• What is One-Time Password (OTP)?

    Back to GlossaryBack to Glossary
    outline of user with checkmark

    How do one-time passwords work?

    OTPs are delivered in many ways, usually via an object the user carries with him, such as his mobile phone (using SMS or an app), a token with an LCD-display, or a security key. OTP technology is compatible with all major platforms (desktop, laptop, mobile) and legacy environments, making it a very popular choice among second-factor protocols.

    password verified illustration

    Are there any limitations to traditional OTP?

    • Users need to type codes during their login process.
    • Manufacturers often possess the seed value of the tokens.
    • Administrative overhead resulting from having to set up and provision devices for users.
    • The technology requires the storage of secrets on servers, providing a single point of attack

    Are there additional advantages to 2-factor authentication when using Yubico OTP?

    finger tap accepted illustration

    No client software needed. The OTP is just a string. If you can send a password, you can send an OTP.

    Read moreRead more
    could with shield inside

    Easy to implement. Using YubiCloud, supporting Yubico OTP is not much harder than supporting regular passwords.

    Read moreRead more
    laptop illustration

    YubiKey ID embedded in OTP. This allows for self-provisioning, as well as authenticating without a username.

    Read moreRead more

    Learn More

    Developer Resources