basalt / auth/src / matchTotpStep
Function: matchTotpStep()
> matchTotpStep(secret, token, options?): number | null
Defined in: auth/src/totp.ts:91
The TOTP step (counter) that token matches within the allowed window, or null. Constant-time over the window (no early exit → no timing side channel). The step is what enables replay prevention: persist the last-accepted step and reject any code whose step is ≤ it (RFC 6238 §5.2).
Parameters
secret
string
token
string
options?
VerifyTotpOptions = {}
Returns
number | null