Enter a valid secret to see the code.
Check a code the way a server would: the current one is accepted, plus up to 2 steps before or after, to tolerate clock drift.
How it works
TOTP (Time-based One-Time Password, RFC 6238) is the algorithm behind the six-digit codes in Google Authenticator, Microsoft Authenticator, Authy or 1Password. The service and your phone share a secret; every 30 seconds both compute an HMAC of the secret with the current time divided into steps, truncate it to six digits and compare the result. Since nobody transmits the code until you type it, it works even when the phone is offline.
HOTP (RFC 4226) is the underlying algorithm: instead of the time, it uses a counter that advances every time a code is requested. TOTP is HOTP with the counter replaced by the number of periods elapsed since 1970. The secret is written in Base32 and travels inside an otpauth:// URI that is shown as a QR code when you enable two-step verification.
The tool generates secrets with the browser's cryptographic random generator, computes the current, previous and next codes, builds the URI and its QR code, reads an existing URI and verifies a code with the same clock tolerance servers use. The secret never leaves your browser and is not included in the share link.
Examples
GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ · SHA1 · 8 · T = 59 s94287082RFC 6238 test vector. The secret is the ASCII text 12345678901234567890 encoded in Base32; at 59 seconds after the Unix epoch the step is 1 and the eight-digit code must be exactly this one.GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ · SHA1 · 8 · T = 1111111109 s07081804Another RFC 6238 vector, useful to check that your implementation does not drop leading zeros: the code is a fixed-length string of digits, not an integer.HOTP · GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ · contador 0755224First RFC 4226 vector with six digits. With the counter at 1, the code becomes 287082.otpauth://totp/Ejemplo:ana%40example.com?secret=JBSWY3DPEHPK3PXP&issuer=EjemploTOTP · SHA1 · 6 · 30 sThe Key URI format defined by Google Authenticator and adopted by the other apps. If algorithm, digits and period are missing, SHA1, 6 and 30 are assumed, so most QR codes only carry the secret and the issuer.Use cases
- Test your application's 2FA enrollment: generate a secret, scan the QR code with your phone and check that the server accepts the same code the app shows.
- Debug why a server rejects valid codes: seeing whether they match the previous or next step reveals clock drift.
- Validate your own TOTP or HOTP implementation against the RFC 6238 and 4226 test vectors.
- Read an otpauth:// URI exported from another app to check which algorithm, how many digits and which period the account uses.
- Load a test account whose Base32 secret you already have into a second app or a password manager.
Frequently asked questions
Why does the server reject a code that the app shows as valid?
It is almost always the clock. TOTP relies on the phone and the server agreeing on the time: with a 30-second difference they already compute different steps. That is why servers accept one or two steps on either side. If the code matches the previous or next step, sync the server time with NTP and turn on automatic time on the phone.
Is it safe to generate the secret for a real account here?
The secret is generated with crypto.getRandomValues and never leaves your browser, but in production it should be generated and stored by the server that will verify the codes. This tool is meant for testing and debugging. Treat any real secret like a password: whoever has it can generate your codes forever.
Should I use SHA-256, 8 digits or 60 seconds?
In theory they are stronger, but several apps, including some versions of Google Authenticator, ignore those parameters and always compute SHA-1 with 6 digits every 30 seconds, so the user sees codes the server rejects. SHA-1 is still secure as an HMAC. For compatibility, almost all services use the defaults.
How long should the secret be?
RFC 4226 requires at least 128 bits and recommends 160, which is 32 characters in Base32. Many services use 80 bits (16 characters) and apps accept them anyway. This tool generates 160 bits.
Does TOTP protect against phishing?
Not entirely. It is much better than SMS, which can be intercepted or stolen through a SIM swap, but a fake site can ask you for the code and use it on the real one within the same 30 seconds. FIDO2 security keys and passkeys are bound to the domain and resist that attack.
What happens if I lose my phone?
Without the secret there is no way to compute the codes. That is why services hand out recovery codes when you enable 2FA: keep them somewhere other than your phone. Some apps let you back up accounts encrypted to the cloud or export them as a QR code to move them to another device.