>_devtools

TOTP Generator & Validator

Generate live time-based one-time passwords with a countdown, and validate a code with a drift window. Supports SHA1, SHA256, SHA512, 6 to 8 digits, and custom periods.

What this does

Computes the same time-based one-time passwords an authenticator app shows (RFC 6238), live, with a countdown to the next code and the previous and next codes for reference. The Validate tab checks a code against the secret and tells you how many time steps it is off.

How it works

A TOTP is an HOTP (RFC 4226) whose counter is the number of periods since the Unix epoch. The secret is Base32, the HMAC is SHA-1 by default, and the code is a few digits of the result. The defaults are 6 digits and 30 seconds. SHA-256, SHA-512, 7 or 8 digits, and other periods are supported, but many authenticator apps ignore them and always use the defaults.

Validation window

Clocks drift, so servers usually accept codes from a step or two before and after the current one. Set the window to the number of steps on each side. A match at a non-zero offset hints at how far the device clock is from the server's. You can also validate at a fixed time to reproduce a failure from a log.

Example

The secret JBSWY3DPEHPK3PXP is a common demo value. The implementation is tested against the RFC 4226 and RFC 6238 test vectors for SHA-1, SHA-256, and SHA-512.

Privacy

The secret is a credential. It stays in memory in this tab: it is not stored, not put in the URL, and not sent to any server. Use test secrets, not the secret protecting a real account.