TOTP Code Generator
Check that the two-factor secret you saved really produces the code on your phone — before the phone is gone.
Runs entirely in your browser
Loading tool...
How to use
- Paste the Base32 secret, or the whole otpauth:// URI from the QR code.
- Compare the code with the one your authenticator app is showing.
- If they match, your saved backup is good. If not, set the account up again.
- Change algorithm, digits or period only if the issuer specifies something unusual.
Features
- RFC 6238, verified against the standard's published test vectors.
- SHA-1, SHA-256 and SHA-512, with six or eight digits.
- Reads an otpauth:// URI and fills in every field.
- Shows how long the current code has left.
- Runs entirely in your browser — the secret is never sent anywhere.
Frequently asked questions
- Should I really paste a two-factor secret into a website?
- Think about it before you do. Nothing is uploaded — the code is computed in the page and there is no server — but a secret pasted anywhere is a secret that has left its safe place, and a browser extension can read this page like any other. The case where it is worth it is the one this tool is for: checking a backup you have just written down, once, before you rely on it.
- The code does not match my phone. What is wrong?
- Usually the clock. TOTP is a function of the current time, so a device whose clock is off by more than a period shows a different code — check that both are synchronised. Otherwise it is a setting: some issuers use eight digits, a sixty-second period, or SHA-256. All three are adjustable above.
- Does this replace my authenticator app?
- No, and it should not. An authenticator keeps the secret in device storage the browser cannot read, which is the whole security argument for the second factor. This is a verification tool: paste, compare, close the tab.
Related tools
The encoding two-factor secrets are printed in — forgiving of the spaces and mistyped characters that come with copying one by hand.
Sign a message with a secret key, or check a webhook signature you were sent.
Create a QR code for a link, text or WiFi network.