2FA Code Generator

Time-based one-time codes from a setup key.

Free. Runs in your browser: nothing you enter or open is uploaded.

For testing and recovery only. A 2FA setup key is as sensitive as a password: anyone who has it can make your codes. Never paste a real key into a site you do not trust. This page computes the codes in your browser and sends nothing, but the safest home for a real key is an authenticator app or a password manager.

------
Previous code
Next code
Time step
Test at a fixed time

Useful to check a server, or to compare with the RFC 6238 test values. Leave it empty to follow the clock.

Codes follow RFC 6238 (TOTP) and RFC 4226 (HOTP) and are computed with your browser's Web Crypto HMAC, the same way Google Authenticator, Microsoft Authenticator, Authy and 1Password do. If the codes here do not match your app, check the time on your device first: TOTP codes depend on an accurate clock.

How to use it

  1. Paste the setup key a site showed you, or the otpauth:// link inside its QR code. Most sites use Base32, six digits, 30 seconds and SHA-1.
  2. Read the current code. The ring shows how long it stays valid; the next code is listed below it.
  3. Copy the code. To test a server, open Test at a fixed time and enter a Unix time.

Questions

When is this useful?

When you build or test a login system and need codes to check against, when you want to confirm a setup key you saved is still right before you rely on it, or when an authenticator app shows codes a site rejects and you want to rule out a wrong setting.

Why does the site reject my code?

Usually the clock: if your device is more than about 30 seconds out, codes will not match. Turn on automatic time in your settings. Otherwise check the digits, period and algorithm, which some services change from the defaults.

What is an otpauth link?

The text inside a 2FA QR code. It names the account and issuer and carries the secret, and sometimes the algorithm, digits and period. Paste it here and the settings fill in for you.

Is it safe to keep backup codes and keys?

Yes, if they are stored safely, such as in a password manager or printed and locked away. Losing your phone without them can lock you out of an account for good.