RFC 4226 · INFORMATIONAL · 2005

HOTP: An HMAC-Based One-Time Password Algorithm

Overview

RFC 4226, “HOTP: An HMAC-Based One-Time Password Algorithm”, is an Informational document published in December 2005 by D. M'Raihi, M. Bellare, F. Hoornaert, D. Naccache, O. Ranen. The canonical text is published by the RFC Editor.

Abstract

This document describes an algorithm to generate one-time password values, based on Hashed Message Authentication Code (HMAC). A security analysis of the algorithm is presented, and important parameters related to the secure deployment of the algorithm are discussed. The proposed algorithm can be used across a wide range of network applications ranging from remote Virtual Private Network (VPN) access, Wi-Fi network logon to transaction-oriented Web applications.

This work is a joint effort by the OATH (Open AuTHentication) membership to specify an algorithm that can be freely distributed to the technical community. The authors believe that a common and shared algorithm will facilitate adoption of two-factor authentication on the Internet by enabling interoperability across commercial and open-source implementations. This memo provides information for the Internet community.

Abstract as published in the RFC, via rfc-editor.org.

What “Informational” means

Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.

Read this RFC

The canonical text of RFC 4226 is hosted at rfc-editor.org. Available in TXT,HTML.

Other RFCs from 2005

Who Is Online

In total there are 87 users online: 0 registered, 81 guests and 6 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Baiduspider Majestic Other Bot SemrushBot

Users active in the past 15 minutes. Total registered members: 354