elefcode

TOTP / 2FA Code Generator

Generate time-based one-time passwords from a secret, the same way an authenticator app does.

Click the code to copyExpires in 30s
Import an otpauth:// URI
Setup URI for this secret
otpauth://totp/account?secret=JBSWY3DPEHPK3PXP&algorithm=SHA1&digits=6&period=30

Paste this into the QR code generator to produce a scannable 2FA setup code.

This is a testing and recovery tool, not a password manager. Codes are computed in your browser and the secret is never sent anywhere — but a 2FA secret kept in the same place as your password defeats the point of two-factor authentication. Use a real authenticator app for accounts you care about.

Advertisement

Guide

About the TOTP / 2FA Code Generator

A TOTP is the six-digit code an authenticator app shows and replaces every thirty seconds. It is not random — it is a hash of a shared secret and the current time, which is how your phone and the server arrive at the same number without ever talking to each other.

This tool implements that calculation in the browser, which makes it useful for testing a 2FA integration you are building, checking that a secret was transcribed correctly, or seeing exactly what a server should expect.

How a TOTP is calculated

Take the Unix time in seconds, divide by the period (normally 30) and throw away the remainder — that is the counter. Compute an HMAC of that counter using the shared secret as the key. Then apply dynamic truncation: the low four bits of the final byte choose an offset, four bytes are read from there, and the result modulo 10digits gives the code. That is RFC 6238 built on RFC 4226, and this implementation is verified against the test vectors published in both.

Why codes sometimes do not match

Almost always a clock problem. Because the counter comes from the current time, a device whose clock has drifted by more than a period will compute a different code. Servers normally accept the codes either side of the current window to absorb a little drift. The other common causes are the wrong algorithm (SHA-1 is the default and what most services use, even though SHA-256 is available) or a secret that was mistyped — base32 has no 0, 1 or 8.

The otpauth:// URI

When a site shows you a 2FA QR code, the thing encoded in it is an otpauth://totp/ URI carrying the secret, issuer, account name, algorithm, digit count and period. You can paste one here to load all its settings at once, or build the URI from your own settings and pass it to a QR generator to produce a scannable setup code.

When to use this and when not to

It is a developer tool. Use it to test an implementation, verify a secret, or recover access while migrating between authenticator apps. Do not use it as your everyday second factor: the whole value of 2FA comes from the second factor living somewhere separate from your password, and a secret pasted into a browser alongside your password manager is no longer a second factor in any meaningful sense.

How to use it

  1. 1Paste your base32 secret, or import an otpauth:// URI to fill in every setting at once.
  2. 2Match the algorithm, digits and period to what the service expects — SHA-1, 6 digits, 30 seconds is the usual default.
  3. 3Read the current code and the countdown showing when it rolls over.
  4. 4Click the code to copy it.

Frequently asked questions

Is my 2FA secret sent to a server?

No. The code is computed in your browser with the Web Crypto API. The secret never leaves the page and nothing is stored.

Why does my code not match the server?

Usually clock drift — TOTP depends on the current time, so a device more than one period out of sync produces a different code. Check the algorithm and digit count too.

What does the countdown mean?

It is the seconds left in the current time window. When it reaches zero the counter increments and a new code is generated.

Which algorithm should I choose?

SHA-1 with 6 digits over 30 seconds, unless a service tells you otherwise. Despite SHA-1 being weak for other purposes, HMAC-SHA1 remains sound here and is what almost every service uses.

Can I use this instead of an authenticator app?

For testing, yes. For real accounts, no — storing a 2FA secret in the same place as your password removes the separation that makes two-factor authentication worth having.

Related tools