HORIZON HASKELLDocslts/ghc-9.10.x248f8f02026-10-05Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · 248f8f0 · 2026-10-05

Modulecryptonite-0.30Haskell2010

Crypto.OTP

One-time password implementation as defined by the HOTP and TOTP specifications.

Both implementations use a shared key between the client and the server. HOTP passwords are based on a synchronized counter. TOTP passwords use the same approach but calculate the counter as a number of time steps from the Unix epoch to the current time, thus requiring that both client and server have synchronized clocks.

Probably the best-known use of TOTP is in Google's 2-factor authentication.

The TOTP API doesn't depend on any particular time package, so the user needs to supply the current OTPTime value, based on the system time. For example, using the hourglass package, you could create a getOTPTime function:

Example4 expressions
import Time.Systemimport Time.Typeslet getOTPTime = timeCurrent >>= \(Elapsed t) -> return (fromIntegral t :: OTPTime)

Or if you prefer, the time package could be used:

Example3 expressions
import Data.Time.Clock.POSIXlet getOTPTime = getPOSIXTime >>= \t -> return (floor t :: OTPTime)
  • 5 types
  • 6 values
  • Packagecryptonite-0.30
  • Exports11
  • LanguageHaskell2010
  • LicenceBSD-3-Clause
  • SourceOTP.hs
typetype OTP = Word32
#

A one-time password which is a sequence of 4 to 9 digits.

valuehotp
  1. :: (HashAlgorithm hash, ByteArrayAccess key)
  2. => hash
  3. -> OTPDigits

    Number of digits in the HOTP value extracted from the calculated HMAC

  4. -> key

    Shared secret between the client and server

  5. -> Word64

    Counter value synchronized between the client and server

  6. -> OTP

    The HOTP value

#
valueresynchronize
  1. :: (HashAlgorithm hash, ByteArrayAccess key)
  2. => hash
  3. -> OTPDigits
  4. -> Word16

    The look-ahead window parameter. Up to this many values will be calculated and checked against the value(s) submitted by the client

  5. -> key

    The shared secret

  6. -> Word64

    The current server counter value

  7. -> (OTP, [OTP])

    The first OTP submitted by the client and a list of additional sequential OTPs (which may be empty)

  8. -> Maybe Word64

    The new counter value, synchronized with the client's current counter or Nothing if the submitted OTP values didn't match anywhere within the window

#

Attempt to resynchronize the server's counter value with the client, given a sequence of HOTP values.

valuetotp
  1. :: (HashAlgorithm hash, ByteArrayAccess key)
  2. => TOTPParams hash
  3. -> key

    The shared secret

  4. -> OTPTime

    The time for which the OTP should be calculated. This is usually the current time as returned by Data.Time.Clock.POSIX.getPOSIXTime

  5. -> OTP
#

Calculate a totp value for the given time.

valuemkTOTPParams
  1. :: HashAlgorithm hash
  2. => hash
  3. -> OTPTime

    The T0 parameter in seconds. This is the Unix time from which to start counting steps (default 0). Must be before the current time.

  4. -> Word16

    The time step parameter X in seconds (default 30, maximum allowed 300)

  5. -> OTPDigits

    Number of required digits in the OTP (default 6)

  6. -> ClockSkew

    The number of time steps to check either side of the current value to allow for clock skew between client and server and or delay in submitting the value. The default is two time steps.

  7. -> Either String (TOTPParams hash)
#

Create a TOTP configuration with customized parameters.