We use cookies.This website uses essential cookies to operate core features. With your consent, we also use analytics cookies to understand traffic and improve the service. For more details, see our .
Was this tool helpful to use?
Your feedback helps us make it better
Generate and verify two-factor authentication (2FA) codes online to secure your accounts.
Supports Base32. Spaces, hyphens, and padding characters are automatically ignored.
Enter a valid secret key to generate TOTP codes, QR codes, and otpauth links.
Overview
Understand what the tool solves, how it works, and the boundaries of its data.
TOTP (time-based one-time password) uses a shared secret and a time-step counter to derive a short code. The authenticator and the service must use the same secret, time period, digit count, and hash algorithm for their outputs to match.
TOTP = HOTP(K, floor((Unix time − T₀) ÷ X))
K is the shared secret, T₀ is the starting time, and X is the time step in seconds.
RFC 6238 specifies 30 seconds as the default time step and allows SHA-256 or SHA-512 HMAC variants as alternatives to SHA-1. This page offers 30- or 60-second periods, 6 or 8 digits, and SHA-1, SHA-256, or SHA-512. Choose values that match the test service.
The secret is entered as Base32 text. Base32 is an encoding format, not encryption or protection for the secret. The page shows the current code and time remaining in the selected period, and it can create a random test secret, an otpauth setup URI, and a QR code using the account and issuer labels.
The URI and QR include the secret and configuration needed by an authenticator. NIST’s current digital identity guidance treats OTP as an authenticator type and explains that manually entered OTPs are not phishing-resistant.
Guide
Follow the workflow and verify inputs and outputs with practical examples.
Enter a Base32 secret reserved for testing, or create a random test secret. Do not paste an active account’s production secret.
Set the digit count, time period, and hash algorithm to the values configured in the test verifier. Account and issuer labels identify the generated setup details; they do not register a key with a service.
Read the current code and seconds remaining. For a setup test, use the displayed URI or QR with a test authenticator, then confirm both sides use the same secret and parameters.
Common causes of mismatched test codes include a mistyped Base32 key, different period or algorithm, a different digit count, or clocks that are not sufficiently aligned.
Use cases
See how the tool fits into real work and everyday tasks.
Developers can generate codes from a dedicated test secret to compare an implementation’s output against a configured test verifier.
An instructor can use a nonproduction key to show how changing the time step or digit count affects the output and why the shared settings must match.
Q&A
Find concise answers to common questions and confusing cases.
No. It calculates and displays a TOTP code and creates setup details. It does not submit a code to a service or confirm that a service has enrolled the same secret.
Check that the shared key, algorithm, digit count, period, and system clocks match. The service may also apply its own acceptance window at time-step boundaries.
No. Base32 represents the key using text characters; anyone who obtains it can use it to derive codes with the matching parameters.
It follows the selected 30- or 60-second period. The page shows the remaining seconds before the next time step.
Notes
Review scope, result limitations, and important precautions before use.
The shared key, setup URI, and QR code contain credentials that can generate valid one-time codes. Do not expose them in screenshots, recordings, messages, or shared screens. Use a test-only secret in this online page; use a dedicated authenticator and follow the service’s own security process for real accounts. A manually entered one-time code is not phishing-resistant, and this page does not prove that a login or account is secure.
Generating a code does not enable two-factor authentication. The service must separately enroll the same secret and matching parameters. Treat a displayed code as sensitive even though it changes with time.
Related
Discover related tools, collections, and available API capabilities.