All tools run in your browser — your files never leave your device.
All tools154

Developer & Security

TOTP Code Generator

Live 2FA codes from a Base32 secret, with the countdown.

What it does. TOTP is the algorithm behind six-digit authenticator codes. It takes a shared secret and the current 30-second time step, computes an HMAC-SHA1 of them, and truncates the result to six digits. Because both sides derive the code from the clock, nothing is transmitted when you log in.
Runs in your browserNothing uploadsNo signupWorks offline

How to use TOTP Code Generator

  1. Paste the Base32 secret from the service’s setup screen.
  2. The current code appears with a countdown to the next one.
  3. Adjust digits or period only if the service specifies something non-standard.

What this is for, and what it is not

This is a debugging and recovery tool. It is useful for checking that a secret you have stored is the right one, for testing a TOTP implementation you are building, and for reading a code when your phone is not to hand.

It is not a replacement for an authenticator app. A secret pasted into a browser page is a secret sitting in a browser page — no worse than this tool makes it, but no better either.

If you are storing long-term secrets, use a dedicated authenticator or a password manager with TOTP support. Both keep the secret in protected storage rather than in a text field.

Why codes fail

  • Clock drift. TOTP is time-based. A device more than about 30 seconds off produces codes the server rejects. This is the cause in the large majority of cases.
  • Wrong period. 30 seconds is standard; a few services use 60.
  • Wrong digit count. Six is standard, some use eight.
  • Wrong algorithm. SHA-1 is standard and still correct here — RFC 6238 specifies it, and the known SHA-1 weaknesses do not apply to HMAC.
  • Secret transcribed wrongly. Base32 excludes 0, 1 and 8, so those characters mean a typo.

Reading a setup QR code

The QR code on a 2FA setup screen encodes an otpauth:// URI containing the secret, the issuer, the account and any non-default parameters.

Most services show a "can’t scan it?" link that reveals the same secret as text. That is the string to paste here.

Store the secret somewhere durable when you set 2FA up. Losing it means recovery codes or an account-recovery process, and the moment to think about that is before it happens rather than after.

Frequently asked questions

Why is my code rejected?

Nine times out of ten, clock drift. TOTP derives the code from the current time, so a device more than about 30 seconds out of sync produces codes the server will not accept. Sync your clock and try again.

Is TOTP still secure if it uses SHA-1?

Yes. RFC 6238 specifies HMAC-SHA1, and HMAC does not depend on the collision resistance that is broken in SHA-1. This is a different use of the algorithm from certificate signing.

Is my secret sent anywhere?

No. The code is computed in your browser with Web Crypto. Nothing is transmitted — which is essential, since the secret is the entire security of your second factor.

Can I use this instead of an authenticator app?

For testing and recovery, yes. As a daily driver, no — a secret pasted into a web page is not protected storage. Use an authenticator app or a password manager with TOTP support.

What if my secret contains 0, 1 or 8?

It does not. Base32 uses A–Z and 2–7 precisely to avoid characters confusable with letters, so a 0, 1 or 8 means the secret was transcribed incorrectly.