Se regenerează în 6s · RFC 6238 TOTP · calculat local - secretul tău nu părăsește niciodată browserul.
(Documentație în engleză)
What it does
Generates time-based one-time passwords (TOTP, RFC 6238) from a Base32 secret - the same algorithm authenticator apps use for 2FA. The algorithm (SHA1, SHA256, SHA512), the digit count (6 or 8), and the period in seconds are all adjustable. A progress bar depletes over the period; when it empties, a new code appears. The display refreshes every second.
How to use it
- Enter the Base32 secret from your 2FA setup - the string behind the
otpauth://QR code. - Set algorithm, digits, and period to match what your service configured. The defaults (SHA1, 6 digits, 30 seconds) match most services.
- Watch the progress bar, and copy the code while it is current.
The big display groups digits with a thin space for readability (123 456), but Copy takes the raw digits (123456), so nothing corrupts the paste. The share link encodes the secret and every option - treat it like a password, because the secret inside it opens your account.
Examples
- Secret
JBSWY3DPEHPK3PXP, SHA1, 6 digits, 30 s: a rolling 6-digit code that regenerates every 30 seconds. - A non-Base32 string (lowercase letters, spaces, a
0or1in the wrong place) showsInvalid Base32 secret.instead of a code.
How TOTP works
A TOTP code is a
HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
keyed by time. Your app and the server hold the same secret and read the same clock; from those two inputs both sides derive the same short number. The secret crosses the wire once, at setup, and never again.The recipe, step by step:
T = floor(unix_time / period) # 30 s steps: T advances every 30 s
mac = HMAC(secret, T as 8 big-endian bytes) # SHA1, SHA256, or SHA512
off = last byte of mac, low 4 bits # an offset (0..15) into the digest
num = 4 bytes at that offset, top bit cleared, mod 10^digits
code = num, zero-padded to the digit count
- Why codes expire.
Tchanges when the period elapses, so theHMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
input changes, so the code changes. Nothing deletes the old code; a new moment simply hashes to a new number. - Why clock drift breaks login. A server usually accepts the code for the current step plus or minus one. Skew further than that, and you compute a code for a step the server refuses.
- Why the secret is Base32. Base32 uses only A-Z and 2-7: no lowercase, no
0, no1, no lookalike pairs. A person can re-type a setup key from the QR-code fallback without ambiguity.
Good to know
- Private: the secret is used only locally to compute the code - it never leaves the browser.
- This tool generates codes; it is not a vault. Keep real secrets in a password manager.
- 8 digits and SHA256/SHA512 exist for services that require them (RFC 6238 allows all three algorithms). Most use the defaults.
- Related tools: Password Strength Analyser,
HMACHMACA construction that combines a hash function with a secret key to prove a message is intact and came from someone holding the key.
Generator, Password Generator.