๐Ÿ” TOTP Secret Key Generator

Generates a Base32 secret key (RFC 4648) from 20 bytes of cryptographic randomness.

Generating...

Generate a random Base32-encoded secret key for setting up two-factor authentication (2FA) with a TOTP authenticator app like Google Authenticator. Also generates an otpauth:// URI in the format used to feed the secret into an authenticator app.

How to use

  1. Enter a service name (issuer) and account name (optional).
  2. The generated secret key and otpauth:// URI are shown automatically.
  3. Click "Regenerate" to generate a new secret key.

How the calculation works

This tool generates a random secret key for two-factor authentication (TOTP) and shows the otpauth URI for adding it to an authenticator app. The secret is 20 random bytes (160 bits) from the browser's cryptographically secure random number generator, encoded in Base32 (the 32 characters Aโ€“Z and 2โ€“7), which gives 32 characters. RFC 4226 requires at least 128 bits and recommends 160, matching the output length of HMAC-SHA1. The otpauth URI looks like this: otpauth://totp/Issuer:account?secret=SECRET&issuer=Issuer The issuer and account name are percent-encoded (a space becomes %20).

Worked example

Sample secret (different every time) JBSWY3DPEHPK3PXPJBSWY3DPEHPK3PXP (32 characters) URI for issuer Heron Tools and account user@example.com otpauth://totp/Heron%20Tools:user%40example.com?secret=(secret)&issuer=Heron%20Tools Turn the URI into a QR code with the QR code generator to scan it with an authenticator app.

Things to be aware of

  • The secret must be known only to the user and the server. Keep it out of logs and screen shares.
  • When building a service, generate secrets on the server and store them encrypted.
  • The secret is generated in your browser and never sent anywhere.

FAQ

Is the generated secret key secure?

Yes. It's generated using the browser's Web Crypto API (a cryptographically secure random number generator), producing 20 random bytes (160 bits) that are then Base32-encoded.

What is the otpauth:// URI?

It's a standard URI format that bundles TOTP/HOTP setup details โ€” secret key, issuer name, account name โ€” into a single string. It's used to feed into authenticator apps, often via a QR code.

Is anything generated here sent anywhere?

No. All processing happens entirely in your browser โ€” the generated secret key is never sent to a server.