OTP Generator Online
A free online OTP generator for authenticator-style one-time passwords. Enter a Base32 secret to get a live TOTP code, or switch to counter-based HOTP when your service requires it. Everything runs in your browser.
Codes are computed in your browser with the Web Crypto API — the secret never leaves this page. Verify any time in DevTools → Network.
This makes authenticator codes, not SMS codes
“OTP generator” can mean two different things. This page generates the kind your authenticator app makes: a code calculated from a secret key you paste in. It does not send SMS codes or email codes — those are delivered by your service itself, and no website can generate them for you. If you are waiting for a text message code, contact your service’s recovery options instead.
HOTP generator — counter-based codes
Time-based codes are the default everywhere, but a handful of systems still use the older HOTP standard (RFC 4226), where each code depends on a counter that increments with every use instead of on the clock:
Paste the same style of Base32 key, enter the counter value your service displays or expects, and the matching HOTP code appears. Reuse of a counter produces the same code, so services invalidate codes as the counter advances.
TOTP vs HOTP at a glance
| TOTP (time-based) | HOTP (counter-based) | |
|---|---|---|
| Standard | RFC 6238 | RFC 4226 |
| Code depends on | Current time window (usually 30s) | A counter that increments per use |
| Expires | Yes, automatically | No, until used |
| Used by | Google Authenticator and nearly all modern apps | Some legacy enterprise and banking systems |
Both are HMAC-based one-time password algorithms from the same family; if you can paste a Base32 key into an authenticator app, the corresponding code can be generated here for either standard.
Which one-time password do I have?
- Six digits that change every 30 seconds → TOTP with defaults. Use the first tool.
- Code rejected with correct key → try SHA-256/SHA-512 or 8 digits in the options.
- Service mentions a “counter” or “resync” → HOTP. Use the second tool.
- Code arrives by SMS or email → not an authenticator OTP; this page cannot help.