Security
Generate and check time-based 2FA codes from a base32 secret, with a live countdown and clock-drift detection.
Runs entirely in your browser, nothing is uploadedAlmost every authenticator app uses SHA-1, 6 digits and 30 seconds. Change these only to match a server that specifies otherwise — an app will not read them from the secret.
Codes are computed here with WebCrypto, and the implementation is checked against the test vectors published in RFC 6238. The secret never leaves this tab — but a secret pasted into any web page should be treated as a test value, not one protecting a real account.
Convert text to and from Base32, the encoding used for TOTP/2FA secret keys.
Open toolGenerate a QR code from text or a URL, or decode one from an uploaded image.
Open toolCompute an HMAC-SHA1/256/384/512 of a message with a secret key.
Open tool