Ukraine flag

We stand with our friends and colleagues in Ukraine. To support Ukraine in their time of need visit this page

Programmable Hardware OTP Token

The Protectimus Flex hardware OTP token is a programmable TOTP one-time password generator.
You can use Protectimus Flex with almost any two-factor authentication system that supports OATH standards.
The Protectimus Flex TOTP tokens come with embedded secret keys that can be reprogrammed via NFC using an Android smartphone.

The Protectimus Flex programmable hardware TOTP token supports secret keys from 16 to 32 characters long in Base32. You can add one secret key per an OTP token. The time synchronization function is supported – the exact current time is set when the secret key is added to the TOTP token.

TOTP tokens Protectimus Flex can be used for two-factor authentication on any website or service that supports OATH algorithms. If it is possible to connect a hardware TOTP token or an application for generating one-time passwords on a particular website, you may use Protectimus Flex on this site.

For example, the Protectimus Flex TOTP token will work for two-factor authentication in Office 365, Microsoft Azure, Google, PayPal, Keycloak, Github, Dropbox, Facebook, Sophos, most cryptocurrency exchanges, and many other services.

Programmable TOTP Token

You can connect the TOTP hardware token Protectimus Flex to any two-factor authentication system, regardless of whether it supports hardware OTP tokens or only 2FA applications. Only your administrators will have secret keys for hardware tokens. The token is programmed using the Protectimus TOTP Burner app on Android smartphone with NFC support.

Time Synchronization

The time synchronization function has been added to Protectimus Flex to eliminate the possibility of time drift that leads to discrepancies between the hardware TOTP token and the two-factor authentication server to which you connect this OTP token. When you add a secret key into an OTP token, the exact current time step is set.

User-Friendly Design

The Protectimus Flex TOTP token looks like a key fob with a small display. The body of the token is protected from shock, as well as from moisture and dust. As practice has shown, this is the most successful design solution for a hardware OTP token. It is convenient for the user to bind such a TOTP token to a keychain and always have it with them.


  • Supported algorithms: TOTP (RFC 6238); SHA-1;
  • Compliance with OATH standards;
  • Can be programmed over NFC with the help of a free app Protectimus TOTP Burner (an Android smartphone is required);
  • Supported secret keys: 16- to 32-character long (Base32);
  • Size: 28.62mm х 61.62mm х 8.8mm;
  • Weight: 16.1 g;
  • Display Type: LED, 6 digits with time indicator;
  • Dust and water resistance: IP67;
  • Possibility of branding for orders of 1000 pieces;
  • Warranty period: 12 months;
  • Battery charge indicator.


Protectimus FLEX (English)

How to buy?

You can easily become a happy owner of this device. Depending on your preference, we can place your company’s logo and other visual features on the device; you can also choose the color of your token. Producing customized tokens based on your specific requirements takes additional 3-4 weeks.

The price of tokens does not include shipping and delivery costs and other additional charges, such as taxes and customs duties.

Delivery times depend on several factors, in particular: lot/consignment size, token availability at our warehouse, and postal service. Besides, the delivery time will depend on whether additional visual features need to be placed on the products. Typically, if there is a sufficient quantity of products at the warehouse, orders are delivered within 2 to 6 weeks.

To place an order, please fill out the form, and our specialist will promptly contact you.

See Also

ImageToken ModelPrice, pcs
Brief DescriptionDescription
PROTECTIMUS TWOPROTECTIMUS TWO$11.99$11.49$10.99$9.99$8.99

$3 when paying service in advance for a year
Bulletproof OTP token: reliable, waterproof, stylishBulletproof TOTP token: reliable, waterproof, stylish

$3 when paying service in advance for a year
PROTECTIMUS FLEXPROTECTIMUS FLEX$19.99$18.99$16.99$15.99$13.99The reprogrammable and stylish hardware TOTP tokenThe reprogrammable hardware TOTP token
PROTECTIMUS SHARKPROTECTIMUS SHARK$14.99$14.49$13.99$12.99$11.99This hardware token offers exceptional security features by supporting TOTP (RFC 6238) and SHA-256 algorithmWe recommend using this token
PROTECTIMUS SLIM MINIPROTECTIMUS SLIM MINI$29.99$28.99$26.99$24.99$21.99Reprogrammable NFC token, that fits any two-factor authentication systemReprogrammable NFC token
PROTECTIMUS SMARTPROTECTIMUS SMARTfreeAvailable for all key Android and iPhone platformsSoftware token for Android and iPhones
PROTECTIMUS SMARTPROTECTIMUS PUSHfreePush via Android and iPhone applicationsСonvenient and reliable
PROTECTIMUS BOTPROTECTIMUS BOTfreeOTP delivery via messenger — easy, secure, convenient. The service is available on Telegram, Viber and Facebook Messenger.The service is available on Telegram, Viber and Facebook Messenger
PROTECTIMUS SMSPROTECTIMUS SMS$2 per user/monthMinimum hassleMinimum hassle

Knowledge base

Programmable TOTP tokens are more secure and convenient to use than classic TOTP tokens for a number of reasons. Firstly, you do not need to have access to the two-factor authentication server to connect such a TOTP token – the secret key is transferred to the programmable TOTP token Protectimus Flex in the same way as in the 2FA application. Secondly, no one except the end owners knows the secret keys of your TOTP tokens if you programmed them yourself. Thirdly, programmable TOTP tokens are often used as a replacement for 2FA applications like Google Authenticator or Protectimus Smart if company employees or customers refuse to use their own smartphones for two-factor authentication.

Programmable hardware TOTP tokens Protectimus FLEX are produced with pre-installed secret keys and you may use them as classic hardware OTP tokens. Upon request, we provide the client with the secret keys from Protectimus FLEX tokens, and they may add these secret keys to their two-factor authentication system. But the main feature of Protectimus FLEX TOTP tokens is the possibility of programming the token. The client can easily reprogram the secret key in the Protectimus FLEX OTP token if they have an NFC-enabled Android smartphone. One Protectimus FLEX OTP token has a slot for one secret key, but you can change it an unlimited number of times.

Hardware OTP token Protectimus FLEX is suitable for any service that supports two-factor authentication according to the standards of the OATH initiative, namely the time-based one-time password generation algorithm (TOTP). If the system you want to protect access to allows you to activate 2FA and use a hardware TOTP token or Google Authenticator app, then in 98 cases out of 100, the Protectimus FLEX OTP token will suit you. For example, you can definitely use Protectimus FLEX with Google, Office 365, Azure MFA, PayPal, Duo, Okta, Mailchimp, Facebook, Dropbox, GitHub, Kickstarter, KeePass, Microsoft, Teamviewer, etc. But note: the length of the secret key generated by the system you want to bind the token to must be no more than 32 characters in Bas32. Check the length of your secret key before purchasing an OTP token.

Programmable OTP tokens Protectimus Flex can be connected to the resources you want to secure access to, just like two-factor authentication apps like Google Authenticator or Protectimus SMART OTP. Start activating 2-factor authentication and choose a 2FA app as your authentication method. At the stage of scanning a QR code with a secret key, use the Protectimus TOTP Burner application. Then bring the Protectimus Flex hardware OTP token to the smartphone and add the scanned secret key into this OTP token via NFC. The Protectimus TOTP Burner application is designed so that you will intuitively understand how to program the secret key into the Protectimus Flex token.

Why programmable hardware OTP token is better than classic?

How does a programmable hardware OTP token work?

How to understand if Protectimus FLEX is right for you?

How to program your Protectimus FLEX token?