2FA Authenticator Code Generator (TOTP)

Paste a TOTP secret key to see the current code and how long it stays valid, or create a new secret key. Nothing leaves your browser.

Paste a Base32 secret key, an otpauth://totp/ link, or a line such as account|password|SECRET. From a line with | fields, only the first field is shown, as the label.

Settings for plain secret keys
Digits
Period
Algorithm

Most sites use 6 digits, 30 seconds and SHA-1. An otpauth:// link carries its own settings, which win.

Create a new secret key

For setting up 2FA in your own app or on a test account. The key is random, made in your browser, and uses the settings above.

Off by default. When on, your secrets are saved unencrypted in this browser's local storage, where anyone who uses this browser could read them. Untick it or press Clear to delete them.

Codes

Device time , Unix time -

Codes appear here. Paste a secret key or press Load example.

    Codes come from your device clock. Time zones don't matter, but if the clock is more than about 30 seconds off, the site may reject the code. Nothing you paste is sent anywhere.

    How to use the 2FA code generator

    Paste a secret key into the box, one per line, or press Load example. Each line gets the current code, a Copy button, the seconds left before the code changes and, in smaller text, the next code. Codes update by themselves at the end of each period. These formats work:

    Line you pasteWhat you see
    JBSW Y3DP EHPK 3PXP "Secret 1" and a code. Case, spaces and dashes don't matter.
    otpauth://totp/Example:alice@example.com?secret=JBSWY3DPEHPK3PXP&issuer=Example "Example", "alice@example.com" and a code that uses the link's settings.
    alice@example.com|password|JBSWY3DPEHPK3PXP "alice@example.com" and a code. The password is never shown.
    JBSWY3DPEHPK3PX0 An error: Base32 has no 0, so it is probably the letter O.
    otpauth://hotp/... Not supported: HOTP uses a counter instead of the time.

    The digits, period and algorithm settings apply to plain keys and | lines. Most services use 6 digits, 30 seconds and SHA-1. In a | line, the last field that is valid Base32 of 16 or more characters is used as the key and the first field as the label. If your file uses commas or tabs instead, Split Text can keep just the columns you need.

    How 2FA codes work

    Authenticator apps use TOTP, the time-based one-time password algorithm from RFC 6238. When you turn on 2FA, the service creates a random secret and gives it to your app, usually through a QR code. From then on, your app and the server each calculate the code from the same two inputs: the secret and the current time. Nothing passes between them, which is why codes work offline and why both clocks must agree.

    The time becomes a counter: Unix time divided by the period, normally 30 seconds. The counter is signed with HMAC, usually HMAC-SHA-1, using the secret as the key. HOTP's dynamic truncation (RFC 4226) then uses the last 4 bits of the result to pick a position, reads 31 bits from there, and keeps the last 6 digits of that number. That is the code.

    Where to find your secret key

    • During setup. Next to the QR code, most sites offer a link such as "Can't scan the code?" or "Enter a setup key". It shows the key as Base32 text, often in groups of four characters.
    • Inside the QR code. The QR code holds an otpauth://totp/ link with the key in its secret parameter. A QR reader that shows the text instead of opening an app will reveal it. Paste the whole link here to keep its settings.
    • After setup. Most services never show the key again. You usually turn 2FA off and on, which creates a new key and retires the old one. Some authenticator apps export accounts as otpauth links or JSON; the JSON formatter makes the secret fields easy to find. Google Authenticator exports otpauth-migration:// links, which this tool can't read.

    Why your code might not work

    • Clock drift. Unix time is the same in every time zone, so only the clock itself matters. Many servers also accept the previous and next code, which covers small errors, but a clock that is more than about 30 seconds off often fails. Turn on automatic time and compare the device time shown above the codes with a trusted clock.
    • Wrong settings. If the service uses 8 digits, 60 seconds or SHA-256, codes made with the defaults never match. otpauth links state these settings; a setup key shown as text usually means the defaults.
    • A typo in the key. Base32 uses only A to Z and 2 to 7. A 0, 1 or 8 is usually O, I or L, or B. One wrong character gives a completely different code, not a nearly right one.
    • An old key. If 2FA was reset on the account, the previous key stopped working.

