๐Ÿ” TOTP Setup QR Code Generator

Generate an otpauth:// QR code from a TOTP (Time-based One-Time Password) secret key, which can be scanned into Google Authenticator, Authy, or other authenticator apps to register an account. Everything runs entirely in your browser โ€” the secret is never sent externally.

How to use

  1. Enter the Base32-encoded secret key.
  2. Enter an account name (display name) and issuer name.
  3. Adjust the algorithm, digit count, and refresh period if needed.
  4. Scan the generated QR code with an authenticator app.

How the calculation works

This tool creates the QR code used to add a TOTP account to an authenticator app such as Google Authenticator or Microsoft Authenticator. The QR code contains a URI in Google's "Key Uri Format": otpauth://totp/Issuer:account?secret=SECRET&algorithm=SHA1&digits=6&period=30&issuer=Issuer Spaces and symbols such as "@" in the issuer and account name are percent-encoded (a space becomes %20). The secret is a Base32 string (Aโ€“Z and 2โ€“7), and trailing "=" padding is removed as the format specifies. The URI is rendered as an SVG QR code with error-correction level M.

Worked example

Secret: JBSWY3DPEHPK3PXP Account: user@example.com Issuer: Heron Tools Generated URI otpauth://totp/Heron%20Tools:user%40example.com?secret=JBSWY3DPEHPK3PXP&algorithm=SHA1&digits=6&period=30&issuer=Heron%20Tools Scanning it with an authenticator app adds "Heron Tools (user@example.com)" and shows a six-digit code every 30 seconds.

Things to be aware of

  • The QR code contains the secret in plain form. Do not let anyone see it through screen sharing or screenshots.
  • Some apps, including Google Authenticator, may not support SHA-256/SHA-512, 8 digits or periods other than 30 seconds. For maximum compatibility, use SHA1, 6 digits and 30 seconds.
  • The QR code is generated in your browser; the secret is never sent anywhere.

FAQ

What is otpauth://?

A URI scheme originally proposed by Google Authenticator that has become a de facto standard supported by most authenticator apps, used to encode TOTP/HOTP account setup information (secret, issuer, algorithm, etc.) into a QR code.

Is the secret sent to a server?

No โ€” the QR code is generated entirely in your browser, on your own device. The secret is never sent externally.

How do I check the actual generated code?

If you want to see the current 6- or 8-digit one-time password itself, use the separate "TOTP Code Generator" tool.