TOTP Authenticator Code: 30-Second One-Time Password
You got a new phone, the authenticator app will not open, and you must log into a service. Or you want to produce a test account code quickly on your desktop. This tool computes the 6-digit code from your Base32 secret, refreshing every 30 seconds with a visible countdown. The math happens entirely in your browser; the secret is never sent to a server or stored anywhere. Still, typing your real account secrets into random websites is a bad habit; think of this tool for testing, backup, and migration moments.
Step by step
- Find the secret key; setup screens usually show it as a Base32 string.
- Type or paste it into the tool; spaces and dashes are stripped automatically.
- Read the 6-digit code on screen along with the remaining seconds.
- Enter the code before time runs out; in the final seconds, wait for the fresh one.
- If codes keep failing, check your device clock is exact and try again.
- When done, close the page; the key was never saved anywhere.
Example scenario
Kerem, a security engineer, set up TOTP for an admin panel in a staging environment. His phone sits in a drawer; only his computer is on the desk. He pastes the secret from setup into the tool and types the on-screen code into the panel before the countdown ends. After three correct codes in a row, he also knows the system clock sync is healthy. For real customer accounts he keeps using the app on his phone; this route stays reserved for testing and backup.
Check your result
Confirm the code has 6 digits and the countdown resets every 30 seconds. A mistyped secret means endless rejections; compare the string letter by letter with the setup screen. If codes from your phone app match the ones here at the same moment, the setup is correct. Avoid logging in during the last 5 seconds; wait for the refresh. Rest easy knowing the key leaves nothing behind when you close the page.
Frequently asked questions
Is my secret key sent to a server?
No. Code generation uses your browser crypto functions; the key never leaves the device and is stored nowhere. Inspecting network traffic shows the key is never transmitted.
Why is my code always rejected?
The most common cause is clock drift; TOTP codes depend on time, and your device clock must be right to the minute. The second cause is a mistyped secret; compare the string from scratch.
My key has spaces and lowercase; is that a problem?
No. The tool strips spaces and dashes and uppercases letters. Just make sure the key uses the Base32 alphabet; digits 0, 1, 8, 9 do not belong to it.
Can I use this for my real accounts?
Technically yes, but it is not recommended. Keep the authenticator app on your phone or hardware key for daily accounts. Reserve this tool for testing, backup, and temporary access.
What if my key gets stolen?
Anyone holding the key can generate your codes. The moment you suspect it, reset two-factor authentication in that service and take a fresh key; old codes die with it.
Open the tool: TOTP Authenticator →
Keep an original copy before processing your file. Examples are illustrative; results depend on your document.