ToolXkit Icon

TOTP Generator

Generate live two-factor codes from a Base32 secret, with the countdown.

  • Free
  • No signup
  • Nothing uploaded
  • No watermark

How to Generate TOTP Codes from a Secret

TOTP Generator: before and after TEXT A YOUR INPUT TOTP GENERATOR DONE A RESULT

Two-factor apps such as Google Authenticator show a six-digit number that changes every 30 seconds. Behind that number is a Base32 secret and a formula anyone can run. Paste the secret here and the page produces the same live code, with a bar counting down to the next one.

Developers use it to test a login flow without reaching for a phone, and to build the otpauth:// link that an authenticator QR code contains. The code is worked out from your device clock inside this tab, so the secret stays on your machine.

No software to install Free Works on any device

Steps to Get a Live TOTP Code

  1. 1. Enter the Base32 secret

    Paste the secret into the Base32 secret box. Letters are turned to capitals and spaces are ignored. To try things out, press Generate a new one for a random test secret.

  2. 2. Read the current code

    The code appears in large digits with a bar and a count of the seconds left. When the bar runs out, a new code replaces it automatically.

  3. 3. Match the service’s settings

    Digits (6, 7 or 8), Seconds per code (30 or 60) and Algorithm (SHA-1 to SHA-512) must match whatever the other side uses. Most services want 6, 30 and SHA-1.

  4. 4. Copy the otpauth link

    Fill in Issuer and Account label, then copy the otpauth:// URI. Turn it into a QR code so an authenticator app can scan it.

Try it now

What Is a TOTP Code?

TOTP means time-based one-time password, defined in RFC 6238. The server and your app share a secret. Both take the current time, count how many 30-second steps have passed since 1970, and mix that number with the secret using HMAC. The last few digits of the result are the code, so both sides get the same number without talking to each other.

Why Use Security and Crypto Tools Locally?

Hashes, keys, tokens and passwords are exactly the things you should not paste into a stranger’s server. Here they are made and checked inside your browser, so secrets stay on the machine in front of you.

“A secret generated on your own device stays yours.”
  • Strong random passwords
  • Keys generated on your device
  • Two-factor codes for testing
  • Files checked against checksums
  • Hashes in every common algorithm
  • JWTs decoded and checked
  • Security headers written for you
  • No secrets sent anywhere

Popular Uses for Hash and Key Generators

Developers and careful users reach for these during everyday security work.

  • New passwords Generate a long random password or passphrase for a new account.
  • Verifying downloads Hash a file with SHA-256 and compare it with the value the publisher lists.
  • Debugging logins Decode a JWT to see its claims and check the signature with your secret.
  • SSH and API keys Create an RSA or Ed25519 key pair or an API key for a new service.
  • Website headers Write a Content Security Policy and other security headers for a web server.
  • Testing two-factor login Generate TOTP codes and secrets to test an authenticator setup during development.
  • Script integrity Make an SRI hash so a browser can tell if a CDN script was changed.
  • Password strength Measure how many guesses a password would take, using its entropy.

What the TOTP Generator Offers

Live code with countdown

The number refreshes on its own, while a shrinking bar marks the time left before it changes.

Every standard setting

Choose 6, 7 or 8 digits, a 30 or 60 second window, and SHA-1, SHA-256, SHA-384 or SHA-512.

Random test secrets

Generate a new one creates a fresh 20-byte secret, ideal for trying out a new login screen.

otpauth:// URI

The exact link that an authenticator QR code holds, built from your issuer, label and settings, ready to copy.

Why Use ToolXkit for TOTP Generator?

Your files stay with you

Everything runs inside your browser. Nothing you open or type is uploaded to a server.

Crypto Tools for Different Users

Web developers

Create security headers, SRI hashes and JWTs while building and testing apps.

System administrators

Generate SSH keys, check fingerprints and verify file checksums on the go.

Security testers

Decode tokens, inspect PEM files and test HMAC signatures without extra tooling.

Computer science students

See how hashing, encryption and key pairs behave by trying them yourself.

Everyday users

Make strong passwords and passphrases that are never sent over the internet.

IT teams

Create API keys and OAuth values for new integrations in a safe place.

Best Times to Generate a Key or Hash

Local crypto tools make sense when you are:

  • Setting up a new server
  • Creating a strong password
  • Checking a downloaded installer
  • Debugging a sign-in problem
  • Adding security headers to a site
  • Testing an authenticator app
  • Learning how encryption works
  • Rotating an old API key

Tips for Two-Factor Codes

  1. If the codes never match, check your device clock. Being out by more than about 30 seconds gives a different code.

  2. Treat a TOTP secret like a password. Anyone who has it can produce your codes for as long as it stays active.

  3. Leave the settings on 6 digits, 30 seconds and SHA-1 unless the service says otherwise. Many apps ignore other values.

  4. Paste the secret with or without spaces. Services often print it in groups of four, and the spaces are removed before use.

Frequently Asked Questions

Answers to common questions about this tool.

Will this give the same code as Google Authenticator?

Yes, as long as the secret, digit count, time step and algorithm match and your device clock is correct. TOTP is an open standard, so every compliant app produces the same number at the same moment.

Where do I find my Base32 secret?

When you turn on two-factor login, most services show a QR code with a link beside it such as Can’t scan? or Enter key manually. That reveals the secret. Save it safely at that point, as many services will not show it again.

Is it safe to use a real secret on this page?

The code is calculated in your browser and the secret is not sent anywhere. Still, a live secret is a second factor for your account. Use this page for testing and recovery on a device you trust, and close the tab afterwards.

Why is my code rejected by the website?

The usual causes are a wrong clock, a secret copied with a missing character, or a setting that differs from the service’s, for example 8 digits instead of 6. Check the time first, then compare each setting.

How do I turn the otpauth link into a QR code?

Copy the otpauth:// URI shown under the settings and paste it into any QR code generator. Scanning that QR code with an authenticator app adds the account with the issuer and label you typed.

Are the keys and passwords made here truly random?

They come from the browser’s built-in secure random number generator, the same source used for encrypted connections. That is suitable for passwords, keys and tokens.

Does TOTP Generator send my secrets to a server?

No. Everything is worked out locally, and what you type or generate is neither uploaded nor logged. For real production keys, it is still wise to generate them on the machine where they will be used.

Is TOTP Generator free for commercial projects?

Yes. Use it for personal, work or client projects at no cost and without an account. What you generate belongs to you, and the site keeps no copy.

Can a hash be reversed to get the original text?

No. A hash is one-way. Short or common passwords can still be guessed by trying many candidates, which is why a long, random password matters more than the hash you pick.

Further reading

More Security & Crypto Tools

Other free tools for the same kind of job.

Browse all tools