What Is a Base32 Secret Key for 2FA?
Learn Base32 secret key, how TOTP authentication works, common configuration issues, privacy considerations, and when to use the ToolNivo 2FA Code Generator.
Core concept
A Base32 TOTP secret is a textual representation of shared key material. It is not the short code displayed during sign-in.
How it works
During authenticator enrollment, a provider may show a QR image and a manual setup key. That setup information can contain the shared secret.
Settings that must match
The standard Base32 alphabet uses uppercase A–Z and digits 2–7. User interfaces may accept normalized variants for convenience.
Common mistakes to avoid
Possession of the shared secret can allow another authenticator to calculate valid codes, so setup QR images can be sensitive too.
Security and recovery
Recovery codes are different credentials. They are not interchangeable with a Base32 TOTP secret.
Standards note: Technical explanations follow RFC 6238 and, where relevant, RFC 4226. Always follow your account provider's configuration and recovery instructions.
Frequently asked questions
Can a TOTP generator bypass 2FA?
No. It needs the correct shared secret and matching settings.
Does TOTP depend on the device clock?
Yes. TOTP uses time as part of its moving factor, so significant clock disagreement can cause rejection.
Should I share my TOTP secret?
No. Treat the shared secret as sensitive authentication material.