Totp Class
Definition
- Namespace
- Bodu.Security.Cryptography
- Assembly
- Bodu.Security.Cryptography.dll
- Package
- Bodu.Security.Cryptography 1.2.0
- Source
- Totp.GenerateCode.cs
Provides the Time-based One-Time Password (TOTP) algorithm defined in RFC 6238, generating and verifying the time-derived codes used for two-factor authentication. This class cannot be instantiated.
public static class Totp
- Inheritance
-
Totp
- Inherited Members
Examples
byte[] secret = Base32.Decode("JBSWY3DPEHPK3PXP"); // from an otpauth:// URI
string code = Totp.GenerateCode(secret, DateTimeOffset.UtcNow);
bool ok = Totp.VerifyCode(secret, userInput, DateTimeOffset.UtcNow); // ±1 step by default
Remarks
TOTP is Hotp with a counter derived from the current time: the counter is the number of whole time
steps of periodSeconds that have elapsed since an epoch (the Unix epoch by default), and the code is then
computed exactly as for HOTP. Because a code changes each step, verification accepts a small window of adjacent
steps to tolerate clock drift and transmission delay.
As with Hotp, the shared secret is supplied as raw key bytes; decode a Base32 otpauth://
secret to bytes before calling these methods. The default 30-second period and 6-digit, SHA-1 configuration match
the de facto authenticator-application defaults.
Like the rest of the library, this implementation offers best-effort side-channel resistance and has not been independently audited.
Methods
GenerateCode(ReadOnlySpan<byte>, DateTimeOffset, DateTimeOffset, int, int, OtpHashAlgorithm)
Generates the RFC 6238 TOTP code for the specified secret and timestamp, counting time steps from an explicit epoch.
public static string GenerateCode(ReadOnlySpan<byte> secret, DateTimeOffset timestamp, DateTimeOffset epoch, int digits, int periodSeconds, OtpHashAlgorithm algorithm)
Parameters
secretReadOnlySpan<byte>The shared secret key, as raw bytes.
timestampDateTimeOffsetThe instant for which to generate the code.
epochDateTimeOffsetThe epoch from which time steps are counted (RFC 6238
T0).digitsintThe number of decimal digits in the returned code.
periodSecondsintThe time-step length, in seconds.
algorithmOtpHashAlgorithmThe HMAC hash algorithm to use.
Returns
- string
The zero-padded decimal code, exactly
digitscharacters long.
Exceptions
- ArgumentOutOfRangeException
digitsis less than 6 or greater than 8,periodSecondsis less than 1,algorithmis not a defined OtpHashAlgorithm value, ortimestampis earlier thanepoch.
GenerateCode(ReadOnlySpan<byte>, DateTimeOffset, int, int, OtpHashAlgorithm)
Generates the RFC 6238 TOTP code for the specified secret and timestamp, counting time steps from the Unix epoch.
public static string GenerateCode(ReadOnlySpan<byte> secret, DateTimeOffset timestamp, int digits = 6, int periodSeconds = 30, OtpHashAlgorithm algorithm = OtpHashAlgorithm.Sha1)
Parameters
secretReadOnlySpan<byte>The shared secret key, as raw bytes.
timestampDateTimeOffsetThe instant for which to generate the code.
digitsintThe number of decimal digits in the returned code.
periodSecondsintThe time-step length, in seconds.
algorithmOtpHashAlgorithmThe HMAC hash algorithm to use.
Returns
- string
The zero-padded decimal code, exactly
digitscharacters long.
Exceptions
- ArgumentOutOfRangeException
digitsis less than 6 or greater than 8,periodSecondsis less than 1,algorithmis not a defined OtpHashAlgorithm value, ortimestampis earlier than the Unix epoch.
VerifyCode(ReadOnlySpan<byte>, ReadOnlySpan<char>, DateTimeOffset, int, int, int, OtpHashAlgorithm)
Verifies a candidate code against the RFC 6238 TOTP codes within a window of time steps around the specified timestamp, counting time steps from the Unix epoch.
public static bool VerifyCode(ReadOnlySpan<byte> secret, ReadOnlySpan<char> code, DateTimeOffset timestamp, int window = 1, int digits = 6, int periodSeconds = 30, OtpHashAlgorithm algorithm = OtpHashAlgorithm.Sha1)
Parameters
secretReadOnlySpan<byte>The shared secret key, as raw bytes.
codeReadOnlySpan<char>The candidate code supplied by the user.
timestampDateTimeOffsetThe instant at which the code is being verified.
windowintThe number of time steps on each side of the current step to also accept, tolerating clock drift.
digitsintThe expected number of decimal digits.
periodSecondsintThe time-step length, in seconds.
algorithmOtpHashAlgorithmThe HMAC hash algorithm to use.
Returns
Exceptions
- ArgumentOutOfRangeException
digitsis less than 6 or greater than 8,windowis negative,periodSecondsis less than 1,algorithmis not a defined OtpHashAlgorithm value, ortimestampis earlier than the Unix epoch.
VerifyCode(ReadOnlySpan<byte>, ReadOnlySpan<char>, DateTimeOffset, int, out int, int, int, OtpHashAlgorithm)
Verifies a candidate code against the RFC 6238 TOTP codes within a window of time steps and reports which step matched, counting time steps from the Unix epoch.
public static bool VerifyCode(ReadOnlySpan<byte> secret, ReadOnlySpan<char> code, DateTimeOffset timestamp, int window, out int matchedStepOffset, int digits = 6, int periodSeconds = 30, OtpHashAlgorithm algorithm = OtpHashAlgorithm.Sha1)
Parameters
secretReadOnlySpan<byte>The shared secret key, as raw bytes.
codeReadOnlySpan<char>The candidate code supplied by the user.
timestampDateTimeOffsetThe instant at which the code is being verified.
windowintThe number of time steps on each side of the current step to also accept.
matchedStepOffsetintWhen this method returns true, the signed step offset that matched (
0is the current step, negative is earlier, positive is later); otherwise,0. Useful for detecting persistent client clock drift.digitsintThe expected number of decimal digits.
periodSecondsintThe time-step length, in seconds.
algorithmOtpHashAlgorithmThe HMAC hash algorithm to use.
Returns
Remarks
Every step in the window is scanned; matching does not short-circuit. A wider window
tolerates more drift but admits more valid codes at once, so keep it small (the default accepts the current step
and one on each side).
Exceptions
- ArgumentOutOfRangeException
digitsis less than 6 or greater than 8,windowis negative,periodSecondsis less than 1,algorithmis not a defined OtpHashAlgorithm value, ortimestampis earlier than the Unix epoch.
Applies to
| Product | Versions |
|---|---|
| .NET | 8, 10 |