TOTP Generator
Generate SHA1 TOTP codes and compare local time windows
Enter a Base32 secret or otpauth URI first to generate the current TOTP immediately; parameter notes are available in Advanced mode.
——0s0The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.
About this tool
Generate RFC 6238 HMAC-SHA1 TOTP test codes from a Base32 secret or an otpauth://totp URI. Supported settings are 6 or 8 digits and 30 or 60 seconds. A nonempty URI supplies the secret and parameters; clear it to edit those fields directly. The tool displays the current and next windows and compares an optional code with those local values. It does not log in, enroll an account, or run a server verifier. Secrets are neither uploaded nor saved as browser drafts.
Production Snippets
RFC 6238 SHA1 known answer at a fixed test time
text
Secret (ASCII bytes): 12345678901234567890
Secret (Base32): GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ
Algorithm: SHA1
Digits: 8; Period: 30 seconds
Unix time: 59; Time step: 1
Expected TOTP: 94287082
The live tool uses your current clock, so it normally shows another code.Frequently Asked Questions
Which algorithms and URI types are supported?
HMAC-SHA1 TOTP only, with 6/8 digits and 30/60-second periods. SHA256, SHA512, HOTP counter URIs, and other period/digit settings are rejected instead of silently producing a different code. Missing URI algorithm, digits, or period use SHA1, 6, and 30.
Does a pasted URI override the secret and options?
Yes. While a URI is present, the secret and option fields are disabled and Generate reads its secret, digits, and period. Editing the URI discards the previous result. Clear the URI to edit the fields directly. A URI must have its own secret; it does not borrow an older field value.
What Base32 secret format is accepted?
Letters A–Z and digits 2–7, case-insensitively, with optional whitespace and correct terminal = padding. The decoded secret must contain complete bytes; impossible lengths and nonzero unused bits are rejected. Hyphens and interior padding are not removed silently.
Does Compare code validate a real login?
No. It compares a numeric string against the current and next locally calculated codes. It does not test the previous window, contact an authentication server, prevent replay, rate-limit attempts, or check that an account is enrolled. A local match alone is not successful authentication.
Why can a code disagree with my authenticator?
Check the exact secret bytes, SHA1 algorithm, digits, period, and clock synchronization. TOTP uses Unix time, so timezone labels are not an input, but an incorrect device clock changes the window. Some authenticator apps ignore non-default digits or periods; test the actual app.
Are my secret and generated codes saved?
No draft is saved and the tool does not upload these values. The public example secret is shared test data, not suitable for a real account. Editing or clearing inputs invalidates pending code generation, and navigating away stops the refresh timer.
Keep browsing