TOTP & HOTP Authenticator Lab

Compute and verify RFC 6238 TOTP or RFC 4226 HOTP codes from a Base32 test secret, and build an otpauth provisioning URI for authenticator setup tests.

Runs locally in your browser
Secrets and one-time codes stay in this browser. Use test secrets whenever possible and never share a live authentication seed.
Authenticator settingsRFC 4226 / RFC 6238 parameters
Parameter review
  • Choose parameters and calculate a code to review the authenticator setup.

Test provisioning before enabling 2FA

Compare the generated value with your implementation using a disposable test secret. Clock drift, secret storage, recovery codes, rate limits, and account recovery still require server-side controls.

Recent tools: