2FA TOTP Authenticator
Generate time-based one-time passwords for your 2FA accounts.
All secrets are stored locally in your browser — never sent anywhere.
No accounts yet
Add your first 2FA account by entering a secret key or scanning a QR code from your authenticator app.
100% Private
Your secret keys are stored only in your browser's localStorage and never transmitted to any server.
Live Countdown
Each code shows a real-time countdown bar so you always know when it expires and the next code generates.
QR Code Support
Import accounts by uploading, dragging, or pasting a QR code image from Google Authenticator, Authy, and more.
How TOTP Works
Time-Based One-Time Passwords (TOTP) are generated using a shared secret key and the current time. Every 30 seconds, a new 6 or 8 digit code is produced using HMAC-SHA1 (or SHA256/SHA512). The server and your authenticator independently compute the same code, so no network communication is needed to verify it.
Supported Standards
- RFC 6238: TOTP standard used by Google Authenticator, Authy, and all major apps.
- otpauth:// URI: Standard format for QR codes and export/import interoperability.
- Base32 secrets: The standard encoding for TOTP secret keys.