TOTP Code Generator

Generate a time-based code from an entered Base32 secret, with explicit algorithm, time step and validity bounds.

Inputs stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Generate code controls

Showing an example. Edit to see your own.

The key stays in this form while the tab is open. Use your existing account settings; this tool does not store or provision accounts.

A whole UTC epoch second. The result is a snapshot, not an auto-refreshing authenticator.

Processed in your browser. Your inputs stay on this device.

How to use TOTP Code Generator

  1. Enter the account’s Base32 key on a trusted device, or use the public test key in the example.
  2. Match the account algorithm, digit count and time step exactly.
  3. Leave Unix time blank for the current clock, or enter a fixed epoch second for a test.
  4. Run once and use the snapshot before its time window ends; clear the key when finished.

Example: TOTP Code Generator

Reproduce a public eight-digit TOTP test vector.

You add
Base32 key: GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ; algorithm: SHA-1; digits: 8; time step: 30 seconds; Unix time: 59.
You get
The generated snapshot code is 94287082. It belongs to time-step counter 1, not to the present time.

Options

Account HMAC algorithm
Use the algorithm configured by the account. A different HMAC algorithm generates a different code even with the same key and time.
Code digits
Six and eight digits are different account settings. Leading zeroes are part of the code and must be retained.
Time step (seconds)
The counter is the whole number of time steps since the epoch. The default is 30 seconds, but the account’s setting must match.
Unix time for a test (blank uses now)
A blank entry reads the device clock at execution. A supplied value is a whole UTC epoch second for a repeatable test; it does not create a live countdown.

Supported inputs and limits

Base32 secrets decode to 10–128 bytes; SHA-1, SHA-256 or SHA-512; six or eight digits; 15–120 second steps. One snapshot, with an optional whole Unix time. Requires Web Crypto in a secure browser context. No account enrollment, secret storage, automatic refresh or secret export. Anyone with the secret can generate the same codes.

Where your input is processed

This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

A correct test code does not enrol an account

The tool calculates from a key and settings you supply. It does not contact an account provider, register a second factor, verify your identity or store a recovery method. The public example key is for testing only and must never protect an account. A real key allows others to reproduce its codes.

Investigate clock and settings before changing the key

A rejected code may come from a clock difference, wrong digit count, different algorithm or a snapshot that has expired. Match the account’s documented settings and check the device time. This page does not automatically refresh, and it is not a replacement for a managed authenticator on an untrusted device.

Questions about TOTP Code Generator

Does the code refresh automatically?

No. Generate another snapshot when needed.

Can I use any settings with my account?

No. They must match the account’s configured secret, algorithm, digit count and time step.

Is my secret saved?

The tool does not save or export it. Clear the input when finished and use a trusted device.

Project manager: Tony Hines · Content updated 3 October 2026 · Report a problem