Developer / Authentication
TOTP Code Generator (Authenticator Test)
Generate time-based one-time passwords (TOTP) from a Base32 secret, with the time left, the next code, SHA-1/256/512, 6–8 digits, and a QR code for authenticator apps, to test two-factor sign-in.
TOTP Code Generator (Authenticator Test): A TOTP code is an HMAC of the number of 30-second periods since 1 January 1970, cut down to 6 digits, as RFC 6238 defines; authenticator apps and servers compute the same code from a shared secret and the current time. The QR code holds an otpauth:// address in the format authenticator apps read. The calculation is checked against the RFC's own test values. Runs 100% locally in your browser with zero server file uploads.
- Category
- Developer tools
- Runs
- In your browser
- Cost
- Free · no sign-up
- Availability
- Ready to use
Runs entirely in your browser
For testing your own app or server. Do not paste the secret of a real account here or anywhere online: anyone with it can make your codes.
QR code for an authenticator app
Scan it before you print it.
Point your phone's camera at the code on screen and check that it offers the right action.
What the code contains
otpauth://totp/Example%3Aalice%40example.com?secret=JBSWY3DPEHPK3PXP&issuer=Example&algorithm=SHA1&digits=6&period=30
Codes follow RFC 6238, the standard Google Authenticator, Microsoft Authenticator, and others use: an HMAC of the number of periods since 1970, truncated to the chosen digits. Your device clock must be right to the second.
Implementing TOTP on a server
Store the secret encrypted, accept the code for the current period and one period either side to allow for clock drift, and remember the last accepted period so the same code cannot be used twice. Rate-limit attempts, since six digits have only a million combinations.
To test the OAuth side of a sign-in flow, use the PKCE generator.
Recovery codes
Give users one-time recovery codes when they enable two-factor sign-in, so losing a phone does not lock them out; store only hashes of the codes.
How to use it
- Enter a Base32 test secret, or create a random one.
- Read the current code and the seconds left; choose digits, period, and algorithm to match your server.
- Scan the QR code into an authenticator app to check both show the same code.
Privacy & limitations
The secret stays in your browser. Use test secrets only.
Related tools
Frequently asked questions
Why does my code not match the app's?
Check that the device's clock is right to within a few seconds, and that digits, period, and algorithm match; most apps assume 6 digits, 30 seconds, and SHA-1.
Is it safe to use this for my real accounts?
No: a two-factor secret is as sensitive as a password. This page is for developers testing their own sign-in, with secrets made for testing.
What is the difference between TOTP and HOTP?
HOTP (RFC 4226) counts uses; TOTP counts time, so codes expire on their own.
Free tool · runs in your browser · no account required