Time-based one-time password (TOTP)
A one-time code computed from a shared secret and the current time, defined in RFC 6238, that changes at a fixed interval and proves possession of the device holding the secret.
TOTP, defined in RFC 6238 (2011), produces a short numeric code from a secret key shared between the authenticator and the verifier at enrolment and the current time, divided into fixed steps, commonly 30 seconds. It extends the counter-based HOTP algorithm of RFC 4226 by using time in place of the counter. The authenticator, typically a phone app or a small hardware token, and the verifier each compute the code, and a match shows the user holds the secret. NIST SP 800-63B-4 section 3.1.4 treats a single-factor OTP authenticator as something you have.
Verifiers commonly accept a small window around the current step to allow for clock drift. SP 800-63B-4 requires each code to be accepted only once while valid. TOTP codes do not travel over the phone number, so SIM swapping alone does not capture them. They are still not phishing-resistant, as SP 800-63B-4 says of OTP authentication generally: a user can type the code into a fake site that relays it within its lifetime. Phishing-resistant authentication closes that gap.
Exam relevance: a scenario is likely to ask which one-time password type depends on synchronised clocks, pointing to TOTP rather than counter-based HOTP. Candidates are expected to count an app code as something you have and to recognise that a phishing site can relay it.