Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

TOTP / HOTP Code Generator

Live 2FA codes from a secret, setup QR codes and authenticator backups, on your device.

Security No upload Free, no sign-up

Secret and settings

Also blurs the setup link and QR code, for screen sharing.
Type

Start time and test time

RFC 6238 counts steps from T0; almost every service uses 0 (1 January 1970 UTC).

Unix seconds, e.g. 1111111109 from the RFC 6238 test table.

One-time code

TOTP — Enter or generate a secret.
Codes around the current one
WindowCodeValid

Check a code

Setup link and QR code

    Anyone who scans this QR code or sees the link can generate your codes. Do not share screenshots of it.

    Next steps

    About the TOTP / HOTP Code Generator

    One-time codes from authenticator apps are TOTP (RFC 6238): an HMAC of the number of 30-second steps since 1970, cut down to 6–8 digits. HOTP (RFC 4226) is the same with a counter instead of the clock. This tool computes both from a secret in Base32, hex or text, with SHA-1, SHA-256 or SHA-512, any digit count from 6 to 8 and any period, and shows the live code with a countdown and the previous and next codes.

    It builds the otpauth:// setup link and QR code that apps scan, checks a code the way a server does (with a ±1-step window), and reads QR codes and links — including Google Authenticator export QR codes (otpauth-migration://), which it turns back into one link and QR code per account so you can back them up or move them to another app. Secrets never leave your browser and nothing is stored.

    How to use it

    1. Paste the secret your service showed you (spaces are fine) or press New random secret. Choose the algorithm, digits and period your service uses — SHA-1, 6 digits and 30 seconds unless it says otherwise.
    2. Read the code in the dark panel; the bar shows how long it stays valid, and the table shows the codes before and after it.
    3. To test a login, type a code under Check a code: the tool says whether it is valid now, one step late or early, or not at all.
    4. To set up an app, fill in the issuer and account name, then scan the QR code or copy the otpauth:// link. Download the QR as PNG or SVG for your documentation.
    5. To back up Google Authenticator, open its menu → Transfer accounts → Export accounts, then on this page choose Import & back up and scan the QR codes with your computer’s camera (or choose a photo of them). Every account appears with its current code; download the backup file or show each account’s QR code for the new app.

    Examples

    RFC 6238 test vector
    Input
    Secret (text): 12345678901234567890 · SHA-1 · 8 digits · 30 s · fixed time 59
    Result
    94287082

    Press RFC 6238 test secret, tick Use a fixed time and enter 59 (or 1111111109 → 07081804). With the 32-byte secret and SHA-256 the time 59 gives 46119246.

    HOTP, RFC 4226 Appendix D
    Input
    Secret (text): 12345678901234567890 · HOTP · counter 0, 1, 2
    Result
    755224, 287082, 359152
    Google’s example setup link
    Input
    Secret JBSWY3DPEHPK3PXP · issuer Example · account [email protected]
    Result
    otpauth://totp/Example:[email protected]?secret=JBSWY3DPEHPK3PXP&issuer=Example

    Parameters left at their defaults (SHA1, 6 digits, 30 seconds) are not written, which keeps the QR code small.

    A Google Authenticator export link
    Input
    otpauth-migration://offline?data=CjEKCkhlbGxvId6tvu8SGEV4YW1wbGU6YWxpY2VAZ29vZ2xlLmNvbRoHRXhhbXBsZTAC
    Result
    Example: [email protected] — TOTP, SHA-1, 6 digits, secret JBSWY3DPEHPK3PXP

    The sample from the open-source dim13/otpauth project.

    Common uses

    • Testing the 2FA sign-up and login of your own web app: generate a secret, scan it, and check codes against your server.
    • Debugging “invalid code” reports by trying the same secret with other algorithms, digit counts, periods and clock offsets.
    • Backing up or moving Google Authenticator accounts to another app before you change phones.
    • Producing the setup QR code for a shared test account in a staging environment.

