Table of Contents
In this article, we will see how to install oathtool on Ubuntu Linux. If you are looking for a command line tool that can generate OTP from terminal then you should definitely consider using OATHTOOL. It is a free and open source tool used for generating and validating OATH one-time passwords. It supports both event-based HOTP mode as well as time-variant TOTP mode. It is no different than any other authenticator app such as Google Authenticator which also uses same TOTP standard. It is just that both are created for different environments.
OATHTOOL takes both hexadecimal as well as base32 encoding of secret key. More on official website. It finds its usage on many applications such as on SSH authentication protected by TOTP, on Linux servers and so on. This tool can be easily installed in any of the popular platforms including on Linux based systems. Here we are installing oathtool on Ubuntu linux based system in few easy steps.

How to Install oathtool on Ubuntu Linux
Also Read: How to Install Kong Gateway on Ubuntu Linux
Step 1: Prerequisites
a) You should have a running Ubuntu Linux system.
b) You should have sudo access to install packages in your system.
c) You should have your system connected with Internet.
Step 2: Update Your Server
Before installing any new package, it is recommended to patch your system with all latest available updates using sudo apt update && sudo apt upgrade command as shown below.
cyberithub@ubuntu:~$ sudo apt update && sudo apt upgrade
Step 3: Install oathtool
To download and install oathtool from default Ubuntu repo, use sudo apt install oathtool command as shown below. This will download and install oathtool packages along with all its dependencies.
cyberithub@ubuntu:~$ sudo apt install oathtool
Step 4: Check Version
Once installed, you can verify the installed version by using oathtool --version command as shown below.
cyberithub@ubuntu:~$ oathtool --version
Step 5: Generate HOTP
To generate HOTP from hexadecimal key, use --hotp switch as shown below.
cyberithub@ubuntu:~$ oathtool --hotp 5510D47A492B809E 267914
You can also generate HOTP from base32 key using -b switch along with --hotp switch as shown below.
cyberithub@ubuntu:~$ oathtool --hotp -b JBFEISCGIFBEISCTI5LVSVCV 958429
Step 6: Generate TOTP
To generate TOTP from hexadecimal key, use --totp switch as shown below.
cyberithub@ubuntu:~$ oathtool --totp 5510D47A492B809E 107431
You can also generate TOTP from base32 key using -b switch along with --totp switch as shown below.
cyberithub@ubuntu:~$ oathtool --totp -b JBFEISCGIFBEISCTI5LVSVCV 171452
Step 7: Generate HOTP using a counter window
You can generate HOTP using counter window by using -w switch. If you would like to generate HOTP of counter window of 3 for hexadecimal key then use -w 3 as shown below.
cyberithub@ubuntu:~$ oathtool -w 3 --hotp 5510D47A492B809E 267914 267392 701484 159402
Similarly, if you are looking to generate HOTP of counter window of 3 for base32 key then use -b switch along with -w 3 as shown below.
cyberithub@ubuntu:~$ oathtool -w 3 --hotp -b JBFEISCGIFBEISCTI5LVSVCV 958429 740144 620400 513692
Step 8: Generate TOTP using a time step
If you are looking to generate TOTP by allowing a window of time steps then use -w switch. Here we are generating TOTP by allowing a window of 3 using -w 3 as shown below for hexadecimal key. In case of TOTP, the default time steps is usually 30 seconds. This means you get a new OTP every 30 seconds.
cyberithub@ubuntu:~$ oathtool -w 3 --totp 5510D47A492B809E 676574 620998 587385 612773
Similarly, if you are looking to generate TOTP by allowing a window of 3 for base32 key then use -b with -w 3 as shown below.
cyberithub@ubuntu:~$ oathtool -w 3 --totp -b JBFEISCGIFBEISCTI5LVSVCV 428663 406940 587522 241409