TOTP Generator and 2FA Code Tester

Generate time-based one-time codes from a Base32 secret, the same six-digit codes authenticator apps show. Test your 2FA setup, check a code, and get the otpauth link and QR code.

Updated
Codes are calculated in your browser. The secret is never sent or stored.

Current code

------

– seconds left · previous – · next –

Scan with an authenticator app
otpauth:// URI
–

How to use the TOTP Generator

  1. Paste the Secret (Base32) from your 2FA setup, or press Generate secret for a new 20-byte secret.
  2. Match the Digits, Period, and Algorithm to your system. The Current code updates with a countdown.
  3. Scan the QR code with an authenticator app, or type a code from your app into Check a code to confirm both sides agree.

How it works

TOTP (RFC 6238) is HOTP (RFC 4226) with the counter taken from the clock:

counter = floor(unix_time / period)
code = truncate(HMAC(secret, counter)) mod 10^digits
  • The counter is written as 8 bytes, big-endian, and signed with HMAC-SHA-1 by default.
  • Dynamic truncation takes the low 4 bits of the last byte as an offset and reads 31 bits from there.
  • The secret is Base32 (A-Z and 2-7), usually 20 bytes, which is 32 characters.
  • Servers normally accept the codes one step before and after, so a clock that is up to 30 seconds off still works.

HMAC runs in your browser with Web Crypto.

Examples

  • RFC 6238 test vector: secret ASCII 12345678901234567890 (Base32 GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ), time 59, SHA-1, 8 digits = 94287082.
  • The same secret at time 1111111109 gives 07081804.
  • The setup link for Utilza and [email protected] looks like otpauth://totp/Utilza%3Aada%40example.com?secret=...&issuer=Utilza.

Limitations

  • Codes depend on your device's clock. If the codes don't match your app, check that both clocks are set automatically.
  • Google Authenticator ignores the algorithm, digits, and period settings on some versions and always uses SHA-1, 6 digits, and 30 seconds.
  • HOTP (counter-based codes) and Steam Guard codes are not supported.
  • Don't paste the secret of a real account you care about into any website. Use this to test your own 2FA setup.

Frequently asked questions

What is TOTP?

A time-based one-time password: a short code, usually 6 digits, that changes every 30 seconds. It is the "authenticator app" form of two-factor authentication.

Why doesn't my code match the authenticator app?

Usually the device clocks differ, or the digits, period, or algorithm settings don't match. Check the time on both devices first.

How long should a TOTP secret be?

RFC 4226 asks for at least 128 bits (16 bytes) and recommends 160 bits (20 bytes). Generate secret creates 20 random bytes.

Is my secret sent anywhere?

No. Codes and the QR code are made in your browser. The secret is never uploaded or stored.

Often used together with the TOTP Generator.

  • QR Code Generator

    Creates QR codes for links, Wi-Fi, contacts, and more, as PNG or SVG.

  • HMAC Generator

    Signs text or files with HMAC-SHA256 and other hashes, and checks signatures.

  • Random Token Generator

    Generates secure random tokens and API keys with a chosen length, alphabet, and prefix.