How TOTP Works - The 6-Digit Code Generated From Time Sync
The 6-digit codes shown by Google Authenticator and similar apps are generated from a shared secret and the current time. This article explains the TOTP algorithm defined in RFC 6238, the difference from HOTP, common time-drift failure modes, and what is actually inside the QR code you scan during setup.