NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #1229 most downloaded on pub.dev
RFC6238 Time-Based One-Time Password / Google Authenticator Library
Last release 10 days ago
28 Sep 2026
Release timing varies
gaps range from 4 weeks to 2.3 years
Nearly every release is documented
notes for 29 of 30 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
31 releases · first in 2013
Update timezone to 0.11.0 (Thanks @EdsonMello-code)
Update timezone to 0.10.0 (Thanks @NM4ik )
One column per quarter.
Allow lowercase base32 strings if isGoogle is set to true by @amadejkastelic in #46
Full Changelog: v3.1.2...3.1.4
Fix incorrect padding logic
Fix incorrect padding logic
- Allow isGoogle flag for HOTP
Loosen version constraint on the crypto so that there is no conflict between our library and those requiring 3.0.1 or 3.0.0. crypto versions 3.0.1 and
crypto so that there is no conflict between our library and those requiring 3.0.1 or 3.0.0. crypto versions 3.0.1 and 3.0.2 don't affect this library or are just doc/link fixes.Bug where all secrets were being treated as Base32 by default, when RFC default is ASCII. Base32 is only when using Google Authenticator mode. This ca
notp and otplib to verify my outputs.Partially change behavior, if it is invalid Base32, it should throw, but in certain cases, it still doesn't throw, so we do fallback behavior.
Fix when secrets are not Base32 causing infinite loops because the resulting list is size 0.
Add remainingSeconds() in order to calculate the remaining seconds based on lastUsedTime. (thanks @AkbarAsghari)
remainingSeconds() in order to calculate the remaining seconds based on lastUsedTime. (thanks @AkbarAsghari)Add lastUsedTime and lastUsedCounter to provide additional information for users and potential debugging points.
lastUsedTime and lastUsedCounter to provide additional information for users and potential debugging points.- Docs and file cleanup
- Nullsafety conversion
Improve pub package score (thanks @DavBfr)
Update quick_log to latest version
Correctly use Google Auth flag (isGoogle) to disable padding. (thanks hpoul)
isGoogle) to disable padding. (thanks hpoul)Add Google Auth flag, because they do SHA1 TOTP without Padding the secret.
Fix secret paddding to follow proper TOTP secret padding and sizing for SHA256, SHA512
Fix type error at runtime for RandomSecret generation. MR #14 (thanks readytopark)
Switch to crypto lib inplace of PointyCastle for HMAC
No changes from rc1, accepting the 1-3 second timing difference between constant time code checks until someone can help me figure out how to make it
Nothing published for this version
Switched to PointyCastle for crypto and support for more than SHA1 hashing for tokens (amadejkastelic)
Add new TOTP interval parameters (optional)
- Cleanup and remove dead code
- Dart 2.0 updates
- Dart 1.0 Readiness
- Fixing crypto library.
- Fixing language changes.
No functionality changes, just fixing a bad file state it git and in the package involving the case of the file.
- Initial Documented Release
Your coding agent can read these notes before it upgrades. Set up the MCP server →