TOTP Generator
A free online TOTP generator for time-based one-time passwords. Paste a Base32 secret — or a complete otpauth:// URI — and choose your algorithm, digit count, and period. Everything is calculated in your browser.
Codes are computed in your browser with the Web Crypto API. To verify, open DevTools (F12) → Network and generate a code: no request is sent, so your secret never leaves this page.
What is a TOTP generator?
A TOTP generator turns two inputs — a shared secret key and the current time — into a short-lived code for two-factor authentication. It implements the Time-Based One-Time Password algorithm from IETF RFC 6238. Your service runs the identical calculation on its side, so both arrive at the same six-digit code within the same 30-second window. When the window ends, the TOTP code changes — that is the “time-based” part.
This TOTP code generator is compatible with every authenticator app that speaks the standard, including Google Authenticator, Microsoft Authenticator, Authy, 1Password, and hardware-adjacent apps. If your service calls the feature “two-step verification”, “2FA”, or “authenticator app”, the same time-based OTP code works.
Supported TOTP parameters
Most services use the defaults (SHA-1, 6 digits, 30 seconds), but some — certain crypto exchanges, enterprise SSO, and self-hosted tools — deviate. This page covers all common variations:
| Parameter | Options | Default |
|---|---|---|
| Hash algorithm | SHA-1 · SHA-256 · SHA-512 | SHA-1 |
| Code length | 6 · 7 · 8 digits | 6 digits |
| Time period | 30 · 60 · 90 seconds | 30 seconds |
| Input format | Base32 secret · otpauth:// URI | Base32 |
If your codes are rejected but the key is correct, the service is probably using a non-default parameter — try SHA-256 or an 8-digit code here before assuming the key is wrong.
Generate a TOTP code from an otpauth:// URI
When you cannot scan a QR code, some services show the full URI instead of a bare key:
otpauth://totp/MyService:you@example.com?secret=JBSWY3DPEHPK3PXP&algorithm=SHA1&digits=6&period=30
Paste the whole URI above and this otpauth URL to code converter reads everything from it — the secret, the
algorithm, the digit count, and the period — so a mismatched setting can never cause a wrong code. The text
after totp/ (the account label) is shown above the result so you can tell accounts apart.
For developers and testers
If you are testing a 2FA implementation, this page works as a quick TOTP tester: paste a known test secret
and compare outputs. The RFC 6238 test secret is the ASCII string 12345678901234567890, which
encodes to the Base32 key GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ. At 8 digits and SHA-1, time
T=59 must produce 94287082 — try it above to verify the generator in one step.
The equivalent calculation in JavaScript with the Web Crypto API looks like this:
// TOTP (RFC 6238): HMAC(secret, big-endian uint64 counter), then dynamic truncation
const key = await crypto.subtle.importKey('raw', base32Decode(SECRET),
{ name: 'HMAC', hash: 'SHA-1' }, false, ['sign']);
const counter = Math.floor(Date.now() / 1000 / 30);
const msg = new Uint8Array(8); new DataView(msg.buffer).setUint32(4, counter);
const h = new Uint8Array(await crypto.subtle.sign('HMAC', key, msg));
const off = h[h.length - 1] & 0x0f;
const code = ((h[off] & 0x7f) << 24 | h[off+1] << 16 | h[off+2] << 8 | h[off+3]) % 1e6;
Secrets for testing can be any valid Base32 string — 16 or 32 characters from the alphabet A–Z and 2–7.
Frequently asked questions
What is a TOTP generator?
A TOTP generator turns a shared Base32 secret and the current time into a short-lived one-time password, following RFC 6238. Your service and the generator calculate the same code independently, which is why the code changes every 30 seconds.
Can this TOTP generator do SHA-256 and 8 digits?
Yes. Use the options to pick SHA-1, SHA-256 or SHA-512, 6, 7 or 8 digits, and a 30, 60 or 90-second period. Services that deviate from the defaults usually need exactly these settings.
Can I paste an otpauth:// URI instead of a bare key?
Yes. Paste the full otpauth://totp/… URI and the generator reads the secret, algorithm, digits, and period from it automatically.
Is the TOTP calculation done on a server?
No. The code is calculated in your browser with the Web Crypto API. The secret never leaves the page — you can confirm in the Network tab that nothing is sent.
Is this a TOTP calculator or a tester?
Both. Enter a secret and a live code appears — like a TOTP calculator synced to the clock — and with a known test vector you can use it to verify your own implementation’s output.