    Is it safe to paste a secret key here?

    Treat a TOTP secret like a password. Anyone who has it can generate your codes without your phone for as long as it stays active. They would still need your password, but the second factor is gone.

    This page calculates codes in your browser with the Web Crypto API. The secret is not sent to our server or anyone else, and it is not saved unless you tick Remember secrets on this device, which keeps it unencrypted in local storage until you untick it or press Clear. You can check: open your browser's developer tools, go to the Network tab and paste a key. No request carries it.

    Your own device still matters: browser extensions that can read pages, clipboard history and anyone else using the computer can see what you paste. For everyday logins, use an authenticator app. Use this page for testing, development and recovery, on a device you trust.

    Testing TOTP in your own app

    Check your implementation against the published test vectors. RFC 4226 appendix D lists HOTP values for the ASCII secret 12345678901234567890: 755224 for counter 0, 287082 for counter 1, up to 520489 for counter 9. RFC 6238 appendix B lists 8-digit TOTP values with a 30-second step:

    Unix timeSHA-1SHA-256SHA-512
    59942870824611924690693936
    1111111109070818046808477425091201
    1234567890890059249181942493441116
    2000000000692790379069882538618901

    The RFC text mentions only the 20-byte seed, but its reference code uses a 32-byte seed for SHA-256 and a 64-byte seed for SHA-512, made by repeating the digits. With the short seed, those columns won't match.

    Pass the time into your TOTP function instead of reading the clock inside it, so tests are repeatable. Write the counter as 8 big-endian bytes, and take the truncation offset from the last byte of the HMAC, which is byte 19 only for SHA-1. When verifying, accept at most one step either side and refuse a code that was already used. To check an enrollment flow, paste the otpauth link from your QR code here and compare the codes.

    Generating a new 2FA secret key

    Press Generate secret key to create a random key with the settings above. It uses the browser's secure random generator and is sized for the hash, as in the RFC 6238 test vectors: 20 bytes (32 Base32 characters) for SHA-1, 32 bytes for SHA-256 and 64 bytes for SHA-512. RFC 4226 asks for at least 160 bits, which the SHA-1 size meets.

    The tool also builds the otpauth link in the Key URI Format that authenticator apps read from a QR code, such as otpauth://totp/My%20App:you%40example.com?secret=...&issuer=My%20App. Digits, period and algorithm are added only when they differ from 6, 30 and SHA-1, because some apps ignore those parameters. Colons are removed from the label because a colon separates the issuer from the account. The link is added to the list, so its codes appear straight away. In production, generate keys on your server and store them encrypted. This button is for prototypes, test accounts and checking your own app's setup flow.

    Frequently asked questions

    Is it safe to enter my 2FA secret key on this site?

    Codes are calculated in your browser and the key is never sent to a server. It is not saved unless you tick Remember secrets on this device. Still treat the key like a password and only paste it on a computer you trust.

    How do I get a 2FA code from a secret key?

    Paste the key, the Base32 text a site shows under a link like "Can't scan the code?" during setup, into the box. The page shows the same code an authenticator app would show for that key, and how many seconds it stays valid.

    Why is my 2FA code not accepted?

    Usually the device clock is off, the service uses other settings such as 8 digits, 60 seconds or SHA-256, or the key has a typo such as 0 instead of O. If 2FA was reset on the account, the old key no longer works.

    Can I get my 2FA codes without my phone?

    Only if you kept the secret key or the otpauth link from when you set up 2FA. Without the key no tool can calculate the codes, so use the backup codes or the account recovery process the service offers.

    How do I generate a 2FA secret key?

    Press Generate secret key. You get a random Base32 key sized for the algorithm, 32 characters for SHA-1, and an otpauth link you can turn into a QR code for an authenticator app. Both are made in your browser and are not sent anywhere.

    What is the difference between TOTP and HOTP?

    TOTP codes change with the time, usually every 30 seconds. HOTP codes change with a counter that goes up each time a new code is generated. Most authenticator apps use TOTP, the only kind this tool supports.

    Does my time zone affect TOTP codes?

    No. TOTP uses Unix time, which counts seconds since 1970 in UTC and is the same everywhere. What matters is that your device clock is accurate to within about 30 seconds.