Android and iOS

Time and recovery in TOTP flows

OAuth, passkeys, biometrics, device registration and recovery.

Identity and sessions1 min readEditorial methods

TOTP generates time-based codes. Validation needs defined windows, replay handling and recovery.

Evaluation approach

Protect enrollment secrets and bind them to the right account. Avoid excessive clock tolerance.

Application example

Adding an authenticator after a device change may require existing strong evidence.

Limits and considerations

TOTP codes can be phished; second factors differ in attack resistance.

Managing recovery codes

Recovery codes are account-access secrets too. Record use, apply suitable single-use or bounded behavior and do not ask users to disclose them during ordinary support conversations.

Checks and decisions

  • Protect enrollment secrets
  • Assess reuse
  • Plan recovery

Sources

The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.