DevToolPal
EN

TOTP / HOTP Code Generator

Generate two-factor authentication codes (TOTP and HOTP) from a Base32 secret or otpauth:// URI, with SHA-1/256/512, 6–8 digits and a live countdown.

Runs locally, never uploaded

Options

Type
Digits
Time step

Secret (Base32) or otpauth:// URI

Codes

Result appears here

What it does

Two-factor authentication apps such as Google Authenticator, Microsoft Authenticator and 1Password show six-digit codes that change every 30 seconds. Each code is a one-time password computed from a shared secret: TOTP (RFC 6238) uses the time, and HOTP (RFC 4226) uses a counter. This tool computes the same codes from the secret, so you can test a 2FA setup, debug a server implementation or check what a code should be.

It shows the current code with a live countdown, plus the previous and next codes, which servers often accept to cover small clock differences.

How to use

  1. Paste the Base32 secret (letters A–Z and digits 2–7; spaces and case do not matter), or paste a whole otpauth:// URI from a QR code. Click Sample to try it.
  2. Choose TOTP or HOTP, and set the algorithm, digits and time step to match the account. Settings inside an otpauth URI take priority.
  3. For HOTP, enter the counter and use Counter +1 to step through codes.
  4. Copy the current code. The countdown shows how long it stays valid.

Example

The demo secret JBSWY3DPEHPK3PXP is the Base32 form of the bytes “Hello!” followed by 0xDEADBEEF. The URI below, as encoded in a QR code, describes an account that uses it with the default settings:

otpauth://totp/Example:alice@example.com?secret=JBSWY3DPEHPK3PXP&issuer=Example&algorithm=SHA1&digits=6&period=30

At Unix time 1700000000 this secret gives the code 324 550, and the window has 10 seconds left.

How the code is calculated

The secret is decoded from Base32 to bytes. For TOTP, the counter is the Unix time in seconds divided by the time step and rounded down. The counter is written as 8 bytes and signed with HMAC using the secret. Dynamic truncation picks 4 bytes from the HMAC output based on its last nibble, and the number is reduced to the requested number of digits, with leading zeros kept.

FAQ

› Why does my code not match the one in my authenticator app?

TOTP codes depend on the clock, so first check that your device time is set automatically. Then check that the algorithm, digits and time step match the account. Most services use SHA-1, 6 digits and 30 seconds, and authenticator apps ignore other settings unless the QR code says so.

› What is the difference between TOTP and HOTP?

TOTP (RFC 6238) uses the current time divided by the time step as the counter, so the code changes every 30 seconds. HOTP (RFC 4226) uses a counter that goes up by one each time a code is used. Both run the secret and the counter through HMAC and keep the last 6 to 8 digits.

› Is my secret stored or sent anywhere?

No. Codes are calculated in your browser with the Web Crypto API. The secret is not saved, not written to the address bar and not included in share links; a shared link only carries the settings. Still, a 2FA secret gives full access to the second factor, so only paste secrets you own.

› Can I use this to set up two-factor authentication for my own app?

Yes. Click Random secret to create a 160-bit Base32 secret, put it in an otpauth:// URI or QR code for your users, and compare the codes your server produces with the ones shown here. Servers usually also accept the previous and next code to allow for clock drift.