otplib is a free, open source browsers & extensions project written in TypeScript and released under MIT. It has 2,292 GitHub stars, 146 forks and 7 open issues, and was last pushed 4 days ago. On this registry it ranks #101 of 140 tracked projects in Browsers & Extensions, with 5 head-to-head comparisons available.

What is otplib?

otplib is a TypeScript-first one-time-password library for Node.js, Bun, Deno, and browser applications that need to add HOTP and TOTP two-factor authentication compatible with Google Authenticator.

What it is

otplib is a set of npm packages — otplib, @otplib/core, @otplib/totp, @otplib/hotp, @otplib/uri, and plugins such as @otplib/plugin-base32-scure — that generates and verifies one-time passwords in TypeScript with full type definitions. It implements RFC 6238 (TOTP) and RFC 4226 (HOTP) with sensible defaults so it works out of the box, and it runs across Node.js, Bun, Deno, and browsers through a plugin system.

The problem it solves is implementing time-based and counter-based two-factor authentication correctly without hand-rolling the cryptography or wiring up a hosted authentication provider. Applications that want to enroll users in 2FA — issuing secrets, producing QR-ready authenticator URIs, and checking submitted tokens — can do so with a small dependency whose default crypto uses @noble/hashes and @scure/base, both independently audited.

Key capabilities

  • Generates secrets and TOTP/HOTP tokens through generateSecret, generate, and verify, with a generateURI helper for authenticator enrollment.
  • Verifies tokens against RFC 6238 (TOTP) and RFC 4226 (HOTP) and is Google Authenticator compatible.
  • Ships a plugin interface for customising cryptographic and base32 requirements when you want to deviate from the defaults.
  • Provides an async-first API — all operations are async by default, with sync variants available for compatible plugins.
  • Is TypeScript-first with full type definitions across all published packages.
  • Defaults to security-audited primitives, using @noble/hashes for hashing and @scure/base for base32 encoding.
  • Is tested against Node.js, Bun, Deno, and browsers, and is published with a CLI topic alongside its library packages.

Who uses it and how

  • Backend teams on Node.js who need login-time 2FA add otplib, call generateSecret() at enrolment, then generate({ secret }) and verify({ secret, token }) during authentication.
  • Front-end and browser developers use the same API in-browser, with plugins selected per runtime to satisfy crypto and base32 requirements.
  • Teams running Bun or Deno install the same package (bun add otplib or deno install npm:otplib) rather than maintaining separate per-runtime authentication code.
  • Maintainers upgrading from earlier versions follow the published Migration Guide, since v13 removed the separate authenticator package and legacy crypto adapters in favour of modern, audited alternatives.
  • Developers evaluating the library use the web demo at https://otplib.yeojz.dev to scan and test TOTP/HOTP QR code samples with their own authenticator app.

Getting started

Install with npm install otplib (or pnpm add otplib / yarn add otplib; for other runtimes bun add otplib or deno install npm:otplib), then import generateSecret, generate, verify, and generateURI from "otplib".

How it compares

The facts do not name other developer OTP libraries in this registry, so it stands alone here as the registry's one-time-password option for Node.js and browsers. Its stated interoperability target rather than competitor is Google Authenticator, with which its tokens are compatible.

When to use it — and when not

Because it is a library rather than a hosted service, there is no database, storage, or SMTP for a self-hoster to operate — the adopting application supplies only a secret storage and the surrounding authentication flow. Pick something else if you want a ready-made login UI or an authentication service rather than a code dependency. Note that v13 is a complete rewrite with breaking changes, so existing users must consult the Migration Guide, and there are 7 open issues on the repository.

project readme (upstream, from github) — read inline

otplib-repo

npm version License: MIT Downloads Code Repository

TypeScript-first library for HOTP and TOTP / Authenticator with multi-runtime (Node, Bun, Deno, Browser) support via plugins.

[!TIP]

A web based demo is available at https://otplib.yeojz.dev.

You can scan and test the TOTP / HOTP QR Code samples with your chosen authenticator app.

Features

  • Zero Configuration - Works out of the box with sensible defaults
  • RFC Compliant - RFC 6238 (TOTP) and RFC 4226 (HOTP) + Google Authenticator Compatible
  • TypeScript-First - Full type definitions
  • Plugin Interface - Flexible plugin system for customising your cryptographic and base32 requirements (if you want to deviate from the defaults)
  • Cross-platform - Tested against Node.js, Bun, Deno, and browsers
  • Security-audited plugins — Default crypto uses @noble/hashes and @scure/base, both independently audited
  • Async-first API — All operations are async by default; sync variants available for compatible plugins

[!IMPORTANT]

v13 is a complete rewrite with breaking changes. For example:

  • (Removed) Separate authenticator package — TOTP now covers all authenticator functionality with default plugins
  • (Removed) Outdated plugins — Legacy crypto adapters removed in favor of modern, audited alternatives

See Migration Guide for details.

Quick Start

# Node
npm install otplib
pnpm add otplib
yarn add otplib
# Other runtimes
bun add otplib
deno install npm:otplib
import { generateSecret, generate, verify, generateURI } from "otplib";

// Generate a secret
const secret = generateSecret();

// Generate a TOTP token
const token = await generate({ secret });

// Verify a token
const result = await verify({ secret, token });
console.log(result.valid); // true

Packages

Documentation

Refer to the Getting Started Guide, or check out the other sections in the guide:

Contributing

See CONTRIBUTING.md for development setup and guidelines.

AI Usage Disclosure

Since v13, parts of the codebase, tests, and documentation have been refined with AI assistance, with all outputs reviewed by humans. See CONTRIBUTING.md for guidelines.

License

MIT

Frequently asked questions

Is otplib free to use?

otplib is open source under the MIT licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does otplib do?

One Time Password (OTP) / 2FA for Node.js and Browser - Supports HOTP, TOTP and Google Authenticator

What is otplib written in?

otplib is primarily written in TypeScript. Its source is publicly available at https://github.com/yeojz/otplib, and it has 2,292 GitHub stars.