- Home
- IAM
- Multi-Factor Authentication and Single Sign-On
- OATH (Open Authentication)
OATH (Open Authentication)
Vendor-neutral org publishing open standards for OTP & strong auth.
OATH (Open Authentication)
Vendor-neutral org publishing open standards for OTP & strong auth.
Go Beyond the Directory. Track the Entire Market.
Monitor competitor funding, hiring signals, product launches, and market movements across the whole industry.
OATH (Open Authentication) Description
OATH (Initiative for Open Authentication) is a global, vendor-neutral organization focused on defining and promoting open standards for strong authentication. It publishes royalty-free specifications for one-time password (OTP) mechanisms and related authentication protocols, including: - HOTP (RFC 4226): HMAC-based One-Time Password algorithm, counter-based, used in hardware tokens and software authenticators. - TOTP (RFC 6238): Time-based One-Time Password algorithm, time-synchronized, used in authenticator apps and online services. - OCRA (RFC 6287): OATH Challenge-Response Algorithm, a flexible framework for challenge/response authentication and transaction signing. OATH's work addresses authentication across cloud, on-premises, and hybrid environments, with a focus on interoperability between tokens, authenticators, and validation servers. The organization provides reference architectures, certification profiles for interoperability validation, and best-practice guides for enterprises migrating from passwords and proprietary OTP systems. OATH also provides guidance for bridging legacy OTP deployments with modern passwordless and multi-factor authentication approaches, and supports technical working groups for implementers to contribute requirements and deployment experience back to the community.
OATH (Open Authentication) FAQ
Common questions about OATH (Open Authentication) including features, pricing, alternatives, and user reviews.
OATH (Open Authentication) is Vendor-neutral org publishing open standards for OTP & strong auth. developed by OATH (Open Authentication). It is a IAM solution designed to help security teams with Authentication, MFA, Security Standards.
FEATURED
Fix-first AppSec powered by agentic remediation, covering SCA, SAST & secrets.
Cybercrime intelligence tools for searching compromised credentials from infostealers
Agentless cloud security platform for risk detection & prevention
Fractional CISO services for B2B companies to build security programs
POPULAR
Real-time OSINT monitoring for leaked credentials, data, and infrastructure
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
AI security assurance platform for red-teaming, guardrails & compliance
TRENDING CATEGORIES
Stay Updated with Mandos Brief
Get strategic cybersecurity insights in your inbox