TOTP Generator

A free online TOTP generator for time-based one-time passwords. Paste a Base32 secret — or a complete otpauth:// URI — and choose your algorithm, digit count, and period. Everything is calculated in your browser.

Codes are computed in your browser with the Web Crypto API. To verify, open DevTools (F12) → Network and generate a code: no request is sent, so your secret never leaves this page.

What is a TOTP generator?

A TOTP generator turns two inputs — a shared secret key and the current time — into a short-lived code for two-factor authentication. It implements the Time-Based One-Time Password algorithm from IETF RFC 6238. Your service runs the identical calculation on its side, so both arrive at the same six-digit code within the same 30-second window. When the window ends, the TOTP code changes — that is the “time-based” part.

This TOTP code generator is compatible with every authenticator app that speaks the standard, including Google Authenticator, Microsoft Authenticator, Authy, 1Password, and hardware-adjacent apps. If your service calls the feature “two-step verification”, “2FA”, or “authenticator app”, the same time-based OTP code works.

Supported TOTP parameters

Most services use the defaults (SHA-1, 6 digits, 30 seconds), but some — certain crypto exchanges, enterprise SSO, and self-hosted tools — deviate. This page covers all common variations:

ParameterOptionsDefault
Hash algorithmSHA-1 · SHA-256 · SHA-512SHA-1
Code length6 · 7 · 8 digits6 digits
Time period30 · 60 · 90 seconds30 seconds
Input formatBase32 secret · otpauth:// URIBase32

If your codes are rejected but the key is correct, the service is probably using a non-default parameter — try SHA-256 or an 8-digit code here before assuming the key is wrong.

Generate a TOTP code from an otpauth:// URI

When you cannot scan a QR code, some services show the full URI instead of a bare key:

otpauth://totp/MyService:you@example.com?secret=JBSWY3DPEHPK3PXP&algorithm=SHA1&digits=6&period=30

Paste the whole URI above and this otpauth URL to code converter reads everything from it — the secret, the algorithm, the digit count, and the period — so a mismatched setting can never cause a wrong code. The text after totp/ (the account label) is shown above the result so you can tell accounts apart.

For developers and testers

If you are testing a 2FA implementation, this page works as a quick TOTP tester: paste a known test secret and compare outputs. The RFC 6238 test secret is the ASCII string 12345678901234567890, which encodes to the Base32 key GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ. At 8 digits and SHA-1, time T=59 must produce 94287082 — try it above to verify the generator in one step.

The equivalent calculation in JavaScript with the Web Crypto API looks like this:

// TOTP (RFC 6238): HMAC(secret, big-endian uint64 counter), then dynamic truncation
const key = await crypto.subtle.importKey('raw', base32Decode(SECRET),
  { name: 'HMAC', hash: 'SHA-1' }, false, ['sign']);
const counter = Math.floor(Date.now() / 1000 / 30);
const msg = new Uint8Array(8); new DataView(msg.buffer).setUint32(4, counter);
const h = new Uint8Array(await crypto.subtle.sign('HMAC', key, msg));
const off = h[h.length - 1] & 0x0f;
const code = ((h[off] & 0x7f) << 24 | h[off+1] << 16 | h[off+2] << 8 | h[off+3]) % 1e6;

Secrets for testing can be any valid Base32 string — 16 or 32 characters from the alphabet A–Z and 2–7.

Frequently asked questions

What is a TOTP generator?

A TOTP generator turns a shared Base32 secret and the current time into a short-lived one-time password, following RFC 6238. Your service and the generator calculate the same code independently, which is why the code changes every 30 seconds.

Can this TOTP generator do SHA-256 and 8 digits?

Yes. Use the options to pick SHA-1, SHA-256 or SHA-512, 6, 7 or 8 digits, and a 30, 60 or 90-second period. Services that deviate from the defaults usually need exactly these settings.

Can I paste an otpauth:// URI instead of a bare key?

Yes. Paste the full otpauth://totp/… URI and the generator reads the secret, algorithm, digits, and period from it automatically.

Is the TOTP calculation done on a server?

No. The code is calculated in your browser with the Web Crypto API. The secret never leaves the page — you can confirm in the Network tab that nothing is sent.

Is this a TOTP calculator or a tester?

Both. Enter a secret and a live code appears — like a TOTP calculator synced to the clock — and with a known test vector you can use it to verify your own implementation’s output.

Related 2FA tools