Generate 6-digit TOTP codes from a Base32 secret, or scan a 2FA setup code with your camera or a screenshot, like an authenticator app in the browser. Supports custom period, digits and SHA-1/SHA-256/SHA-512, and builds the otpauth URI. Handy for testing two-factor login during development.
TOTP (Time-based One-Time Password, RFC 6238) is the algorithm behind most authenticator apps used for two-factor authentication (2FA). The service and your device share a secret key; both compute an HMAC of the secret and the current 30-second time step, and turn the result into a short numeric code. Because the code changes every period, a stolen code is only useful for a few seconds. This tool calculates the same codes in your browser, so you can test a 2FA implementation or check what code a secret should produce without setting up a phone app.
JBSWY3DPEHPK3PXP.otpauth://totp/... URIs from QR codes and fills in secret, label, issuer, algorithm, digits and period automatically= are ignored2FA setup QR codes contain a URI such as:
otpauth://totp/Example:alice@example.com?secret=JBSWY3DPEHPK3PXP&issuer=Example&algorithm=SHA1&digits=6&period=30
secret is the Base32 key, issuer and the label identify the account, and algorithm, digits and period default to SHA1, 6 and 30 when omitted.
No. QR decoding and code generation happen in your browser, and the camera image is not uploaded. The secret and settings are saved in this browser's storage so the code is available next time, so treat this page like an authenticator on a shared computer and clear the secret when you are done.
It is meant for development and testing, and it holds a single secret at a time. For your real accounts, use a dedicated authenticator app or password manager with backups.
TOTP depends on the clock. Check that your device's time is correct, and that the period, digits and algorithm match the server's settings.
No. Only otpauth://totp is supported; otpauth://hotp QR codes are rejected with an error.