Use the Google Authenticator App and check the code with this PHP script
Latest commit f9e2673 Aug 8, 2012 1 @chregu Merge pull request #2 from jhitesma/master
Fixed QR code URL


Ported from

You can use the Google Authenticator app from here
to generate One Time Passwords/Tokens and check them with this little
PHP app (Of course, you can also create them with this).

There are many real world applications for that, but noone implemented it yet.

See example.php for how to use it.

There's a little web app showing how it works in web/, please make users.dat 
writeable for the webserver, doesn't really work otherwise (it can't save the
secret). Try to login with chregu/foobar.

What's missing in the example:

* Prevent replay attacks. One token should only be used once 
* Show QR Code only when providing password again (or not at all)
* Regenrate secret