TOTP 2FA Codes
Generate 2FA codes from secret keys.
Scan into an authenticator app
Next code in –s · counter
About TOTP 2FA Codes
Time-based one-time passwords are the numbers that refresh every thirty seconds inside authenticator apps. Under the hood they are a simple calculation: an HMAC of the current time counter using a shared secret, folded down to a short number. This generator runs that calculation in your browser from any base32 secret, such as the one a service shows you when setting up two-factor authentication. Paste the secret and the current code appears instantly, updates every second, and turns red in the final seconds of its window. The same secret also produces a QR code in the otpauth format, so you can move it into Google Authenticator, Aegis, or any standard app by scanning once. Support covers six and eight digit codes, thirty and sixty second periods, and the SHA-1, SHA-256, and SHA-512 algorithms.
How to Use TOTP 2FA Codes
Paste the base32 secret
Copy the secret text the service showed when you enabled two-factor authentication. It is a string of letters A to Z and digits 2 to 7, usually presented in groups of four.
Match the settings
Leave digits, period, and algorithm at their defaults unless the service said otherwise. Nearly every site uses six digits, thirty seconds, and SHA-1.
Read the current code
The large number at the top is your current code, refreshed every second. It shows how long remains before it expires, and the counter below it is the internal time step.
Move it to an app if you prefer
Scan the QR code with any authenticator app, or copy the otpauth URL below it into an app that accepts manual URI entry. After that the app produces the same codes independently.
Why Use TOTP 2FA Codes: Common Use Cases
Recovering access without your phone
If you stored the original secret when setting up 2FA, this page regenerates valid codes on any computer, so a dead phone battery does not lock you out.
Enrolling a second device
Scan the QR built from your existing secret into a backup authenticator, and both devices produce identical codes from that moment on.
Checking whether a code is still valid
The countdown shows exactly how many seconds remain. If a code keeps getting rejected on a site, it is usually because the window expired mid-typing.
Testing 2FA implementations
Developers building TOTP support can enter a known secret and compare generated codes against their own implementation to confirm both sides agree.
TOTP 2FA Codes Specifications
| Input Formats | Base32 secret, Digits (6 or 8), Period (30s or 60s), Algorithm (SHA-1, SHA-256, SHA-512) |
|---|---|
| Output Formats | Current TOTP code, otpauth:// URL, QR code |
| File Size Limit | No strict limit (dependent on device memory) |
| Processing Engine | 100% Client-side (Runs locally in your browser) |
| Data Retention | Files never leave your device |
| Batch Processing | Single file processing |
Tips for TOTP 2FA Codes
Spaces and dashes in a pasted secret are ignored, so a secret copied in groups of four works without cleanup.
The code you generate is only correct if your device clock is accurate. Codes failing everywhere is the classic symptom of a drifting system clock.
Store the original secret, not just the app entry. The secret is the root credential; the app is just one way to calculate codes from it.
If you lose both the phone and the secret, recovery codes printed at setup time are your fallback. Keep them somewhere offline.
Each code is meant for one login. Services reject a code twice in a row even before it expires, so generate a fresh one rather than retrying the same digits.
Building the underlying hash math yourself? Hash Generator computes raw HMAC and message digests for comparison, and JWT Generator covers the token side of API auth.
Frequently Asked Questions
Is it safe to paste my 2FA secret here?
The secret never leaves your browser. The HMAC calculation runs locally with the Web Crypto API, and nothing is sent, logged, or stored. Still, treat the secret like a password: only paste it on a device you trust.
Why is SHA-1 used when SHA-256 exists?
SHA-1 in TOTP is not the broken SHA-1 used for certificates. The attacks that weakened SHA-1 do not apply to HMAC, which is why virtually every service still issues SHA-1 secrets. This tool supports the stronger options too, for services that offer them.
What is the counter shown under the code?
It is the number of time steps since the Unix epoch, calculated by dividing the current time by the period. Both your device and the server compute the same counter, which is how the codes stay in sync without any network traffic.
My code is rejected. What is wrong?
Three usual causes: your device clock is off by more than the allowed skew, the secret was pasted incompletely, or the code expired while you typed it. Check the clock first, then re-copy the secret carefully.
Can I generate codes for several accounts at once?
One secret at a time in this tool. Change the secret in the box to switch accounts, or better, move the QR into an authenticator app that holds all of them together.
Does the generated QR code contain my secret?
Yes. A QR built from an otpauth URL includes the secret in plain form, which is exactly how authenticator apps receive it. Only scan it on a device you control, and never post the image anywhere.