LazyTools

🔒 Every tool runs in your browser, the files and values you enter are never uploaded to any server. How it works

🔐 TOTP Authenticator Code Generator

Paste a Base32 TOTP secret to see the current 6-digit two-factor code with a live countdown, computed on your device, never sent anywhere.

This runs entirely in your browser, your secret never leaves this page. Still, only paste a 2FA secret into tools you trust and control.

Enter or generate a Base32 secret to see the current one-time code.

Codes here match Google Authenticator / Authy for the same secret. Adjacent-window checking allows for small clock differences between your device and the server.

Rate this tool:
Anonymous, no account, no identifier

How the totp authenticator code generator works

A TOTP code is an HMAC of the current time step and your shared secret, truncated to 6 (or 8) digits, the exact scheme (RFC 6238) that Google Authenticator, Authy and 1Password use. The tool Base32-decodes your secret, computes the HMAC with the browser's Web Crypto API for the current 30-second window, and shows the code with a countdown, refreshing each second. It supports SHA-1 (the default), SHA-256 and SHA-512, 6 or 8 digits, and a verify mode that checks a code against the current and adjacent windows to allow for clock skew.

A word on trust: this computes codes locally and your secret never leaves the page. You can watch the network tab stay silent, or run it offline. Even so, a TOTP secret is a long-lived credential, so only ever paste one into a tool you trust and control. This is genuinely useful as a backup way to get a code when your phone isn't to hand, or to test a 2FA integration you're building, not a replacement for keeping the secret safe.

Frequently asked questions

What is a TOTP code?

A Time-based One-Time Password (RFC 6238): a 6- or 8-digit code derived from a shared secret and the current time, rotating every 30 seconds. It's the second factor apps like Google Authenticator and Authy generate.

Will these codes match Google Authenticator?

Yes, for the same Base32 secret and settings (algorithm, digits, period), this produces identical codes, because it implements the same RFC 6238 standard. The default SHA-1 / 6 digits / 30 seconds matches almost every service.

Is it safe to paste my 2FA secret here?

The computation is entirely local, your secret never leaves your browser, and it works offline. That said, a TOTP secret is a sensitive long-lived credential, so only enter one into tools you trust and control, like this open, no-upload page.

What is the countdown for?

It shows how many seconds remain before the code rotates. Codes are valid for their 30-second window (and usually the adjacent one), so a code with only a second or two left may expire before you can use it, wait for the next one.

Why would I generate TOTP codes on a computer?

As a backup when your phone isn't available, to store a shared team secret you can access without a specific device, or to test a two-factor login you're developing. Keep the secret itself protected either way.

Related privacy & security tools

From the blog