TOTP Code Generator
Paste a Base32 secret for live TOTP codes, with verification and a migration QR.
Two-factor login hides an awkward gap: reinstalling your phone, or logging into a 2FA-protected service from your laptop while the authenticator lives on the phone. The code is sitting inside the secret, and the secret is a Base32 string. This tool cuts through: paste the secret and the browser computes the current code per RFC 6238, refreshing every 30 seconds with a visible countdown.
The implementation is fully standard: HMAC-SHA-1/256/512, 6 or 8 digits, 30/60-second steps, RFC 4226 dynamic truncation — validated against every official test vector in RFC 6238 Appendix B. It also renders an otpauth:// migration QR that mainstream authenticator apps can scan, and offers a verify box: type the code your phone shows to confirm the secret and settings match.
How TOTP actually works
Server and device share a key K; both compute HOTP(K, floor(now/30)) — the 30-second window number feeds an HMAC, whose output is truncated to 6 digits. Clocks within one window agree on the code, which is also why "wrong phone time breaks 2FA": the counters disagree.
Why a browser tool can claim safety
TOTP's security boundary fits the browser perfectly: computation is pure-local (WebCrypto HMAC), the secret stays in memory and works offline. The exposure equals the authenticator app's — the secret itself. So this page deliberately offers no persistence: refresh clears everything, no copies remain.
Frequently asked questions
- Where do I get the secret?
- When enabling 2FA, sites show a QR plus a "can't scan?" text key — that string is the Base32 secret. Pasting an otpauth:// link works too; the secret parameter is read out of it.
- What is the verify box for?
- After migrating or rebuilding an authenticator, type the code your phone currently displays: a match confirms the secret, algorithm, step and digit count all agree with the server — catching a bad setup now instead of at next login.
- How does this relate to Google Authenticator?
- Same standard (RFC 6238). Google Authenticator is one app implementing it; this page is its web equivalent, and the otpauth:// QRs are interchangeable.