OATH
OATH (Initiative for Open Authentication) is a vendor-neutral nonprofit standards organization publishing open, royalty-free specifications for strong authentication, including HOTP, TOTP, and OCRA, serving authentication vendors, service providers, enterprises, and device manufacturers globally.
- Company typePrivate
- Founded2000
- HeadquartersAnaheim, United States
- Headcount—
- GTM typeB2B
- OfferingServices
What OATH does
OATH (Initiative for Open Authentication) is a vendor-neutral, nonprofit industry collaboration that publishes open, royalty-free specifications for strong authentication. Headquartered in Anaheim, California, and in operation since 2000, OATH does not sell commercial products; its outputs are standardized authentication algorithms and reference architectures distributed at no cost to implementers. Core specifications include HOTP (HMAC-based One-Time Password, RFC 4226), TOTP (Time-based One-Time Password, RFC 6238), OCRA (OATH Challenge-Response Algorithm, RFC 6287), PSKC (RFC 6030), and DSKPP (RFC 6063), collectively underpinning authentication for billions of users and devices globally.
The organization operates through technical working groups and a certification program that validates interoperability across vendor products, including HOTP Token, TOTP Authenticator, and OCRA Transaction Signing profiles. Its primary constituents are authentication vendors producing tokens and authenticators, service providers and enterprises deploying authentication at scale, and device manufacturers requiring standardized built-in authentication. OATH publishes reference architectures, implementation guides, and deployment guidance to support adoption and to bridge legacy OTP deployments with modern passwordless and phishing-resistant approaches.
In January 2025, OATH joined the Passwordless Collaboration Initiative to align open OTP standards with broader passwordless and phishing-resistant authentication efforts. Its distribution model is open publication via openauthentication.org and IETF RFCs, with no direct revenue stream tied to sales; the organization's value is realized through ecosystem adoption and standards-body recognition rather than commercial monetization.
OATH firmographics
Firmographics- Name
- OATH
- Legal name
- Initiative for Open Authentication
- Website
- https://openauthentication.org
- Company type
- Private
- Founded year
- 2000
- Operating status
- Operating
- Short description
- OATH (Initiative for Open Authentication) is a vendor-neutral nonprofit standards organization publishing open, royalty-free specifications for strong authentication, including HOTP, TOTP, and OCRA, serving authentication vendors, service providers, enterprises, and device manufacturers globally.
- Ownership category
- akta.pro rank
OATH industry classification
Industry- Product category
- Authentication Standards
- NAICS
- Computer Systems Design Services (541512)
- SIC
- Services-Computer Programming Services (7371)
- akta.pro primary industry
- Multi-Factor Authentication (MFA) & Passwordless Authentication (HDAEAJAC)
- akta.pro secondary industry
- Authentication (MFA/Passwordless/Biometrics) Platforms (BPAMAEAE)
Keywords
Where OATH is headquartered
LocationHeadquarters
- HQ city
- Anaheim
- HQ country
- United States
- HQ region
- North America
Markets served
OATH business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Operations
Distribution channels3 records
Marketing channels5 records
OATH product offering
Product offeringCore offering
OATH (Initiative for Open Authentication) is a vendor-neutral, nonprofit industry collaboration that publishes open, royalty-free specifications for strong authentication, including the HOTP (RFC 4226), TOTP (RFC 6238), and OCRA (RFC 6287) one-time password algorithms, along with PSKC (RFC 6030) and DSKPP (RFC 6063) key provisioning standards. It complements these specifications with an OATH Reference Architecture, implementation guides, and a vendor Certification Program that validates interoperability across hardware tokens, software authenticators, and validation servers. OATH does not sell end-user products; instead it defines interoperable building blocks that vendors and enterprises implement in their own authentication solutions.
Product overview
OATH (Initiative for Open Authentication) is a vendor-neutral standards organization, not a product company. It publishes open, royalty-free specifications for strong authentication, including core OTP algorithms (HOTP, TOTP, OCRA) and key provisioning standards (PSKC, DSKPP). The portfolio consists of technical standards documents (RFCs), reference architecture guidance, implementation guides, and a certification program for vendor products. OATH does not sell or offer end-user products; instead it defines interoperable building blocks that vendors implement in their own authentication solutions.
