THE AUTHENTICATOR HANDBOOK

Understanding an otpauth URI

An otpauth URI is a setup link used by many authenticator apps. It carries the information an app needs to configure a code generator.

Read the parts

The link identifies the OTP type and label, followed by query parameters such as secret and issuer. Treat the entire link as sensitive because it can contain the key.

A label is not proof of identity

An issuer or account name can help you recognize an entry. It does not authenticate the service that supplied the link.

Encoding and compatibility

Characters in labels and parameters need appropriate URL encoding. A link can be readable by one app and behave differently in another, particularly with optional settings.

Inspect before sharing

Use a made-up key for examples and bug reports. Redacting only the account name does not remove the secret from a setup link.

References