TOTP Generator and Verifier
Generate time-based authentication codes, create authenticator provisioning URIs, and verify TOTP codes locally.
Time-based one-time password
Generate and verify RFC-style TOTP authentication codes locally.
TOTP settings
Current authentication code
Enter or generate a secret
The current authentication code and expiration countdown will appear here.
Provisioning URI
Enter a valid secret and account name to create an authenticator-compatible provisioning URI.
Verify authentication code
Multi-factor authentication
Generate short-lived authentication codes from a shared secret
TOTP is commonly used as an additional authentication factor, but the shared secret must remain protected because it can be used to reproduce valid codes.
Protect the shared secret
Treat the Base32 secret and provisioning URI like a password. Anyone who obtains either value can generate valid authentication codes.
Keep system clocks synchronized
TOTP depends on time. Significant clock differences between the authenticator and server can cause otherwise correct codes to fail verification.
Guide
About TOTP Generator and Verifier
TOTP generates short-lived authentication codes from a shared secret and the current time.
This tool creates and verifies codes and can produce authenticator provisioning information.
The Base32 secret and provisioning URI must be protected because either can reproduce valid codes.
How TOTP works
TOTP derives a moving counter from time and computes an HMAC-based one-time password.
Configurable parameters
Common settings include algorithm, number of digits, time period, issuer, and account label.
Clock synchronization
Authenticator and server clocks must be reasonably aligned, with only limited verification windows.
Secret protection
Treat the Base32 secret like a password and avoid exposing QR codes or otpauth URIs.
FAQ
Frequently asked questions
What is TOTP?
TOTP is a time-based one-time password algorithm commonly used for MFA.
Why do codes change every 30 seconds?
Thirty seconds is the common time step, though it can be configured.
What is a Base32 secret?
It is a text encoding of the shared secret used to calculate codes.
What is an otpauth URI?
It is a provisioning URI understood by many authenticator applications.
Why does verification fail?
The secret, time, algorithm, digit count, period, or clock synchronization may differ.
Is the secret uploaded?
Generation and verification are intended to run locally in your browser.
Continue exploring
Related tools
Useful tools for the next step in the same workflow.
Secure Password Generator
Generate strong random passwords locally in your browser.
Authentication
HMAC Generator
Generate and verify keyed message authentication codes.
Cryptography
AES Encrypt / Decrypt
Encrypt and decrypt text with password-based AES-256-GCM.
Cryptography
Unix Timestamp Converter
Convert Unix timestamps and readable date values locally.
Encoding & Data
JWT Decoder
Decode JWT headers and claims locally without uploading the token.
Authentication
JWT Signature Verifier
Verify HMAC JWT signatures and important claims locally.
Authentication