Security Tools
TOTP codes.
Paste a Base32 authenticator (2FA) secret and get a live, auto-refreshing 6-digit code — computed locally with the standard TOTP algorithm (RFC 6238). Nothing is sent over the network; there isn't even a network call in this page.
Secret
Current code
Enter a secret and press Start generating.
How it works
- Standard algorithm: this is RFC 6238 TOTP on top of RFC 4226 HOTP — the same algorithm every authenticator app uses. The secret is Base32-decoded, combined with the current 30-second time step via HMAC, then dynamically truncated to a 6-digit code. Verified in this build against the official RFC 6238 Appendix B test vectors (SHA-1, SHA-256 and SHA-512, at three timestamps each) before shipping.
- Fully local: the secret and every code computed from it stay in this tab's memory only. Nothing is written to storage and no network request is ever made by this page.
- Use it for: confirming a setup key works before you commit to it, generating a code when you're mid-setup and the app hasn't scanned the QR yet, or testing a TOTP integration you're building.
- Think twice before pasting a real, high-value secret (banking, email, your password manager) into any web page, including this one — not because this page phones home (it doesn't), but because the safest secret is one that only ever touched your authenticator app. For test accounts and low-stakes 2FA this is fine.