TOTP Code Generator & Validator — Free
Runs 100% in your browser — your files never leave your device.
Testing authenticator setup usually requires a live time-based code, the underlying counter, and a valid otpauth URI. Enter or generate a base32 secret to see adjacent six-digit TOTP windows, verify a token with clock tolerance, inspect the hexadecimal secret and counter, and scan a locally rendered QR code.
How it works
- 1
Enter or generate a base32 secret
- 2
Read the live TOTP windows
- 3
Verify a code or scan the QR
About this tool
How the codes are computed
The tool computes time-based one-time passwords (TOTP) the same way authenticator apps do: your shared secret combines with the current 30-second time window through HMAC, producing the six-digit code. The computation runs entirely in your browser — the secret never leaves the device.
Why on-device matters
The shared secret IS your second factor. Pasting it into a web service that stores or transmits it hands over everything needed to generate your codes forever. Here the secret stays local: paste, generate, close the tab, and the secret exists nowhere but your machine.
Codes expire by design
Each code is valid for one 30-second window; the tool shows the countdown so you know when it rolls. If a code is rejected, the usual cause is clock drift between your device and the server — regenerate close to the deadline rather than early.
Frequently asked questions
Where do I get the shared secret?
From the service you are setting up two-factor authentication for — it displays as a base32 string in the setup QR code or an alternative "enter manually" view.
Are the generated codes stored anywhere?
No — codes are computed in memory from your secret and the current time, and nothing persists after the page closes.
Why is my code rejected even though it looks right?
Clock drift — TOTP depends on both sides agreeing on the time within the window. Sync your device clock, or try the code immediately after it rolls over.