Runs entirely in your browser
2FA codes without an authenticator app
Not everyone wants to install an authenticator app. Paste your 2FA secret key — from Google, GitHub, AWS or any other service — and the six-digit code appears, rotating every 30 seconds. The calculation happens inside this tab using the Web Crypto API: no backend, no trackers, and your key never crosses the network.
- Standard
- RFC 6238
- Network requests
- 0
- Test vectors passing
- 28/28
Paste your key, get the code
The key stays in this tab's memory and disappears when you close the page.
How TOTP works
TOTP never sends a code anywhere. The server and your device each hold the same secret key, then compute the same number from that key plus the current time. Because both sides calculate it independently, there is nothing in transit to intercept.
-
1
A shared secret key
A base32 string, usually about 160 bits, handed to you once as a QR image or as text when you enable 2FA.
-
2
Time divided by the period
Seconds since 1 January 1970 divided by 30, rounded down. Both sides land on the same counter, which is why your clock has to be roughly correct.
-
3
HMAC, then truncated
Key and counter are combined with HMAC, and the result is truncated to the decimal digits you see — the procedure defined in RFC 4226.
How this differs from other online 2FA tools
Some online 2FA tools send your secret key to their server to be computed there — a few place it directly in the URL, which means the key also lands in server logs and browser history. A 2FA secret is not a one-time code: it stays valid for as long as 2FA is enabled, so anyone holding it can produce codes at will.
This page loads one JavaScript file and then stops talking. You do not have to take that on trust: open DevTools on the Network tab, use the tool, and the request count stays at zero. Or disconnect from the internet after the page loads — the codes keep coming. A tool that computes server-side stops working the moment the connection drops.
When a tool like this helps
This is for people who will not — or cannot — install an authenticator app. One thing still deserves saying plainly: an authenticator app keeps your key in encrypted device storage, whereas here you paste it in each time. That is a fair trade, and these are the four situations where it makes sense.
You do not want another app
A locked-down work phone, no storage left, or simply no appetite for one more app for a single rarely-used account. You keep the key yourself, in a password manager.
Signing in without your phone
Flat battery, phone left at home, or a device being reset — while you do have a copy of the secret key.
Testing a TOTP integration
When you are building 2FA into your own application and need to compare codes against an implementation that passes the official test vectors.
Working out why a code is refused
By changing the algorithm, digits and period you can find the combination a service actually uses — some run 8 digits or SHA-256.
Frequently asked questions
Is my secret key sent to a server?
No. Every calculation runs in your browser using the Web Crypto API. This site has no backend, loads no third-party scripts and installs no analytics. You can disconnect from the internet after the page loads and it keeps working.
I already have a secret key. How do I get the OTP?
Paste it into the field labelled Your 2FA secret key. The six-digit code appears immediately, with no button to press.
The key is what the service showed you when you turned 2FA on: base32 text
such as JBSWY3DPEHPK3PXP, often
printed in groups of four, usually next to the QR image behind a link like
“can't scan the QR?”. If you only have the QR image, scan it with
any app and paste the otpauth://
URI it gives you — the same field accepts it.
What is TOTP, and how is it different from SMS 2FA?
TOTP stands for Time-based One-Time Password. The server and your device each hold the same secret key and compute the same number from that key plus the current time, so nothing is transmitted and there is nothing to intercept. SMS codes travel over the phone network and can be redirected through SIM swapping.
Why is my code rejected by the service?
Three usual causes. Your device clock is off, since TOTP depends on time. The service uses different parameters, such as 8 digits or SHA-256 instead of the 6-digit SHA-1 default. Or the secret was mistyped: 0, 1, 8 and 9 are not part of base32 and are usually misread from O, I, B and g.
Is this safe to use for important accounts?
For day-to-day use an authenticator app or a password manager is the better choice, because it keeps the key in encrypted device storage instead of asking you to paste it each time. This tool is for verifying a backup key, signing in when your phone is unavailable, and testing a TOTP integration. Anyone holding your secret key can generate valid codes, so treat it like a password.
Does the secret key get stored in my browser?
Nothing is stored automatically. The key stays in page memory and is gone when you close or reload the tab. No localStorage, no sessionStorage and no cookies are used to keep it.
Which algorithms and code lengths are supported?
SHA-1, SHA-256 and SHA-512; lengths of 6 to 10 digits; periods of 15, 30 or 60 seconds. The implementation is tested against every official test vector in RFC 6238 Appendix B and RFC 4226 Appendix D.