How it works
A one-time passcode is intended for a single authentication or verification event rather than repeated use as a permanent password. Some codes expire after a short period; others depend on a particular transaction. Delivery and validity rules belong to the service, so not every six-digit number has the same security properties.
A practical example
A login can request a code from an authenticator app or a message. An attacker posing as support may ask the user to read that same code aloud. If it confirms the attacker’s attempted login instead, the user has helped authorize an action despite not sharing the ordinary password.
What to check
Read the message or prompt carefully to identify the account and purpose. Enter a code only in the legitimate process you initiated and never disclose it to an unexpected caller. If an app-generated code fails, check the selected account and device time before repeatedly requesting replacements. Use the service’s genuine recovery flow if access is lost.
Limits and safe use
Single use does not make a code phishing-resistant: it can be relayed while still valid. Receiving an unexpected code does not by itself prove a successful account breach. Investigate the associated activity through the real service. Keep backup codes private too; their format and validity differ from regularly generated authenticator codes.