Skip to content

basalt / auth/src / matchTotpStep

Function: matchTotpStep() ​

> matchTotpStep(secret, token, options?): number | null

Defined in: auth/src/totp.ts:91

The TOTP step (counter) that token matches within the allowed window, or null. Constant-time over the window (no early exit → no timing side channel). The step is what enables replay prevention: persist the last-accepted step and reject any code whose step is ≤ it (RFC 6238 §5.2).

Parameters ​

secret ​

string

token ​

string

options? ​

VerifyTotpOptions = {}

Returns ​

number | null

Released under the MIT License.