Open 2FA Code Generator

Learn how to generate TOTP codes from your own Base32 secret or QR image, check the countdown and settings, and keep authentication data local in your browser.

What a 2FA code generator actually does

A 2FA code generator calculates a short authentication code from a shared secret and the current time. When an account supports TOTP authentication, its setup process supplies a secret, often inside a QR code. Your authenticator and the account provider use matching settings to calculate and verify the code.

ToolNivo's 2FA Code Generator is a temporary browser utility for this task. It is not an account recovery service, a password finder or a way to bypass two-factor authentication. You must already have the correct TOTP secret for your own account. A login password, recovery code or previous six-digit code cannot replace that secret.

Start with the correct Base32 secret

Open the tool and enter the secret from your account's authenticator setup. Standard Base32 uses letters A–Z and digits 2–7. ToolNivo accepts lowercase letters and spaces, validates the encoding and displays an error when the input is malformed. The secret field is masked by default; Show secret reveals it when you need to check your entry.

Valid encoding does not prove that a secret belongs to an account. A correctly formatted but unrelated secret can still produce numbers. Only the account provider can decide whether a submitted code matches its configuration. Never put a secret into the browser address bar or share it in a support message.

Import an authenticator setup QR image

If you have a QR image instead of a written key, select the image in the tool. It supports PNG, JPG and WebP files under 8 MB and 20 megapixels. Use a clear image with the full QR square visible. If decoding fails, try a sharper crop or enter the original Base32 secret manually.

The image is decoded inside the browser. The tool accepts standard otpauth://totp configurations and fills the secret, code length, period and algorithm from the decoded configuration. It also displays the issuer and account label when available, helping you check which account you are preparing to use.

HOTP codes and authenticator migration or export QR formats are not supported. A QR image containing an ordinary website link is also not a TOTP setup. The tool reports unsupported content without opening the decoded address or uploading the image.

Check digits, period and algorithm

The default configuration produces six digits with SHA1 and a 30-second period. The tool also supports eight-digit codes, SHA256, SHA512 and whole-number periods from 1 to 3,600 seconds. Choose the values supplied by your account provider or imported from its setup QR code.

Do not change the algorithm or digit count simply because another option looks stronger. These settings must match the provider's configuration. Selecting SHA256 in this utility does not change an account that was configured for SHA1, and an eight-digit output will not work where the provider expects six digits.

For a manually entered key, check the original setup instructions if the defaults do not work. A copied secret alone does not necessarily tell you which non-default settings the account uses.

Generate, copy and use the current code

Select Generate code. The tool displays the current authentication code and a countdown to the next period. It automatically calculates a new code when the period changes, using your device clock. The default countdown lasts up to 30 seconds; imported custom periods use their own duration.

Use Copy Code to copy the current value, then paste it into the correct account's sign-in screen. If the countdown is almost finished, waiting for the next code can give you more time to enter it. Acceptance still depends on the provider's settings and verification rules.

The browser hides the displayed code when the tab is in the background and updates it when you return. Select Clear when you finish. Clear removes the active secret, account label and displayed code from the tool, but it does not delete the original QR file or erase a code already copied to your operating system clipboard.

Understand the local privacy model

ToolNivo performs TOTP calculations using the browser's Web Crypto implementation and reads QR images with a bundled local decoder. The tool does not upload the secret, QR image, decoded content or generated codes to a conversion service. Its generation workflow does not need a paid API or server-side authentication processing.

The page does not automatically store secrets in cookies, localStorage or sessionStorage. It does not add entered values to URLs or browser history. Refreshing the page or leaving and returning clears the active configuration. This behavior makes the tool a temporary utility rather than an authenticator vault or backup.

Local processing does not make an untrusted device safe. Browser extensions, password managers, keyboards and clipboard history are outside the page's control. Input masking protects against casual on-screen viewing, not a compromised browser. Keep your normal authenticator and recovery method securely available instead of relying on this page to remember accounts.

Why a generated code may be rejected

First check that the secret belongs to the account you are signing into. Then check the digit count, algorithm and period. A typo can sometimes produce a different valid Base32 secret rather than an obvious input error, so an apparently working countdown is not proof that the setup is correct.

Next check your device's date and time. TOTP depends on time agreement between the authenticator and provider. Enable your device's automatic time setting if its clock is wrong. ToolNivo does not contact a time server or test codes against your account.

If a fresh code with the correct settings is still rejected, use the provider's official recovery or support process. Repeatedly inventing new secrets or changing algorithms cannot recover the account's original configuration.

Frequently asked questions

Can the tool generate a valid code without my secret? No. It needs the correct shared secret and matching settings. It cannot bypass 2FA or derive the secret from a previous code.

Is a QR code image sensitive? An authenticator setup QR image can contain the secret needed to generate account codes. Protect it like the written secret and avoid including it in screenshots you share publicly.

Will Clear remove a copied code? No. The operating system manages the clipboard and may keep clipboard history. Clear only removes the tool's active input and result.

Can I use it on my phone? Modern HTTPS browsers with Web Crypto support can generate codes. If QR image decoding is unavailable, use the Base32 input. The interface adapts to mobile screens without changing the provider's required settings.

Does this replace an authenticator app? It is intended for temporary local use and does not save accounts. Keep a secure primary authenticator and the recovery options supplied by your account provider.

Open 2FA Code Generator

An original practical guide, prepared with AI assistance. Examples are illustrative; they are not performance results. Our editorial approach.