Lukis' Space

← Tools

TOTP generator

Turn a TOTP secret or otpauth:// link into the current code. The secret stays on your device.

Runs entirely in your browser. Nothing you enter here is sent to the server.

Base32, spaces and dashes ignored. Paste a whole otpauth://totp/… link and the settings below fill themselves in.

How TOTP works, and what it means to paste a secret here

A TOTP code is HMAC(secret, current_time / period), with the result squeezed down to six digits. There is no network call and no server: your phone and the site you are logging into both compute the same number from the same shared secret and the same clock. That is the whole protocol.

Which means this page can do it too — and does, entirely in your browser. The secret is typed into this tab, used with the browser's own HMAC, and forgotten when you close it. It is never sent anywhere, never stored, never put in the URL.

Still, think about why you are using it

If you compute your second factor on the same machine that holds your password, you no longer have two factors — you have one, split in two places that fall together. This tool is for testing a setup, recovering when your phone is gone, or checking that a secret you were handed actually works. It is not an authenticator app.

The settings

  • Digits — six, effectively always. Some enterprise tokens use eight.
  • Period — 30 seconds, effectively always.
  • Algorithm — SHA-1. It is the standard here and it is not a weakness: HMAC-SHA-1 is unaffected by the collision attacks that killed plain SHA-1. Many apps ignore anything else even when the link asks for it.

If a code is rejected, the usual cause is a clock more than a few seconds out, not a wrong secret. The "next" code is shown so you can tell the difference: if that one is accepted, your clock is behind.

MD5 was on the old tool's list and is gone. No authenticator implements it and the browser's crypto engine will not do HMAC-MD5 at all.

Other tools

  • Code scanner — Read QR codes and barcodes with your camera or from an image. Every format ZXing knows.
  • Code generator — Make a QR code, Data Matrix, Aztec, PDF417 or a linear barcode and download it.
  • Link inspector — See where a link really goes before you open or shorten it: the real host, lookalike letters, hidden redirects and tracking parameters.
  • Base converter — Encode and decode between text and Base2 through Base85, or convert integers between any two bases.
  • Hash generator — MD5, SHA family, CRC32 and MySQL5 over text or a file. The file is read in your browser.
  • JWT decoder — Read a JSON Web Token's header and claims, with every timestamp as a date. Decoded right here; the token is never sent or stored.
  • SSH key fingerprint — SHA256 and MD5 fingerprints, key type and size, and SSHFP records for a public key. Private keys are refused unread.
  • Password generator — Random passwords from a CSPRNG, with the character classes you pick.
  • Timestamp converter — Unix time to a calendar date and back, in every format at once. Live clock included.
  • Subnet calculator — IPv4 and IPv6: network, range, host count, masks and reverse-DNS pointers.
  • Image resizer — Resize and convert an image without it ever leaving your browser. Re-encoding drops EXIF and GPS.
  • IP info — Your public IPv4 and IPv6, as this server sees them.
  • PHP obfuscator — Wrap PHP so it self-decodes at runtime. Runs on the server; the code is never stored.