TOTP & HOTP Authenticator Lab LOCAL ONLY

Generate and verify RFC-compatible one-time passwords from a Base32 secret, then build an otpauth URI without sending credentials anywhere.

Secrets and one-time codes stay in this browser. Use test secrets whenever possible and never share a live authentication seed.
Authenticator settingsRFC 4226 / RFC 6238 parameters
Parameter review
  • Choose parameters and calculate a code to review the authenticator setup.

Test provisioning before enabling 2FA

Compare the generated value with your implementation using a disposable test secret. Clock drift, secret storage, recovery codes, rate limits, and account recovery still require server-side controls.

Recent tools: