TOTP Generator - Two-Factor Codes & otpauth QR Code (RFC 6238)
TOTP Generator
Generate two-factor codes from a secret and make a QR code for your authenticator app
Live Codes
See the current code with a countdown to the next one, and the next code in advance.
QR Code for Your App
Turns any secret into an otpauth:// link and QR code you can scan with an authenticator app.
Digits, Period and Algorithm
6, 7 or 8 digits, any period and SHA-1, SHA-256 or SHA-512, to match the service you are testing.
Full Privacy
The secret is used only in your browser and is never sent anywhere. Even so, do not paste secrets for accounts you care about into any web page.
How Time-Based Codes Work
A TOTP code is derived from a shared secret and the current time. The time is divided into steps, usually 30 seconds long; the step number is fed, with the secret, into an HMAC, and the result is cut down to 6 digits. Your phone and the server both know the secret and the time, so they arrive at the same code without talking to each other, and the code changes every step.
If codes do not match a server's, the usual cause is a clock that is off by more than a step, so check the device time. The tool follows RFC 6238 and matches its published test vectors. Secrets are written in Base32; most apps expect SHA-1, 6 digits and 30 seconds, and ignore other settings in the QR code, so keep those defaults for apps like Google Authenticator.
Key Takeaways
- Standard: RFC 6238 (TOTP) on RFC 4226 (HOTP), checked against the published vectors.
- Random secrets: The Random button makes a 160-bit secret with your browser's secure random generator.
- Related tools: See also the HMAC Generator and the Password Generator.