PyOTP
Python One Time Password Library
Decision gist · record as of 2026-08-14
Yes. PyOTP is production-stable (Development Status 5), actively maintained, has no dependencies, and implements standard RFC-based OTP algorithms. It is well-suited for adding 2FA/MFA to applications, provided you implement the required application-level security controls (HTTPS, secret storage, replay prevention, rate limiting) documented in its guidelines.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low install friction with no runtime dependencies.
- Active maintenance with a recent release 61 days ago and ongoing repository activity.
- Supports modern Python versions from 3.8 through 3.13.
License · maintenance · safety
MIT (permissive) — MIT license permits commercial and private use with minimal restrictions, making it suitable for proprietary applications.
last release 2026-06-14 (61 days) · last repo commit 2026-06-29 · 3,328 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 38,726,681 downloads/mo, #709 on PyPI
Alternatives
Verify before relying
pip install pyotp
import pyotp
totp = pyotp.TOTP('base32secret3232')
print(totp.now()) # Generate current OTP
print(totp.verify('492039')) # Verify an OTP code- Whether the package includes built-in rate limiting or replay attack prevention mechanisms, or if these must be implemented separately in the application layer.
- Performance characteristics when handling high volumes of OTP generation or verification requests.
What it is and what it does
PyOTP is a Python library that implements server-side support for RFC 4226 (HOTP) and RFC 6238 (TOTP) standards, enabling developers to add one-time password authentication to their applications. It handles the cryptographic generation and verification of time-based and counter-based OTPs, and can produce provisioning URIs compatible with Google Authenticator, Authy, and other OTP client apps for QR code scanning.
The library has no external runtime dependencies and works across macOS, POSIX systems, and multiple Python implementations (CPython and PyPy). Developers must implement application-level security controls—such as HTTPS transport, secure secret storage, replay attack prevention, and rate limiting—as outlined in the RFC security requirements and OWASP authentication guidelines. The package includes helper functions for generating secrets and parsing provisioning URIs, making it straightforward to integrate OTP authentication into login flows.
Use it for
- Add time-based OTP (TOTP) verification to web application login flows compatible with Google Authenticator.
- Implement counter-based OTP (HOTP) for systems requiring sequential one-time password validation.
- Generate provisioning URIs and QR codes for users to enroll their OTP secrets in authenticator apps.
- Build multi-factor authentication systems where OTP serves as a second authentication factor.
- Parse and validate otpauth:// URIs from user-provided QR codes or provisioning links.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
PyOTP is production-stable (Development Status 5), actively maintained, has no dependencies, and implements standard RFC-based OTP algorithms. It is well-suited for adding 2FA/MFA to applications, provided you implement the required application-level security controls (HTTPS, secret storage, replay prevention, rate limiting) documented in its guidelines.
Install
pyotp on PyPI
Before you install
Low install friction with no runtime dependencies. Active maintenance with a recent release 61 days ago and ongoing repository activity. Supports modern Python versions from 3.8 through 3.13.
License in practice
MIT license permits commercial and private use with minimal restrictions, making it suitable for proprietary applications.
Quickstart
pip install pyotp
import pyotp
totp = pyotp.TOTP('base32secret3232')
print(totp.now()) # Generate current OTP
print(totp.verify('492039')) # Verify an OTP code
Verify before relying
- Whether the package includes built-in rate limiting or replay attack prevention mechanisms, or if these must be implemented separately in the application layer.
- Performance characteristics when handling high volumes of OTP generation or verification requests.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.8 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 61 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 38,726,681 / month, #709 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersOperating System :: MacOS :: MacOS XOperating System :: POSIXProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Programming Language :: Python :: Implementation :: CPythonProgramming Language :: Python :: Implementation :: PyPyTopic :: Software DevelopmentTopic :: Software Development :: Libraries :: Python Modules |
Evidence: pyotp-2.10.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “TOTP HOTP implementation”
- PyOTPPyOTP generates and verifies one-time passwords (HOTP and TOTP) for…
- django-otpAdds one-time password (OTP) support to Django applications, enabling…
- oathtoolGenerates one-time passwords (TOTP codes) from a shared secret key,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Software Development packages
Provides backported and experimental type hints for Python 3.9+, allowing use of newer typing features on older Python versions and enabling early experimentation with type system PEPs before they enter the standard library.
NumPy provides an N-dimensional array object and a comprehensive suite of mathematical, linear algebra, Fourier transform, and random number functions for scientific computing in Python.
FastAPI is a Python web framework for building REST APIs using type hints, with automatic request validation, serialization, and interactive API documentation.
Provides a way to document function parameters, class attributes, return types, and variables inline using Python's `Annotated` type hint syntax instead of traditional docstrings.
Typer builds command-line applications from Python functions using type hints, automatically generating help text, argument parsing, and shell completion.
Install it if you are building CLIs in Python.
Distlib provides low-level packaging utilities for building, distributing, and managing Python software—including metadata handling, version specifiers, wheel support, script installation, and dependency resolution.
See also django-otp · oathtool · yubico-client · authy · django-two-factor-auth · django-otp-webauthn · pyu2f · django-allauth-2fa · fido2 · soft-webauthn