Security

TOTP Generator

Generate time-based one-time passwords from Base32 secrets or otpauth URIs without sending credentials outside your browser.

Local processing. Your data stays in this browser.

Advanced settings

These defaults apply to plain Base32 secrets. Values inside an otpauth URI take priority.

Secrets or otpauth URIs
A TOTP secret can unlock account codes. Only enter it on a device you trust.
Current codes0 valid
Generated codes appear here. Nothing is stored after you leave or reload this page.
Your secrets are processed locally and never leave your browser.

How to use it

  • Enter one Base32 secret or otpauth TOTP URI per line.
  • Review any line-specific errors, then generate the current codes.
  • Copy individual codes or a labeled list before the current period expires.

Example

Input
Naminc demo: JBSWY3DPEHPK3PXP
Output
Naminc demo | 6-digit code that changes every 30 seconds

How TOTP works

TOTP combines a shared secret with the current time window and signs that counter with HMAC. Both the authenticator and the service can independently calculate the same short-lived code.

TOTP and HOTP

TOTP advances with time, commonly every 30 seconds. HOTP advances with an event counter instead. This tool accepts TOTP entries only and rejects otpauth HOTP URIs.

Protect the shared secret

Anyone who obtains a TOTP secret can generate future codes. Use this tool only on a trusted device, avoid real credentials on shared computers, and clear the page when finished.

Common questions

Does this TOTP generator upload my secret?
No. Parsing and HMAC generation run locally with the browser Web Crypto API. Secrets are not stored after you leave or reload the page.
Is it compatible with authenticator apps?
It follows RFC 6238 and supports SHA-1, SHA-256, SHA-512, 6 or 8 digits, and custom periods supplied by compatible otpauth URIs.
Why does my code differ from my authenticator?
Check the device clock, secret, algorithm, digit count, and period. Even a small clock difference near a period boundary can briefly show a different code.
Can this tool verify that a 2FA code is accepted?
No. It calculates a code from the supplied secret and time. Only the service that owns the account can verify whether a code is accepted.