TOTP / HOTP 2FA Generator
CryptoGenerate time-based (TOTP) or counter-based (HOTP) one-time passwords from a Base32 secret or an otpauth:// URI. Live countdown and a scannable QR code — all locally in your browser.
Remote URLs are not fetched; paste your JSON directly.
Scan with Google Authenticator, Authy, 1Password or any TOTP app.
On this page
What is a TOTP?#
A time-based one-time password (TOTP) is the rotating 6-digit code your authenticator app shows next to each account. Underneath, it is an HMAC: the shared secret and the current time window are hashed together, and the result is truncated to a short numeric code. Because the code depends on the clock, it rolls over on its own every 30 seconds — which is what makes “something you have” (the secret) usable as a second factor without any network round-trip between your phone and the service.
This page is a fully working TOTP and HOTP generator. TOTP derives the code from the current time and refreshes itself as the period elapses; HOTP derives it from a counter that advances on each use. You can type a Base32 secret directly, or paste an otpauth:// URI (the string encoded in the QR codes services show you when enabling 2FA) and have every field filled in automatically. The page also emits the canonical otpauth:// URI and renders a scannable QR code, so you can provision a new account into a phone app straight from here.
Everything runs locally: the secret never leaves the page, and there is no online call to any authentication service.
How to use it#
- Pick a mode: TOTP (time-based, refreshes itself) or HOTP (counter-based, advances manually).
- Provide the secret. Either paste the Base32 secret into the secret field, or paste an
otpauth://URI into the URI field to auto-fill every parameter at once. - Set the issuer and account label (these only affect how the entry is named in an authenticator app, not the code itself).
- Choose algorithm (SHA-1 / SHA-256 / SHA-512 — SHA-1 is the universal default), digits (6 / 7 / 8 — 6 is standard), and — for TOTP — the period in seconds (default 30). For HOTP, set the counter and click +1 to advance it after each use.
- Click Generate. The code appears large with a countdown ring showing seconds left in the current period; below it, the
otpauth://URI and a scannable QR code.
Key features#
- TOTP and HOTP in one place. Switch between the time-based and counter-based variants without re-entering the secret.
- Tolerant Base32 handling. Spaces, hyphens, lowercase, and stray characters are cleaned up automatically, so secrets copied from awkward formats still work.
- URI import and export. Paste an
otpauth://URI to populate every field, or copy the generated URI to provision a new account elsewhere. - Live QR code. Rendered in-page from the URI, ready to scan into any authenticator app.
- Countdown ring. A visual countdown to the next rollover, so you know whether the code you are about to type has enough time left.
- Zero upload. Generation, parsing, and QR rendering are all local; the secret is never transmitted.
Worked example#
The RFC 6238 reference seed is the ASCII string 12345678901234567890, which in Base32 is GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ. Type that secret, set digits 8 and period 30, and the codes match the published test vectors exactly:
- SHA-1 at time = 59 seconds into the epoch →
94287082 - SHA-256 at the same instant →
46119246 - SHA-512 at the same instant →
90693936
At time = 1111111109 (a date far in the future), SHA-1 produces 07081804. These are the same known-answer values this tool’s own test suite checks against, so they are a reliable way to confirm a generator is correct. For everyday 2FA, services use 6 digits, SHA-1, and a 30-second period — switch digits back to 6 and the same secret produces the rotating code an authenticator app would show.
FAQ#
My code does not match my phone app. What is wrong?#
Almost always the secret or the clock. First confirm the Base32 secret is identical — copy it again from the service’s setup page, since a single wrong character changes everything. Then check the parameters: most services use SHA-1, 6 digits, 30-second period; if the service uses SHA-256 or 8 digits and you have SHA-1 / 6 selected, the codes will differ. Finally, make sure your device clock is correct — TOTP tolerates a little skew, but more than about 30 seconds off will break it.
What is the difference between TOTP and HOTP?#
TOTP uses the current time as the moving factor, so it advances automatically every period. HOTP uses a simple counter that increments each time a code is consumed, so both sides must stay in sync about how many codes have been used. TOTP is what almost every consumer 2FA flow uses today, because it needs no synchronisation beyond the clock.
Is it safe to put my secret into a web page?#
The secret never leaves this page — generation, parsing, and QR rendering all run locally in your browser, with no network call. That said, for a production 2FA secret you control, the safest practice is to generate and store it in an environment you fully trust rather than any web page, and to keep the recovery codes the service gave you.
Why does pasting my otpauth:// URI fill in everything?#
That URI is the standard format authenticator apps exchange: it encodes the type, issuer, account, secret, algorithm, digits, and period (or counter) in one string. The parser reads those fields out and populates the form, which is exactly what happens when you scan a QR code with your phone — the QR is just that URI rendered as an image.