v1/hotp— Generate an RFC 4226 counter-based HMAC one-time password from a base32 secret and counter. Configurable digits (6–10, default 6) and algorithm (SHA1/SHA256/SHA512, default SHA1). An invalid base32 secret is a clean 400. (0.004 USDC on Base)POST/v1/uri— Build an otpauth:// provisioning URI (the string encoded in authenticator QR codes) for a totp or hotp secret. Includes label, issuer, algorithm, digits and period (totp) or counter (hotp). The secret must be valid base32. (0.004 USDC on Base)
First seen · last seen