TOTP / HOTP Generator
Generate TOTP (Google Authenticator-style) and HOTP one-time passwords from a Base32 secret using the Web Crypto API, with a live expiry countdown. Secrets never leave the browser.
Generate a code from a demo secret
Load a well-known demo secret and generate a 6-digit TOTP code that refreshes every 30 seconds.
JBSWY3DPEHPK3PXP decodes to the ASCII string “Hello!” — it’s only a demonstration. Use your own authenticator’s secret for real codes.
FAQ
What is TOTP?
Time-based One-Time Password. It derives a short-lived code from your secret and the current time window (usually 30 seconds), so codes change constantly and can’t be reused.
How do I get the secret for an account?
When you enable two-factor authentication on a site it gives you a Base32 secret or an otpauth:// link. Paste either here. Never share this secret — whoever has it can generate your codes.
Is it safe to enter my real secret here?
Yes for the purpose of generating a code, because everything runs in your browser and nothing is sent anywhere. Still, treat the secret like a credential and clear the input when you’re done.
Why did my code fail to authenticate?
If you wait until the counter shows 0 the next code is already active. Also make sure your device clock is accurate — TOTP depends on the current time.