LOCAL AUTHENTICATION UTILITY
2FA Code
Generator.
Generate time-based authentication codes from your own Base32 TOTP secret or an authenticator setup QR image.
Local processing.
No account, storage or API.
This tool does not bypass 2FA. You need the correct secret issued by your account provider; a password, recovery code or previous 6-digit code will not work.
Base32 letters A–Z and digits 2–7. Spaces and lowercase letters are accepted. Never put your secret in the page address.
PNG, JPG or WebP under 8 MB / 20 megapixels. Standard otpauth://totp QR codes only. No camera access needed.
Keep the provider's settings. Changing these settings does not change the configuration of your account.
Current authentication code
Your 2FA secret and authentication codes are processed locally in your browser and are never sent to our servers. Nothing is automatically saved. Clear removes the active input and code. Clipboard copies are managed by your device and are not removed by Clear.
What is a TOTP code?
A time-based one-time password is calculated from a shared secret and the current time. Many authenticator setups use a 6-digit code with a 30-second period. The account provider must have the matching secret and settings to accept the code. This tool cannot recover a missing secret, verify account access or bypass two-factor authentication.
How to use the 2FA Code Generator
- Enter the Base32 secret from your own account's authenticator setup, or select an image of its setup QR code.
- Check the algorithm, code length and period. QR imports also show the issuer and account label when present.
- Select Generate code. The countdown shows time until the next period; the code refreshes automatically.
- Copy the code into the provider's sign-in screen. Select Clear when finished.
Privacy and security
The browser's Web Crypto implementation performs HMAC calculations locally. QR images are decoded locally using a bundled library. This page has no analytics, value logging, remote conversion service, or automatic secret storage in cookies, localStorage or sessionStorage. It does not add entered values to URLs or browser history. Navigating away clears the active state, including when returning through the back button.
Use a trusted device and browser. Extensions, password managers, keyboards and operating-system clipboard history are outside this page's control. Masking hides the input visually; it does not protect against a compromised device. JavaScript cannot guarantee immediate physical erasure of all memory copies. For everyday account protection, keep your primary authenticator and recovery method securely available.
The implementation follows RFC 6238. Your device clock must be correct; this page does not contact a time server.
AUTHENTICATOR CODE HELP
Questions about TOTP.
Can I generate a code without the correct secret?
No. A syntactically valid Base32 value can produce numbers, but they will not authenticate an account unless the secret, algorithm, period and digit count match that account.
Why is my code rejected?
Check that you used the correct account secret and settings. Enable automatic date and time on your device, wait for a fresh code and try again. The tool cannot check acceptance with your provider.
Which QR configurations are supported?
Standard otpauth://totp configurations with Base32 secret, issuer, account label, 6 or 8 digits, SHA1/SHA256/SHA512 and a whole-number period from 1 to 3,600 seconds. Defaults are 6 digits, SHA1 and 30 seconds. HOTP, Steam and authenticator migration/export QR formats are not supported.
Does Clear erase my clipboard?
No. Clear removes the active secret, account label and displayed code from this tool. It does not alter your original QR file, password manager or clipboard history. Copy Code writes only the current code to your device clipboard when you request it.
Does this replace my authenticator app?
This is a temporary local utility, not a vault or backup. It remembers no accounts after leaving or refreshing. Keep your provider's recovery methods and your normal authenticator available.
Does it work on a phone?
Modern HTTPS browsers with Web Crypto can generate codes. QR image import needs image-decoding support. You can enter the Base32 secret manually if an image cannot be read.