Codes are generated in this browser and the secret is never saved: your files and inputs never leave your device.
No code yet
Paste a Base32 secret or an otpauth:// URI to start generating codes.
Related tools
- HMAC GeneratorCompute and verify HMAC digests for a message and a secret key, in your browser.
- Bcrypt & Argon2 HasherHash and verify passwords with bcrypt, argon2, and scrypt, entirely in your browser.
- Password Strength CheckerScore a password's real entropy and crack time, with plain English reasons, on your device.
- Password GeneratorGenerate random passwords or EFF diceware passphrases in your browser, each one reported with its exact entropy in bits and a crack-time estimate.
- Text EncrypterEncrypt and decrypt text with a passphrase using AES-256-GCM, entirely on your device.
- JWT Vulnerability CheckDecode a JWT and test it for alg=none and weak HMAC signing secrets, entirely in your browser.
What it does
Turns a two-factor secret into the six digit code your provider is expecting right now. Paste the Base32 secret, or the whole otpauth:// URI hidden behind a setup QR code, and you get the current code, the seconds left before it rolls over, and the codes on either side of it. It implements RFC 6238 (TOTP) on top of RFC 4226 (HOTP), so SHA1, SHA256, and SHA512 secrets at 6, 7, or 8 digits all work, along with counter based HOTP URIs. Everything runs in your browser with no account and no rate limit.
How to use it
Paste the secret your provider showed you when you enabled 2FA, or the full otpauth:// URI decoded from its QR code. An otpauth URI carries its own algorithm, digit count, and period, so those are read from the URI and the dropdowns are ignored. For a bare secret, set the algorithm, digits, and period yourself; the defaults (SHA1, 6 digits, 30 seconds) are what almost every provider uses. The time override exists for debugging: leave it at 0 for live codes, or set a unix timestamp to reproduce the code from a specific moment.
Why this one
The obvious way to check a TOTP secret is to paste it into one of the many online 2FA generators, which means handing a long lived credential to a server you know nothing about. Here the secret is decoded and hashed in your browser, and your files and inputs never leave your device. There are no ads, no signup wall, and no daily limit on how many codes you can generate while you debug an integration.
FAQ
- Is it safe to paste my secret here?
- The secret stays in your browser and is never uploaded, which is a real improvement over the server side generators. It is still a permanent credential, so treat this as a tool for test secrets, integration debugging, and one off recovery. For an account you care about, keep the secret in a dedicated authenticator app or password manager instead of a web page.
- Can I paste the otpauth:// URI from a setup QR code?
- Yes. Paste the whole otpauth://totp/... or otpauth://hotp/... string and the account name, issuer, algorithm, digit count, period, and HOTP counter are all read from it. Those values override the dropdowns, because a URI already describes itself completely.
- Does it support SHA256 and SHA512?
- Yes, along with 7 and 8 digit codes and non standard periods. The RFC 6238 Appendix B test vectors for all three hash functions are covered by the test suite. If your codes do not match, check the algorithm first: nearly every provider uses SHA1 even though the spec allows more.
Keyboard shortcuts: press ? anywhere on this page to see them.