๐ TOTP Setup QR Code Generator
Generate an otpauth:// QR code from a TOTP (Time-based One-Time Password) secret key, which can be scanned into Google Authenticator, Authy, or other authenticator apps to register an account. Everything runs entirely in your browser โ the secret is never sent externally.
How to use
- Enter the Base32-encoded secret key.
- Enter an account name (display name) and issuer name.
- Adjust the algorithm, digit count, and refresh period if needed.
- Scan the generated QR code with an authenticator app.
How the calculation works
This tool creates the QR code used to add a TOTP account to an authenticator app such as Google Authenticator or Microsoft Authenticator. The QR code contains a URI in Google's "Key Uri Format": otpauth://totp/Issuer:account?secret=SECRET&algorithm=SHA1&digits=6&period=30&issuer=Issuer Spaces and symbols such as "@" in the issuer and account name are percent-encoded (a space becomes %20). The secret is a Base32 string (AโZ and 2โ7), and trailing "=" padding is removed as the format specifies. The URI is rendered as an SVG QR code with error-correction level M.
Worked example
Secret: JBSWY3DPEHPK3PXP Account: user@example.com Issuer: Heron Tools Generated URI otpauth://totp/Heron%20Tools:user%40example.com?secret=JBSWY3DPEHPK3PXP&algorithm=SHA1&digits=6&period=30&issuer=Heron%20Tools Scanning it with an authenticator app adds "Heron Tools (user@example.com)" and shows a six-digit code every 30 seconds.
Things to be aware of
- The QR code contains the secret in plain form. Do not let anyone see it through screen sharing or screenshots.
- Some apps, including Google Authenticator, may not support SHA-256/SHA-512, 8 digits or periods other than 30 seconds. For maximum compatibility, use SHA1, 6 digits and 30 seconds.
- The QR code is generated in your browser; the secret is never sent anywhere.
FAQ
What is otpauth://?
A URI scheme originally proposed by Google Authenticator that has become a de facto standard supported by most authenticator apps, used to encode TOTP/HOTP account setup information (secret, issuer, algorithm, etc.) into a QR code.
Is the secret sent to a server?
No โ the QR code is generated entirely in your browser, on your own device. The secret is never sent externally.
How do I check the actual generated code?
If you want to see the current 6- or 8-digit one-time password itself, use the separate "TOTP Code Generator" tool.