pkg.sopackage field notes

brew / rank 1431

Install oath-toolkit with Homebrew

Tools for one-time password authentication systems. Version 2.6.14 via Homebrew; verified 2026-06-27.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install oath-toolkit

provider-native install command

overview

Package summary

Tools for one-time password authentication systems

Commands and aliases

  • oathtool
  • pskctool

history

Project history and usage

OATH Toolkit is a long-running free software implementation of one-time password infrastructure. It provides shared C libraries, the oathtool and pskctool command-line tools, and a pam_oath module for integrating HOTP/TOTP authentication into Unix login stacks.

Project history

Simon Josefsson introduced the OATH Toolkit publicly in January 2011 as software for OATH one-time password authentication, including oathtool and pam_oath. A May 2011 release announcement for version 1.10.0 points to the Nongnu project page, man pages, PAM documentation, API reference, signed release tarballs, and the Savannah project home.

The toolkit tracks the standards ecosystem around one-time passwords: HOTP from RFC 4226, TOTP from RFC 6238, and PSKC from RFC 6030. Later releases added support for HMAC-SHA256 and HMAC-SHA512 TOTP generation and validation APIs in version 2.6.0, and the project moved version-controlled source hosting to GitLab in version 2.6.2 before moving public Git hosting to Codeberg in version 2.6.13.

Adoption history

OATH Toolkit spread through Unix package ecosystems because it solved a boring but durable operations problem: generating and validating standard OTP values and adding PAM-based OTP checks to existing systems. The input package record lists apk, Homebrew, Debian, Fedora, MacPorts, Nix, Arch, Ubuntu, and openSUSE package names, reflecting broad distribution rather than a single application community.

How it is used

Developers use liboath when embedding HOTP/TOTP validation in C applications, operators use oathtool for token generation and testing, pskctool handles Portable Symmetric Key Container data, and administrators use pam_oath to require OTP values during PAM authentication. A common deployment stores token records in a usersfile such as /etc/users.oath.

Why package nerds care

The package is a classic security-toolchain package: small command-line utilities, a C library ABI, a PAM module, man pages, signed source releases, and long-term distro packaging. It also shows how standards-based authentication plumbing ages: compatibility fixes, crypto algorithm additions, build-system maintenance, and security advisories matter as much as new features.

Timeline

  • 2005: RFC 4226 defined the HOTP algorithm.
  • 2010: RFC 6030 defined PSKC for symmetric key container data.
  • 2011: RFC 6238 defined TOTP.
  • 2011-01-20: Simon Josefsson published an introduction to OATH Toolkit.
  • 2015-05-19: OATH Toolkit 2.6.0 added TOTP support with HMAC-SHA256 and HMAC-SHA512 APIs.
  • 2016-08-27: OATH Toolkit 2.6.2 noted that version-controlled source moved to GitLab.
  • 2024-10-03: OATH Toolkit 2.6.12 addressed CVE-2024-47191 in pam_oath/liboath.
  • 2025-07-29: OATH Toolkit 2.6.13 moved Git hosting to Codeberg.

Related projects

  • OATH Toolkit is directly tied to the OATH HOTP/TOTP standards, Unix PAM, libxmlsec for PSKC-related functionality, and downstream distro packages such as Debian's oathtool/liboath-dev packages.

Sources

security posture

Risk level: green

narrow executable package without higher-risk signals.

Risk classifier

green risk · low confidence · appliance

Why

  • narrow executable package without higher-risk signals

Signals

  • metadata:no-higher-risk-signals

Install behavior

  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Credential files

Credential-bearing paths to review before unattended agent runs.

Unix
/etc/users.oath

executables

Installed executables

CommandKindExposureNote
oathtoolexecutableindexed executableDiscovered from the local executable index.
pskctoolexecutableindexed executableDiscovered from the local executable index.

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-08-03
manager version2.6.14
manager updated2026-06-27
local dataunknown
upstreamnot available
latest detectednot detected
  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:oath-toolkit
Version2.6.14
Package managerHomebrew
Homepagehttps://oath-toolkit.codeberg.page/
Last updated2026-06-27T14:40:16-04:00
Pulseupdated
Bottlenot recorded
Servicenone declared

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • Nucleus package database
  • curated configuration and credential file locations
  • curated package history
  • pkgdb category and tag curation