    How the codes are calculated

    HOTP(K, C) = Truncate(HMAC-SHA-1(K, C)) mod 10^digits, where C is the counter as 8 bytes, big-endian. "Truncate" takes the low 4 bits of the last HMAC byte as an offset and reads the 31-bit number that starts there (RFC 4226 §5.3). TOTP uses C = ⌊(Unix time − T0) / X⌋ with T0 = 0 and X = 30 seconds by default (RFC 6238 §4); SHA-256 and SHA-512 variants use the same steps with a longer HMAC. The results here are checked against the test vectors in RFC 4226 Appendix D and RFC 6238 Appendix B.

    RFC 4226 requires a secret of at least 128 bits and recommends 160 bits (20 bytes, 32 Base32 characters), which is what New random secret makes by default.

    otpauth:// links and app compatibility

    Setup QR codes contain a link like otpauth://totp/Issuer:account?secret=…&issuer=…, defined by Google’s Key Uri Format page (archived). The secret is Base32 without "=" padding, and the issuer should appear both before the colon and as the issuer parameter.

    That page says Google Authenticator ignores the algorithm and period parameters, and that its Android version ignores digits. Apps change, so check the app your users have; SHA-1, 6 digits and 30 seconds work everywhere.

    Checking codes like a server

    RFC 6238 §5.2 recommends accepting at most one time step of network delay, and says a code that has already been accepted must not be accepted again. Check a code uses ±1 step by default and tells you which step matched, so you can see clock drift. For HOTP it looks ahead a few counters, as RFC 4226 §7.4 describes for tokens pressed without logging in.

    About Google Authenticator export codes

    Export QR codes contain otpauth-migration://offline?data=…, a Base64 Protocol Buffers message that Google does not document. This tool reads it with the field layout published by open-source projects such as dim13/otpauth: secret, name, issuer, algorithm, digits, type and counter for each account, plus the batch number when the export is split into several QR codes. The export has no period, because the app always uses 30 seconds. Back-up files made here are plain text: anyone who reads them can make your codes, so keep them encrypted and offline.

    Limitations

    • TOTP codes are only right when this device’s clock is right; use Use a fixed time to test a specific moment.
    • Only standard TOTP and HOTP codes are made; proprietary schemes that use letters instead of digits are not supported.
    • Reading export QR codes relies on a format Google has not published; a future app version could change it.
    • Accounts that use MD5 can be read from an export, but this generator does not offer MD5 codes.
    • Nothing is saved: secrets, imported accounts and codes are gone when you close or reload the page.

    Privacy

    Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot. Codes, links and QR codes are made on your device. To read a QR image, browsers without a built-in QR reader download the decoder (zxing-wasm) from this site once. Secrets and pictures are never uploaded.

    Frequently asked questions

    Why do my codes differ from the ones in my authenticator app?

    Check, in this order: the device clocks (TOTP needs both to be within about 30 seconds of the real time), the secret and its format (Base32 vs hex vs text), and the algorithm, digits and period. Some apps ignore non-default settings in a QR code and compute SHA-1, 6-digit, 30-second codes anyway.

    Is it safe to type my real 2FA secret here?

    Everything is computed in your browser: the secret is not sent, logged or stored, and codes are calculated without any connection once the page has loaded. A 2FA secret is as sensitive as a password, though — use test secrets where you can, tick Hide the secret (it also blurs the setup link and QR code) before sharing your screen, and close the tab when you are done.

    What is the difference between TOTP and HOTP?

    Both compute an HMAC of a number and shorten it to a few digits. TOTP uses the current 30-second time step, so codes change on their own and expire; HOTP uses a counter that goes up by one each time a code is used, so a code stays valid until it is used. Most websites and apps use TOTP.

    How do I back up my Google Authenticator accounts?

    In the app, open the menu → Transfer accounts → Export accounts. On this page choose Import & back up and scan each QR code with your computer’s camera, or choose a photo of it. Then download the backup file (one otpauth:// link per line) and store it encrypted, or show each account’s QR code and scan it with the new app.

    How long should a TOTP secret be?

    RFC 4226 requires at least 128 bits and recommends 160 bits — 20 random bytes, which is 32 Base32 characters. Some services still use 80-bit (16-character) secrets; they work but are below the RFC minimum.

    Why is a code still accepted after it has changed in the app?

    Servers usually accept the previous step too, to allow for network delay and small clock differences — RFC 6238 recommends at most one step. Try it with Check a code: a code from the previous window shows as “1 step ago”.

    Quick answers and tool search

    Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.