What this does
Generates HMAC-based one-time passwords (RFC 4226) for a Base32 secret and a counter, and shows the next few codes so you can see the sequence. The Validate tab checks a code against a look-ahead window and reports which counter matched.
How it works
The counter is written as an 8-byte big-endian number, run through HMAC with the secret (SHA-1 unless you pick another), and dynamically truncated to 6 to 8 decimal digits. Unlike TOTP, nothing depends on time: the code only changes when the counter does, so a token and a server can drift apart if the user generates codes that are never submitted.
Resynchronizing
Servers accept a code from any counter inside a look-ahead window and then move their stored counter to one past the match. Enter the server's counter, set the look-ahead, and validate: the page shows the matching counter and the value the server should store.
Example
"Load example" fills the RFC 4226 secret 12345678901234567890 in Base32. Counter 0 gives 755224 and counter 1 gives 287082, matching the published test vectors.
Privacy
Secrets stay in memory in this tab and are not stored or uploaded. Use test secrets, not the one protecting a real account.