2FA TOTP Authenticator

Generate time-based one-time passwords for your 2FA accounts. All secrets are stored locally in your browser — never sent anywhere.

No accounts yet

Add your first 2FA account by entering a secret key or scanning a QR code from your authenticator app.

100% Private

Your secret keys are stored only in your browser's localStorage and never transmitted to any server.

Live Countdown

Each code shows a real-time countdown bar so you always know when it expires and the next code generates.

QR Code Support

Import accounts by uploading, dragging, or pasting a QR code image from Google Authenticator, Authy, and more.

How TOTP Works

Time-Based One-Time Passwords (TOTP) are generated using a shared secret key and the current time. Every 30 seconds, a new 6 or 8 digit code is produced using HMAC-SHA1 (or SHA256/SHA512). The server and your authenticator independently compute the same code, so no network communication is needed to verify it.

Supported Standards

  • RFC 6238: TOTP standard used by Google Authenticator, Authy, and all major apps.
  • otpauth:// URI: Standard format for QR codes and export/import interoperability.
  • Base32 secrets: The standard encoding for TOTP secret keys.

Algorithms Supported

SHA1 (default — most compatible)
SHA256 (more secure)
SHA512 (highest security)