otplib is a TypeScript-first one-time-password library for Node.js, Bun, Deno, and browser applications that need to add HOTP and TOTP two-factor authentication compatible with Google Authenticator.
What it is
otplib is a set of npm packages — otplib, @otplib/core, @otplib/totp, @otplib/hotp, @otplib/uri, and plugins such as @otplib/plugin-base32-scure — that generates and verifies one-time passwords in TypeScript with full type definitions. It implements RFC 6238 (TOTP) and RFC 4226 (HOTP) with sensible defaults so it works out of the box, and it runs across Node.js, Bun, Deno, and browsers through a plugin system.
The problem it solves is implementing time-based and counter-based two-factor authentication correctly without hand-rolling the cryptography or wiring up a hosted authentication provider. Applications that want to enroll users in 2FA — issuing secrets, producing QR-ready authenticator URIs, and checking submitted tokens — can do so with a small dependency whose default crypto uses @noble/hashes and @scure/base, both independently audited.
Key capabilities
- Generates secrets and TOTP/HOTP tokens through
generateSecret, generate, and verify, with a generateURI helper for authenticator enrollment.
- Verifies tokens against RFC 6238 (TOTP) and RFC 4226 (HOTP) and is Google Authenticator compatible.
- Ships a plugin interface for customising cryptographic and base32 requirements when you want to deviate from the defaults.
- Provides an async-first API — all operations are async by default, with sync variants available for compatible plugins.
- Is TypeScript-first with full type definitions across all published packages.
- Defaults to security-audited primitives, using
@noble/hashes for hashing and @scure/base for base32 encoding.
- Is tested against Node.js, Bun, Deno, and browsers, and is published with a CLI topic alongside its library packages.
Who uses it and how
- Backend teams on Node.js who need login-time 2FA add
otplib, call generateSecret() at enrolment, then generate({ secret }) and verify({ secret, token }) during authentication.
- Front-end and browser developers use the same API in-browser, with plugins selected per runtime to satisfy crypto and base32 requirements.
- Teams running Bun or Deno install the same package (
bun add otplib or deno install npm:otplib) rather than maintaining separate per-runtime authentication code.
- Maintainers upgrading from earlier versions follow the published Migration Guide, since v13 removed the separate authenticator package and legacy crypto adapters in favour of modern, audited alternatives.
- Developers evaluating the library use the web demo at https://otplib.yeojz.dev to scan and test TOTP/HOTP QR code samples with their own authenticator app.
Getting started
Install with npm install otplib (or pnpm add otplib / yarn add otplib; for other runtimes bun add otplib or deno install npm:otplib), then import generateSecret, generate, verify, and generateURI from "otplib".
How it compares
The facts do not name other developer OTP libraries in this registry, so it stands alone here as the registry's one-time-password option for Node.js and browsers. Its stated interoperability target rather than competitor is Google Authenticator, with which its tokens are compatible.
When to use it — and when not
Because it is a library rather than a hosted service, there is no database, storage, or SMTP for a self-hoster to operate — the adopting application supplies only a secret storage and the surrounding authentication flow. Pick something else if you want a ready-made login UI or an authentication service rather than a code dependency. Note that v13 is a complete rewrite with breaking changes, so existing users must consult the Migration Guide, and there are 7 open issues on the repository.
project readme (upstream, from github) — read inline

otplib-repo

TypeScript-first library for HOTP and TOTP / Authenticator with multi-runtime (Node, Bun, Deno, Browser) support via plugins.
[!TIP]
A web based demo is available at https://otplib.yeojz.dev.
You can scan and test the TOTP / HOTP QR Code samples with your chosen authenticator app.
Features
- Zero Configuration - Works out of the box with sensible defaults
- RFC Compliant - RFC 6238 (TOTP) and RFC 4226 (HOTP) + Google Authenticator Compatible
- TypeScript-First - Full type definitions
- Plugin Interface - Flexible plugin system for customising your cryptographic and base32 requirements (if you want to deviate from the defaults)
- Cross-platform - Tested against Node.js, Bun, Deno, and browsers
- Security-audited plugins — Default crypto uses
@noble/hashes and @scure/base, both independently audited
- Async-first API — All operations are async by default; sync variants available for compatible plugins
[!IMPORTANT]
v13 is a complete rewrite with breaking changes. For example:
- (Removed) Separate authenticator package — TOTP now covers all authenticator functionality with default plugins
- (Removed) Outdated plugins — Legacy crypto adapters removed in favor of modern, audited alternatives
See Migration Guide for details.
Quick Start
# Node
npm install otplib
pnpm add otplib
yarn add otplib
# Other runtimes
bun add otplib
deno install npm:otplib
import { generateSecret, generate, verify, generateURI } from "otplib";
// Generate a secret
const secret = generateSecret();
// Generate a TOTP token
const token = await generate({ secret });
// Verify a token
const result = await verify({ secret, token });
console.log(result.valid); // true
Packages
Documentation
Refer to the Getting Started Guide, or check out the other sections in the guide:
Contributing
See CONTRIBUTING.md for development setup and guidelines.
AI Usage Disclosure
Since v13, parts of the codebase, tests, and documentation have been refined with AI assistance, with all outputs reviewed by humans. See CONTRIBUTING.md for guidelines.
License
MIT