TOTP Generator From a Base32 Secret: Complete Guide
Learn TOTP generator from Base32 secret, how TOTP authentication works, common configuration issues, privacy considerations, and when to use the ToolNivo 2FA Code Generator.
Core concept
TOTP setup keys are commonly represented as Base32 text so binary key material is easier to enter manually.
How it works
Standard Base32 uses letters A–Z and digits 2–7. Some interfaces normalize lowercase letters, spaces or optional padding.
Settings that must match
The Base32 value is decoded to key bytes. TOTP combines the key with the current time step through HOTP/HMAC processing and derives the configured decimal output.
Common mistakes to avoid
The digit count, algorithm and period must match the account provider. Common defaults should not be used to guess a non-default configuration.
Security and recovery
A real TOTP secret should never be published, placed in a URL or entered into an untrusted page.
Standards note: Technical explanations follow RFC 6238 and, where relevant, RFC 4226. Always follow your account provider's configuration and recovery instructions.
Frequently asked questions
Can a TOTP generator bypass 2FA?
No. It needs the correct shared secret and matching settings.
Does TOTP depend on the device clock?
Yes. TOTP uses time as part of its moving factor, so significant clock disagreement can cause rejection.
Should I share my TOTP secret?
No. Treat the shared secret as sensitive authentication material.