Free online tools to generate, calculate,
convert, format, encode, and play.
 

2FA Code Generator

Generate time-based one-time passwords (TOTP) from a secret key. Codes refresh every 30 seconds, matching apps like Google Authenticator. Everything runs locally in your browser.


Enter the Base32-encoded secret from your service provider. Spaces and dashes are ignored.
Enter a secret key and click Generate
Time remaining: -- Period: --
Options
Recent Codes
Details
Current Code --
Time Step --
Unix Time --
Algorithm --
Digits --
Tips
  • Keep your secret key private and secure
  • Most services use 6-digit, 30-second, SHA-1 codes
  • Ensure your device clock is accurate for correct codes
  • Store backup codes in case you lose access
  • Use a password manager to store 2FA secrets

How It Works

TOTP (Time-Based One-Time Password) is defined in RFC 6238 and is the standard behind apps like Google Authenticator, Authy, and Microsoft Authenticator. It generates short-lived codes from a shared secret and the current time.

The TOTP Algorithm

1
Time Counter

Divide current Unix time by the period (default 30s) to get a counter value.

2
HMAC

Compute HMAC-SHA1 (or SHA-256/512) of the counter using the shared secret as key.

3
Truncation

Extract a 4-byte dynamic binary code from the HMAC output using dynamic truncation.

4
Code

Convert to a decimal number and take the last 6 (or 8) digits as the OTP.

T = floor(unix_time / period)
HMAC = HMAC-SHA1(secret, T)
offset = HMAC[19] & 0x0F
code = (HMAC[offset..offset+3] & 0x7FFFFFFF) mod 10^digits

Base32 Encoding

Secrets are encoded in Base32 (A-Z, 2-7) as defined in RFC 4648. This encoding is case-insensitive and avoids confusing characters, making it suitable for manual entry. Spaces and dashes in the input are stripped before decoding.

Security Considerations

  • Shared secret: The Base32 key is a symmetric secret. Anyone with it can generate valid codes. Keep it confidential.
  • Time sync: TOTP relies on clock accuracy. A drift of more than one period will produce invalid codes.
  • Window tolerance: Most servers accept codes from the previous and next time step to account for minor clock skew.
  • Client-side only: This tool uses the Web Crypto API. No data is transmitted, and secrets never leave your browser.

Common Parameters

Parameter Default Description
AlgorithmSHA-1HMAC hash function (SHA-1, SHA-256, SHA-512)
Digits6Length of the generated code (6 or 8)
Period30sTime step in seconds before a new code is generated
Secret-Base32-encoded shared secret key

Embed This Util

You can embed this util on your own site as a widget. Adding ?embed=1 to the URL loads a compact version with just the tool itself; no header, menu, or documentation. Paste this snippet into your HTML:


    

Copy snippet Adjust the height to taste.



Feedback

Help us improve this page by providing feedback, and include your name/email if you want us to reach back. Thank you in advance.


Share with