How Authenticator Apps Generate 6-Digit Codes Every 30 Seconds, Even Offline
The TOTP algorithm behind every authenticator app: the shared secret in the QR code, 30-second time windows, HMAC-SHA1 and dynamic truncation.
Two-factor authentication has become a standard security layer across modern applications. Yet a common question remains: how do authenticator apps keep producing new 6-digit codes every 30 seconds, even when the device is offline?
The answer is a deterministic cryptographic mechanism called TOTP, short for Time-Based One-Time Password, defined in RFC 6238. It is built entirely on predictable hashing and synchronized clocks, with no network communication involved.
This article gives a clear, technical explanation of the TOTP process, its internal components, and why it is trusted in security-critical environments.
What the QR Code Actually Contains#

During 2FA setup, the service shows a QR code that embeds an otpauth:// URI. Inside this URI are a Base32-encoded shared secret key, the issuer name, the number of output digits, and the period (in seconds) for which each code stays valid.
Once scanned, the authenticator app stores the secret locally. The server keeps the same secret. This single exchange is enough; no further synchronization is needed.
The Core Mechanism Behind TOTP#
TOTP divides the current time into discrete 30-second windows.
The algorithm starts with the current Unix timestamp. Instead of using continuous time, TOTP converts it into discrete 30-second windows:
Both the server and the device compute the same value as long as their clocks are aligned.
This time window and the shared secret are then fed into HMAC with SHA-1:
This produces a 20-byte hash. The OTP is then derived with dynamic truncation and a modulo reduction.
How Dynamic Truncation Extracts the Code#
Dynamic truncation extracts a 31-bit integer from the 20-byte HMAC output.
The HMAC output is not a number you can show to users directly. Dynamic truncation turns the 20-byte hash into a predictable integer:
- Take the lower 4 bits of the last byte of the HMAC output to get an offset.
- Extract 4 consecutive bytes starting at that offset.
- Combine them into a 31-bit integer.
The final step is a modulo operation:
This produces a 6-digit number between 000000 and 999999.
Why Six Digits#
Six digits balance usability and security.
Six digits give one million possible combinations. That is large enough to resist brute-force attempts within a short validity period, while staying easy for users to read and type. It also matches legacy hardware tokens, which keeps compatibility broad across platforms.
Some systems use seven or eight digits, but six remains the most widely supported standard.
Why the 30-Second Validity Period Exists#
The 30-second interval balances security with practical usability.
Thirty seconds is long enough for a user to enter the code, and short enough that attackers get only a narrow window. It also absorbs minor differences between system clocks. The standard allows custom periods, but 30 seconds has proven the most reliable balance in production.
Why TOTP Works Without Internet#
TOTP relies entirely on deterministic math rather than network calls.
Once the secret is stored, nothing else needs to be fetched from the server. The server and the device each derive the same result independently, using:
- The shared secret
- The current time window
- The HMAC computation
- The same truncation and modulo rules
If the values match on both sides, the login is valid. If the device clock drifts too far, the server usually checks neighboring time windows to allow for small variations.
The Algorithm in One Line#

For reference, the whole method can be summarized as:
This single line powers almost every authenticator app in use today.
Final Thoughts#
Time-based one-time passwords are not random, and they don’t rely on hidden communication. They come from a predictable cryptographic process built on hashing and time synchronization. Understanding how TOTP works explains why authenticator apps can generate codes offline, and why this system remains one of the most dependable approaches to multi-factor authentication.
Filed under authentication, totp, cryptography
Written by Dhananjay Aggarwal