Differentiator
Problem solved
Functional benefit
Products and services
- HOTP (HMAC-based One-Time Password)
Quantifiable outcome
- Widely deployed across billions of users and devices globally
Companies that use OATH
Customer profileSegments3 records
Ideal customer profiles3 records
OATH technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature7 records
OATH partnerships and signals
Strategic signalScale indicators1 record
Recent moves4 records
Expansion highlights4 records
OATH competitors and assessment
Company assessmentBroad incumbents
- GSMA: Global mobile industry organization that drives standards relevant to SIM-based and mobile authentication. Comparable to OATH in setting industry-wide authentication norms that span vendors and operators.
- Internet Engineering Task Force (IETF): The standards body that publishes the RFCs in which OATH's specifications (HOTP, TOTP, OCRA, PSKC, DSKPP) are formalized. Comparable as the upstream venue where authentication standards are defined and evolved.
- World Wide Web Consortium (W3C): Standards organization driving Verifiable Credentials and Web Authentication (WebAuthn). Operates in the same identity and authentication standards space as OATH and influences where ecosystem investment flows.
- OASIS (Organization for the Advancement of Structured Information Standards): Standards consortium that develops open standards including security and identity-related specifications (e.g., SAML, KMIP). Peer to OATH in producing open, royalty-free specifications adopted by enterprise and government customers.
- National Institute of Standards and Technology (NIST): U.S. government body that publishes authentication and cryptographic standards (SP 800-63, FIPS). Peer to OATH as a foundational authority whose guidance shapes which authentication standards gain enterprise adoption.
Others
- Internet Society (ISOC): Global nonprofit supporting open Internet standards and governance, including IETF. Operates in the same broader ecosystem that OATH depends on and influences how open authentication standards are governed and adopted.
Emerging players
- Trusted Computing Group (TCG): Industry body defining hardware-rooted trust standards (TPM, TPM 2.0). Overlaps with OATH in shaping how authentication credentials and keys are securely provisioned and bound to devices.
- Kantara Initiative: Industry group focused on digital identity assurance, identity management, and interoperability. Operates in the same identity-standards ecosystem as OATH with overlapping enterprise and government stakeholders.
Direct peers
- OpenID Foundation: Manages open standards for identity and authentication (OpenID Connect, OAuth). Overlaps with OATH in the broader authentication/identity standards landscape and works with overlapping vendors and identity providers.
- FIDO Alliance: Industry consortium developing open authentication standards (FIDO2, WebAuthn, passkeys). Direct peer to OATH as both publish royalty-free authentication specifications and run vendor certification programs targeting the same identity stakeholder base.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
OATH social profiles
Digital presenceOATH financial estimates
Financial estimateRevenue estimate
Valuation estimate
OATH leadership team
Management profileNumber of profiles
Profiles1 record
OATH funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
OATH M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about OATH
What does OATH do?
OATH (Initiative for Open Authentication) is a vendor-neutral, nonprofit industry collaboration that publishes open, royalty-free specifications for strong authentication, including the HOTP (RFC 4226), TOTP (RFC 6238), and OCRA (RFC 6287) one-time password algorithms, along with PSKC (RFC 6030) and DSKPP (RFC 6063) key provisioning standards. It complements these specifications with an OATH Reference Architecture, implementation guides, and a vendor Certification Program that validates interoperability across hardware tokens, software authenticators, and validation servers. OATH does not sell end-user products; instead it defines interoperable building blocks that vendors and enterprises implement in their own authentication solutions.
Is OATH a public or private company?
OATH is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was OATH founded?
OATH was founded in 2000.
Where is OATH based?
OATH is headquartered in Anaheim, United States, in the North America region.
Who are OATH's main competitors?
Broad incumbents on record are GSMA, Internet Engineering Task Force (IETF), World Wide Web Consortium (W3C), OASIS (Organization for the Advancement of Structured Information Standards) and National Institute of Standards and Technology (NIST). Internet Society (ISOC) is listed as an others. Emerging players are Trusted Computing Group (TCG) and Kantara Initiative. Direct peers are OpenID Foundation and FIDO Alliance.
Does OATH have an API?
No public API is recorded for OATH.
What industry is OATH in?
OATH's product category is Authentication Standards. Its primary akta.pro industry code is HDAEAJAC, Multi-Factor Authentication (MFA) & Passwordless Authentication, with a secondary code of BPAMAEAE, Authentication (MFA/Passwordless/Biometrics) Platforms. Its NAICS code is 541512 and its SIC code is 7371.