TOTP 2FA Token Generator
Generate RFC 6238 time-based 2FA one-time passwords, test authenticator secrets & preview QR codes
About TOTP 2FA Token Generator
How TOTP 2FA Token Generator Works
Decodes Base32 secret keys per RFC 4648, calculates 64-bit counter time intervals, and signs payloads with HMAC-SHA1/SHA256/SHA512 using the browser's native Web Crypto API (crypto.subtle). Extracts dynamic truncation offsets into 6-digit or 8-digit codes with zero network transmission so 2FA keys never leak.
TOTP 2FA Token Generator & Authenticator Simulator is a cybersecurity and developer testing utility for calculating time-based one-time password (TOTP) codes compliant with RFC 6238 and RFC 4226 standards. Designed for software engineers, DevOps professionals, and QA teams developing multi-factor authentication (MFA) workflows or testing API endpoints (such as Supabase, Auth0, Firebase, or custom backend services), it allows instant local generation of 6-digit or 8-digit verification codes from any Base32 secret key without requiring a physical smartphone or authenticator mobile app. Features include a live 30-second countdown circular timer, clock-skew drift verification across a ±1 step interval (previous, current, and next codes), cryptographic random Base32 secret generation, and standard otpauth:// URI QR code rendering. All HMAC calculations run 100% on-device via the browser's native Web Crypto API (crypto.subtle), guaranteeing zero leakage of critical 2FA authentication seeds.
Frequently asked questions
How does the TOTP algorithm (RFC 6238) calculate 6-digit codes?+
TOTP divides the current Unix epoch timestamp by a time step (typically 30 seconds) to produce an integer counter. It then computes an HMAC hash (using HMAC-SHA1, SHA256, or SHA512) of this counter using your decoded Base32 secret key. Dynamic truncation extracts 4 bytes from the hash, which is modulo-divided by 1,000,000 to produce the final 6-digit one-time password.
Is it safe to paste production or staging 2FA secrets into this tool?+
Yes. DevToolkit Hub calculates HMAC digests entirely inside your browser's local sandbox using window.crypto.subtle. No network requests are initiated, no analytics capture your keystrokes, and no data is stored on remote servers.
What is Clock Skew Drift and why does this tool show previous and next codes?+
If your computer's clock or your authentication server's clock drifts by a few seconds, standard authenticators may show a code from the next or previous 30-second window. The Clock Skew Drift panel displays the code from 30 seconds prior (T-1) and 30 seconds in the future (T+1) to help developers test and debug server authentication tolerance windows.
Can I scan the generated QR code into Google Authenticator or 1Password?+
Yes. Tapping 'Scan in Mobile App (Show QR)' formats your secret, issuer, and label into a standard otpauth:// URI and renders a compliant QR code that any iOS or Android authenticator app can immediately scan and enroll.
What should I do if my secret key has spaces or lowercase letters?+
The input automatically trims whitespace and normalizes lowercase letters into standard uppercase Base32 characters according to RFC 4648.
Limitations
Ensure your computer's system clock is synchronized via NTP (Network Time Protocol), as time-based tokens rely on accurate system time.