TOTP Generator and Verifier

Generate time-based authentication codes, create authenticator provisioning URIs, and verify TOTP codes locally.

Browser only2FA & MFAWeb Crypto

Time-based one-time password

Generate and verify RFC-style TOTP authentication codes locally.

TOTP settings

Current authentication code

Enter or generate a secret

The current authentication code and expiration countdown will appear here.

Provisioning URI

Enter a valid secret and account name to create an authenticator-compatible provisioning URI.

Verify authentication code

Multi-factor authentication

Generate short-lived authentication codes from a shared secret

TOTP is commonly used as an additional authentication factor, but the shared secret must remain protected because it can be used to reproduce valid codes.

Protect the shared secret

Treat the Base32 secret and provisioning URI like a password. Anyone who obtains either value can generate valid authentication codes.

Keep system clocks synchronized

TOTP depends on time. Significant clock differences between the authenticator and server can cause otherwise correct codes to fail verification.

Guide

About TOTP Generator and Verifier

TOTP generates short-lived authentication codes from a shared secret and the current time.

This tool creates and verifies codes and can produce authenticator provisioning information.

The Base32 secret and provisioning URI must be protected because either can reproduce valid codes.

How TOTP works

TOTP derives a moving counter from time and computes an HMAC-based one-time password.

Configurable parameters

Common settings include algorithm, number of digits, time period, issuer, and account label.

Clock synchronization

Authenticator and server clocks must be reasonably aligned, with only limited verification windows.

Secret protection

Treat the Base32 secret like a password and avoid exposing QR codes or otpauth URIs.

FAQ

Frequently asked questions

What is TOTP?

TOTP is a time-based one-time password algorithm commonly used for MFA.

Why do codes change every 30 seconds?

Thirty seconds is the common time step, though it can be configured.

What is a Base32 secret?

It is a text encoding of the shared secret used to calculate codes.

What is an otpauth URI?

It is a provisioning URI understood by many authenticator applications.

Why does verification fail?

The secret, time, algorithm, digit count, period, or clock synchronization may differ.

Is the secret uploaded?

Generation and verification are intended to run locally in your browser.

Continue exploring

Useful tools for the next step in the same workflow.