What is a TOTP generator?
A TOTP generator combines a shared secret with the current time to calculate a short-lived numeric code. It follows RFC 6238 and commonly changes every 30 seconds. The account and authenticator must use the same secret, algorithm, digit length, and time period.
TOTP versus HOTP
TOTP is time based. HOTP follows RFC 4226 and advances with a counter instead. An HOTP code only matches when both sides use the same counter, so this tool never advances that counter silently. Use the explicit next-counter control after the verifying service has advanced.
How to generate a one-time password
- Copy the Base32 shared secret from the system you are testing.
- Select TOTP or HOTP and match the algorithm and code length.
- For TOTP, match the 30- or 60-second period. For HOTP, enter the exact counter.
- Generate and copy the code before its time period ends.
- Clear the secret and close the tab when finished.
Why SHA-1 is the default
SHA-1 remains the default here because it is the most widely supported HMAC option for authenticator interoperability, not because it is recommended for general-purpose file hashing. RFC 6238 also permits SHA-256 and SHA-512 when both systems agree.
Clock and counter troubleshooting
If a TOTP code fails, verify the device clock and all enrollment settings. If an HOTP code fails, the client and server counters may be out of sync. Do not keep advancing the counter without understanding the verifier’s resynchronization process.
Standards and verification
The implementation is tested against the published vectors in RFC 4226 and RFC 6238, including the corrected algorithm-specific test secrets documented by the RFC Editor.