About this tool
This is a workbench for anyone building or debugging two-factor sign-in. Paste a Base32 secret or a full otpauth:// link and you get the same six- or eight-digit codes an authenticator app would show, refreshed live with a countdown ring. It handles both kinds of one-time password: TOTP, where the code changes every 30 or 60 seconds, and HOTP, where it changes each time a counter goes up.
The most common 2FA bug is “the code is always wrong”, and the cause is usually a clock that is a little out, a secret copied wrongly or a mismatched setting. So the tool shows the codes for the steps either side of now, lets you type in a code from an app or server to see exactly which time step or counter it belongs to, and explains bad Base32 characters in plain words. You can also generate a fresh random secret and get its otpauth:// link and QR code to scan into a test phone.
Please use it only with test accounts. The secret is the whole lock: never paste one that protects a real account into any website. Here, every code is calculated with your browser’s built-in cryptography, and nothing is stored or sent.
How to use 2FA Code Generator (TOTP)
- Paste a Base32 secret or an otpauth:// link into the top box, or press “New random secret” to make one.
- Check the settings match your server: TOTP or HOTP, the algorithm, 6 or 8 digits, and a 30 s or 60 s period (or the counter for HOTP). A pasted link fills these in for you.
- Read the current code, watch the ring count down, and press Copy when you need it.
- If a code is rejected, type it into “Check a code” to see whether it belongs to an earlier or later step.
- To try a secret on a phone, fill in Issuer and Account, then scan the QR code or press “Download QR (PNG)”.
The RFC 6238 test secret “12345678901234567890” (Base32 GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ) gives the 8-digit SHA-1 code 94287082 at 59 seconds past midnight on 1 January 1970, exactly as the standard says.
Features
- TOTP (RFC 6238) and HOTP (RFC 4226) codes, checked against the official test vectors.
- SHA-1, SHA-256 and SHA-512, 6 or 8 digits, and 30 or 60 second periods.
- Reads otpauth:// links, filling in the secret, issuer, account, algorithm, digits, period and counter.
- Secrets in Base32, hex or plain text, with clear messages for mistyped Base32 and secrets that are too short.
- Codes for two steps before and after now, and a code checker that looks 20 time steps either way (10 minutes at 30 s) or 15 counters ahead.
- New random secrets sized to the algorithm (160, 256 or 512 bits) from your browser’s secure random generator.
- otpauth:// link and black-on-white QR code to scan, copy or save as PNG.
- Shows your device’s clock in local time and UTC, since every TOTP code depends on it.
Tips and good to know
- Many authenticator apps, including Google Authenticator, ignore anything other than SHA-1, 6 digits and 30 seconds. Test unusual settings with the app your users actually have.
- If codes are always one step out, the server or phone clock is drifting. Turn on automatic time on both rather than widening the server’s accepted window a lot.
- Most servers accept the previous code as well as the current one, so a code typed just as the ring runs out usually still works.
- Base32 secrets are often shown in groups of four with spaces. Paste them as they are: spaces, dashes and lower case are fine.
Frequently asked questions
Is my secret uploaded or saved?
No. The codes are calculated by your browser’s built-in cryptography on your device. Nothing you type is sent anywhere or stored, and it is gone when you close the tab. Even so, only use secrets from test accounts.
Can I use this instead of an authenticator app?
Please don’t. A website is the wrong place to keep the key to a real account, and a tab is easy to lose. Use a proper authenticator app or password manager for real accounts; this tool is for building and testing 2FA.
Is it free? Are there limits?
Yes, it is free, with no sign-up and no limits on how many secrets or codes you try.
Does it work on a phone or offline?
Yes. It works in Safari, Chrome and Firefox on phones and computers, and once loaded it needs no connection. Time-based codes rely on your device’s clock being correct.
Why doesn’t my code match the app?
Usually one setting differs (algorithm, digits or period), the secret was copied with a wrong character, or one of the clocks is out. Type the app’s code into “Check a code” to see if it matches a nearby time step.
What is the difference between TOTP and HOTP?
TOTP codes come from the current time, so they change every 30 or 60 seconds. HOTP codes come from a counter that goes up each time a code is used, so a code stays valid until the next one is used. TOTP is far more common.
Page last reviewed
