RFC 6238 test vector
With the ASCII secret “12345678901234567890” at unix time 59, the 8-digit SHA-1 code is 94287082.
Generate time-based one-time passwords from a 2FA secret or otpauth link, like an authenticator app.
From the site's 2FA setup page (the text under the QR code).
Enter a secret to see the current code.
Runs in your browser — nothing you enter is sent to a server.
Two-factor apps generate time-based one-time passwords (TOTP, RFC 6238) from a shared secret. Paste the secret shown during 2FA setup (Base32 letters and digits) or the full otpauth:// link, and the tool shows the current code and when it changes — usually every 30 seconds — using your device's clock.
counter = floor(unix time ÷ 30)
code = truncate(HMAC-SHA-1(secret, counter)) mod 106
The HMAC-based one-time password (HOTP, RFC 4226) with the time as counter.
With the ASCII secret “12345678901234567890” at unix time 59, the 8-digit SHA-1 code is 94287082.
Paste a test account's secret to check your server accepts the codes before rolling 2FA out.
It stays in your browser, but a 2FA secret is as sensitive as a password. Only use this for testing or recovery on a trusted device.
Check your device clock — TOTP depends on accurate time — and that the digits, period and algorithm match the service.
Use the recovery codes the service gave you at setup; if you saved the secret, you can generate codes here.
Create strong random passwords with the length and characters you choose, generated privately in your browser.
Security Tools
Generate HMAC-SHA256, SHA-384, SHA-512 or SHA-1 signatures from a message and secret key.
Security Tools
Convert Unix timestamps to dates in UTC and your time zone, and dates back to timestamps.
Developer Tools