the enrolled TOTP record
the code as typed (spaces and hyphens ignored)
Optionalopts: { at?: number; window?: string | number }
optional { at, window } to override the moment and window
{ ok: true, counter, drift }, or { ok: false, reason, detail }
with reason one of shape, store, mismatch or replay
Verifies a presented code against an enrolled record, in constant time, across the skew window.
The digits, period and algorithm come from the record; the window is read live. A code at or below the record's
lastCounteris refused as already spent. A refusal carries its error code.