OpenOTP Authentication Server
OpenOTP Authentication Server
OpenOTP™ Server (Multi-Factor with OTP & FIDO2)

OpenOTP™ is an enterprise-grade user authentication solution based on open standards.
OpenOTP provides an authentication server for your Domain users. It supports the combination of single-factor and multi-factor authentication for user access with One-Time Password technologies (OTP) and FIDO2.
Try it Now!
Secure all your IT with one solution
Secure your Domain users

It is very easy to implement OpenOTP One-Time Password and/or FIDO2 functionalities into your existing Web Applications. Additional integration software from RCDevs provides support for Windows, ADFS, Linux, and even Network Access Control (NAC) like WiFi. Integration can be done with SAML2, OpenID Connect and OAuth.
OpenOTP Authentication Server provides the most advanced OTP authentication system supporting simple registration with QRCode scan, Software Token based on OATH standards, and Approve/Deny login with push notifications. For software token registration, you must have an OTP authentication token application installed on your phone (OpenOTP Token recommended).
OpenOTP Token is the official software token to enjoy all features offered by the OpenOTP server (like push login, phishing protection, etc…).
For hardware tokens, any OATH Token based on HOTP, OCRA, or TOTP server works with OpenOTP.
Main Features
Supports any OATH Hardware or Software Token (HOTP, TOTP or OCRA)
Supports Mobile-OTP Software Tokens with PIN code
Supports all Yubikeys from Yubico
Supports FIDO2
Supports SMS, Mail and Secure Mail OTP (on-demand & prefetched)
Secure Token Inventory with easy graphical management in WebADM
Up to 10 simultaneous Tokens per-user (Hardware / Software)
PSKC Hardware Token seed import system (Vasco, Feitian, Gemalto…)
Easy Hardware Token registration via serial number
Easy Software Token registration via QRCode scanning
Intelligent contextual authentication with IP address and device fingerprint
Application-specific password for mobile applications not supporting OTP
SOAP, REST & JSON native APIs over HTTPS with WSDL service description
RADIUS for VPNs and RADIUS-enabled systems (OpenOTP Radius Bridge)
OpenID API for OpenID-enabled websites (OpenID Service Provider)
SAMLv2 IdP with POST redirections and IdP-initiated requests
Domain segregation with mappings to LDAP subtrees or dedicated LDAP
Trust Domains allowing authentication to be relayed to another OTP server
Per-client, group and network authentcation policies
Group-based access control & authentication policies
Support hardware security modules with Yubico YubiHSM
Data consistency with no replication/import/synchronization of LDAP users
Advanced replay attack protection for Tokens
Many configurations adjustable per server, domain, group, user, client
Two-Factor with challenged OTP or password concatenation
Support for both LDAP direct and indirect (Active Directory) groups
Mobile Push Authentication
Application Passwords
Contextual Authentication
QRCode Key Provisioning
OpenOTP Web Apps
- The Self-Desk Web App allows end-users to self-configure some personal settings, update their account information (ex. mobile number or email address), download, register and re sync their tokens.
- The Self-Reg Web App allows administrators to trigger a user email with a one-time self-registration URL. By clicking the URL and entering his password, the user can register, re sync and test tokens.
- The Password Reset Web App allows users to securely reset their lost or expired Domain passwords with token / SMS OTP, PKI and even FIDO2.
- The Help-Desk Web App allows federation of the 1st line of support. The Helpdesk support team can help end-users with basic needs such as changing their password, email, phone number etc... It also gives them access to their tokens and their settings, login history, SSO, SSH and PKI.
Hardware Security Modules
OpenOTP Trusted Domains
It is also very easy to implement OpenOTP One-Time Password and/or FIDO2 functionalities into your existing Web applications.
Additional integration software from RCDevs provides support for Windows, ADFS, Linux and even WiFi access.
Web Applications (Java, PHP, ASP, Python, .Net…)
VPNs & SSL-VPNs (Checkpoint, Cisco, Nortel, Juniper, F5, Palo-Alto…)
OpenVPN Variants & PFsense
Citrix Access Gateway & Web Interface
Microsoft Reverse-Proxies (TMG / UAG / 2012 Server)
Microsoft ADFS (Exchange, Sharepoint…)
Linux PAM (SSH, FTP, OpenVPN, PPTP, POP/IMAP…)
Windows Login (Credential Provider for Vista, 7, 8)
Web Products (SugarCRM, Joomla, WordPress, RoundCube, Magento…)
OpenID-enabled Web Sites (Livejournal, Sourceforge…)
Corporate SAML & Google Apps
Cloud Applications (SalesForce, SugarCRM, GoToMeeting…)
Enterprise WiFi Access (with EAP-GTC and EAP-TTLS-PAP)
Amazon Elastic Compute Cloud (EC2 / AWS)
Any other system (Using our simple integration libraries)
Choose the method that best suits you