Authentication · Open source
typed-totp
- 01Public API
- 02TOTP / HOTP
- 03Injectable ports
- 04Web Crypto
problem
Generate and verify time-based and counter-based passwords without tying core logic to a particular clock or cryptographic backend.
requirements
Correct HOTP and TOTP output, a testable clock, no runtime dependencies, and an API usable both as plain functions and as a configured instance.
architecture
A functional API wraps application services. TOTP delegates to HOTP; pure counter and formatting functions sit behind injectable clock, HMAC, encoding, and comparison ports.
decision
Use platform Web Crypto and zero runtime dependencies. Keep I/O behind interfaces for deterministic tests, while leaving pure mathematics as simple functions. A functional API makes adoption easy; an object API supports reusable configuration.