>_devtools

HOTP Generator & Validator

Generate counter-based one-time passwords per RFC 4226 and validate a code against a look-ahead window to resynchronize a counter.

What this does

Generates HMAC-based one-time passwords (RFC 4226) for a Base32 secret and a counter, and shows the next few codes so you can see the sequence. The Validate tab checks a code against a look-ahead window and reports which counter matched.

How it works

The counter is written as an 8-byte big-endian number, run through HMAC with the secret (SHA-1 unless you pick another), and dynamically truncated to 6 to 8 decimal digits. Unlike TOTP, nothing depends on time: the code only changes when the counter does, so a token and a server can drift apart if the user generates codes that are never submitted.

Resynchronizing

Servers accept a code from any counter inside a look-ahead window and then move their stored counter to one past the match. Enter the server's counter, set the look-ahead, and validate: the page shows the matching counter and the value the server should store.

Example

"Load example" fills the RFC 4226 secret 12345678901234567890 in Base32. Counter 0 gives 755224 and counter 1 gives 287082, matching the published test vectors.

Privacy

Secrets stay in memory in this tab and are not stored or uploaded. Use test secrets, not the one protecting a real account.