RFC 4226 and RFC 6238

TOTP and HOTP Generator

Generate a time-based or counter-based one-time password from an existing Base32 shared secret. The secret and generated code remain in this browser tab.

Generate a one-time password

Paste the Base32 secret supplied by the system you are testing. Spaces and hyphens are accepted for readability.

Enter a Base32 shared secret to begin.

TOTPSHA-16 digits
Refreshes in —
Local calculationYour shared secret and one-time codes are not submitted to this website or saved in browser storage.

What is a TOTP generator?

A TOTP generator combines a shared secret with the current time to calculate a short-lived numeric code. It follows RFC 6238 and commonly changes every 30 seconds. The account and authenticator must use the same secret, algorithm, digit length, and time period.

TOTP versus HOTP

TOTP is time based. HOTP follows RFC 4226 and advances with a counter instead. An HOTP code only matches when both sides use the same counter, so this tool never advances that counter silently. Use the explicit next-counter control after the verifying service has advanced.

How to generate a one-time password

  1. Copy the Base32 shared secret from the system you are testing.
  2. Select TOTP or HOTP and match the algorithm and code length.
  3. For TOTP, match the 30- or 60-second period. For HOTP, enter the exact counter.
  4. Generate and copy the code before its time period ends.
  5. Clear the secret and close the tab when finished.

Why SHA-1 is the default

SHA-1 remains the default here because it is the most widely supported HMAC option for authenticator interoperability, not because it is recommended for general-purpose file hashing. RFC 6238 also permits SHA-256 and SHA-512 when both systems agree.

Clock and counter troubleshooting

If a TOTP code fails, verify the device clock and all enrollment settings. If an HOTP code fails, the client and server counters may be out of sync. Do not keep advancing the counter without understanding the verifier’s resynchronization process.

Standards and verification

The implementation is tested against the published vectors in RFC 4226 and RFC 6238, including the corrected algorithm-specific test secrets documented by the RFC Editor.