TOTP code generator
Generate time-based one-time codes from a secret, locally.
Runs in this tab. The file stays here.
For testing and backup only — not a replacement for your primary authenticator app. Your secret stays in this tab and is never sent anywhere.
—
Refreshes in 30s
This runs in your browser. Nothing is uploaded.
About TOTP code generator
Generate time-based one-time codes from a secret key, the same codes an authenticator app makes. The secret never leaves your browser.
Paste a base32 secret and the page shows the current code with a countdown to the next one, calculated with the standard TOTP method from RFC 6238. Period, digit count (6, 7, or 8), and hash algorithm (SHA-1, SHA-256, or SHA-512) are all editable, because a few services don't use the usual 6 digits, 30 seconds, and SHA-1. This is helpful for testing a 2FA setup, checking that a secret you saved really works, or getting in when your phone is out of reach.
Treat the secret like a password. It isn't stored or transmitted, and it isn't put in the URL, but anyone who can see your screen can read it, and a browser extension with page access could too. The page itself is a testing and backup tool, and shouldn't replace your primary authenticator app.
The code is only correct if your device's clock is. TOTP is a function of the current time, so a clock that's a minute off produces a code the server rejects, and the countdown here follows your system time, not the server's.
How to use TOTP code generator
- 1Paste the base32 secret.
- 2Check that the digits, period, and algorithm match the service, usually 6, 30s, and SHA-1.
- 3Copy the code before the timer runs out.
What it won't do
- Needs a base32 secret; it doesn't read QR codes or otpauth links.
- Period is capped at 300 seconds, digits at 6 to 8.
- Accurate only when your device clock is.
Common questions
Is it safe to paste my 2FA secret here?
The calculation is local and nothing is sent, but a secret in any browser tab carries some risk. Don't use it as your only copy, and for accounts where an authenticator app on a separate device is an option, use that.
Why doesn't my code match?
Usually the device clock is off by more than the 30-second window, or the service uses non-default digits or a different algorithm. Check your system time sync first, then the three settings.
Where do I find the secret?
It's the text key shown beside the QR code when you set up 2FA, sometimes labelled "manual entry" or "setup key". This page can't read QR codes; if you only have the QR, the QR scanner can show the text inside it, which is an otpauth link with the secret as a parameter.
Related tools
Why this one doesn't upload your file
There is no server to upload to. This page is a static file, and the work happens in your browser using the same graphics and WebAssembly code that renders every other site you visit. Your file is read from disk into memory, processed, and handed back as a download. Once the page has loaded you can disconnect from the network entirely and it keeps working. The longer explanation