TOTP Emulator

Generate 6-digit TOTP codes from a Base32 secret, or scan a 2FA setup code with your camera or a screenshot, like an authenticator app in the browser. Supports custom period, digits and SHA-1/SHA-256/SHA-512, and builds the otpauth URI. Handy for testing two-factor login during development.

About this tool

What is TOTP?

TOTP (Time-based One-Time Password, RFC 6238) is the algorithm behind most authenticator apps used for two-factor authentication (2FA). The service and your device share a secret key; both compute an HMAC of the secret and the current 30-second time step, and turn the result into a short numeric code. Because the code changes every period, a stolen code is only useful for a few seconds. This tool calculates the same codes in your browser, so you can test a 2FA implementation or check what code a secret should produce without setting up a phone app.

How to use

  1. Get the secret in one of these ways:
    • Camera: click Use camera, then Start with the camera you want, and show the 2FA setup QR code. The camera stops after a successful scan.
    • File: switch to File and drop (or click to choose) a screenshot of the QR code.
    • Type the secret into Secret (Base32), for example JBSWY3DPEHPK3PXP.
  2. The current code is shown in large digits with a bar and the seconds remaining. Click the code to copy it.
  3. Use the eye icon to show or hide the settings.

Features

  • Reads otpauth://totp/... URIs from QR codes and fills in secret, label, issuer, algorithm, digits and period automatically
  • Period (seconds): any positive integer (default 30)
  • Digits: 1 to 10 (default 6)
  • Algorithm: SHA1 (default), SHA256 or SHA512
  • Base32 secrets are case-insensitive; spaces, hyphens and trailing = are ignored
  • Constructed otpauth URI shows the URI for the current settings, and Actual otpauth URI from QR code shows exactly what was scanned, so you can compare them
  • The code is computed with the browser's Web Crypto API and refreshes automatically at each time step

The otpauth URI

2FA setup QR codes contain a URI such as: otpauth://totp/Example:alice@example.com?secret=JBSWY3DPEHPK3PXP&issuer=Example&algorithm=SHA1&digits=6&period=30

secret is the Base32 key, issuer and the label identify the account, and algorithm, digits and period default to SHA1, 6 and 30 when omitted.

FAQ

Is my secret sent anywhere?

No. QR decoding and code generation happen in your browser, and the camera image is not uploaded. The secret and settings are saved in this browser's storage so the code is available next time, so treat this page like an authenticator on a shared computer and clear the secret when you are done.

Can I use this instead of my authenticator app?

It is meant for development and testing, and it holds a single secret at a time. For your real accounts, use a dedicated authenticator app or password manager with backups.

Why does the code not match the server?

TOTP depends on the clock. Check that your device's time is correct, and that the period, digits and algorithm match the server's settings.

Are HOTP (counter-based) codes supported?

No. Only otpauth://totp is supported; otpauth://hotp QR codes are rejected with an error.