๐Ÿ”‘ TOTP/HOTP Generator

Enter a secret key

Enter a Base32 secret key to generate an RFC 6238-compliant time-based one-time password (TOTP), the same kind used by authenticator apps (Google Authenticator, etc.). Customize the digit count, refresh interval, and hash algorithm. All computation happens in your browser via the Web Crypto API โ€” your secret is never sent anywhere.

How to use

  1. Enter a Base32-format secret key (the string shown when setting up an authenticator app).
  2. Adjust the digit count (6 or 8), refresh interval (seconds), and hash algorithm as needed.
  3. The current one-time password is shown and refreshes automatically at the configured interval.

How the calculation works

TOTP (Time-based One-Time Password) is the scheme behind the six-digit codes that change every 30 seconds in authenticator apps such as Google Authenticator and Microsoft Authenticator. It is defined in RFC 6238. The calculation goes like this: 1. Divide the current Unix time (seconds since 1 January 1970) by 30 and round down to get the counter. 2. Compute HMAC-SHA1 (or SHA-256 / SHA-512) of the counter with the Base32-encoded secret key. 3. Take the last 4 bits of the HMAC as an offset, read 4 bytes from that position, and drop the top bit to get a 31-bit integer (dynamic truncation). 4. Take that integer modulo 10โถ to get the six-digit code. The results have been checked against the test vectors in the appendix of RFC 6238.

Worked example

RFC 6238 test vectors (secret "12345678901234567890", 8 digits, SHA-1) Time 59 s โ†’ 94287082 Time 1111111109 s โ†’ 07081804 Time 2000000000 s โ†’ 69279037 The default secret JBSWY3DPEHPK3PXP ("Hello!\xDE\xAD\xBE\xEF" in Base32) is a common test value.

Things to be aware of

  • Entering the real secret for a service shows that account's codes. Treat secrets like passwords and never show them to anyone.
  • If your device clock is off, the codes will be wrong. Set the clock to update automatically.
  • Most services use 6 digits, 30 seconds and SHA-1.

FAQ

Is this calculation correct?

It has been verified against the official RFC 6238 test vector (secret "12345678901234567890", Unix time 59 seconds, producing the 8-digit code "94287082").

Is my secret key safe?

All computation happens entirely in your browser via the Web Crypto API and is never sent to a server. That said, be mindful of shared devices or onlookers when entering a real authentication secret.

Why does this use Base32?

Because the secret shown during authenticator app setup (via QR code or manual entry key) is typically encoded in Base32 format.