Tools marked “Coming soon” are being built now.

Developer tools
Developer · Free · Private

2FA Code Generator (TOTP)

Live authenticator codes from a test secret, with clock-drift checks and a scannable QR code. For developers and testers.

  • Runs in your browser
  • No upload
  • No sign-up

For testing and development only. Never paste the secret of a real account you care about into any website, this one included: anyone who has the secret can make your codes forever. This page stores nothing and sends nothing. Every code is worked out on your device.

Code type
Digits
Period
Current code––– –––
Codes either side of now, for clock-drift checks

Type a code from an app or server to see which time step (or counter) it belongs to.

Add it to an authenticator app

Scan the code with Google Authenticator, Microsoft Authenticator, 1Password, Authy or similar. The QR contains the secret, so treat it like a password.

About this tool

This is a workbench for anyone building or debugging two-factor sign-in. Paste a Base32 secret or a full otpauth:// link and you get the same six- or eight-digit codes an authenticator app would show, refreshed live with a countdown ring. It handles both kinds of one-time password: TOTP, where the code changes every 30 or 60 seconds, and HOTP, where it changes each time a counter goes up.

The most common 2FA bug is “the code is always wrong”, and the cause is usually a clock that is a little out, a secret copied wrongly or a mismatched setting. So the tool shows the codes for the steps either side of now, lets you type in a code from an app or server to see exactly which time step or counter it belongs to, and explains bad Base32 characters in plain words. You can also generate a fresh random secret and get its otpauth:// link and QR code to scan into a test phone.

Please use it only with test accounts. The secret is the whole lock: never paste one that protects a real account into any website. Here, every code is calculated with your browser’s built-in cryptography, and nothing is stored or sent.

How to use 2FA Code Generator (TOTP)

  1. Paste a Base32 secret or an otpauth:// link into the top box, or press “New random secret” to make one.
  2. Check the settings match your server: TOTP or HOTP, the algorithm, 6 or 8 digits, and a 30 s or 60 s period (or the counter for HOTP). A pasted link fills these in for you.
  3. Read the current code, watch the ring count down, and press Copy when you need it.
  4. If a code is rejected, type it into “Check a code” to see whether it belongs to an earlier or later step.
  5. To try a secret on a phone, fill in Issuer and Account, then scan the QR code or press “Download QR (PNG)”.
Example

The RFC 6238 test secret “12345678901234567890” (Base32 GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ) gives the 8-digit SHA-1 code 94287082 at 59 seconds past midnight on 1 January 1970, exactly as the standard says.

Features

  • TOTP (RFC 6238) and HOTP (RFC 4226) codes, checked against the official test vectors.
  • SHA-1, SHA-256 and SHA-512, 6 or 8 digits, and 30 or 60 second periods.
  • Reads otpauth:// links, filling in the secret, issuer, account, algorithm, digits, period and counter.
  • Secrets in Base32, hex or plain text, with clear messages for mistyped Base32 and secrets that are too short.
  • Codes for two steps before and after now, and a code checker that looks 20 time steps either way (10 minutes at 30 s) or 15 counters ahead.
  • New random secrets sized to the algorithm (160, 256 or 512 bits) from your browser’s secure random generator.
  • otpauth:// link and black-on-white QR code to scan, copy or save as PNG.
  • Shows your device’s clock in local time and UTC, since every TOTP code depends on it.

Tips and good to know

  • Many authenticator apps, including Google Authenticator, ignore anything other than SHA-1, 6 digits and 30 seconds. Test unusual settings with the app your users actually have.
  • If codes are always one step out, the server or phone clock is drifting. Turn on automatic time on both rather than widening the server’s accepted window a lot.
  • Most servers accept the previous code as well as the current one, so a code typed just as the ring runs out usually still works.
  • Base32 secrets are often shown in groups of four with spaces. Paste them as they are: spaces, dashes and lower case are fine.

Frequently asked questions

Is my secret uploaded or saved?

No. The codes are calculated by your browser’s built-in cryptography on your device. Nothing you type is sent anywhere or stored, and it is gone when you close the tab. Even so, only use secrets from test accounts.

Can I use this instead of an authenticator app?

Please don’t. A website is the wrong place to keep the key to a real account, and a tab is easy to lose. Use a proper authenticator app or password manager for real accounts; this tool is for building and testing 2FA.

Is it free? Are there limits?

Yes, it is free, with no sign-up and no limits on how many secrets or codes you try.

Does it work on a phone or offline?

Yes. It works in Safari, Chrome and Firefox on phones and computers, and once loaded it needs no connection. Time-based codes rely on your device’s clock being correct.

Why doesn’t my code match the app?

Usually one setting differs (algorithm, digits or period), the secret was copied with a wrong character, or one of the clocks is out. Type the app’s code into “Check a code” to see if it matches a nearby time step.

What is the difference between TOTP and HOTP?

TOTP codes come from the current time, so they change every 30 or 60 seconds. HOTP codes come from a counter that goes up each time a code is used, so a code stays valid until the next one is used. TOTP is far more common.

Page last reviewed