Security · Developer tools
otpauth:// URIs.
Take apart the link inside a 2FA QR code, or build one from a Base32 secret. Follows the Key Uri Format used by authenticator apps. Runs entirely in your browser; nothing is sent anywhere.
Parse a URI
Build a URI
Result
Parse or build a URI to see the result.
The format
- Shape:
otpauth://TYPE/LABEL?PARAMETERS, where TYPE istotporhotpand LABEL isissuer:account(colon literal or %3A). - Parameters:
secret(required, Base32, padding omitted);issuer(strongly recommended);algorithmSHA1/SHA256/SHA512 (default SHA1);digits6 or 8 (default 6);counter(required for hotp);periodin seconds for totp (default 30). - Compatibility: the specification notes Google Authenticator ignores algorithm, digits and period, so non-default values may behave differently between apps.
- Source: the google-authenticator project's Key Uri Format wiki page. Treat a real secret like a password: this page never sends it anywhere, but avoid pasting high-value secrets into any web page. To see live codes for a secret, use the TOTP Code Generator.