MODULE 01 / TIME-BASED TOKEN

2FA code generator

Enter your Base32 secret to generate a one-time code for the current 30-second window.

TOTP / SHA-1
SOURCE SECRET

Enter secret

01
EMPTY

Spaces, hyphens, and letter case are supported and cleaned before submission.

CURRENT TOKEN

Current code

------
READY WHEN YOU ARE
SECRETWaiting for secret
REFRESHES IN—

No code generated yet

HOW IT WORKS

Codes rotate every 30 seconds. When a new window starts, this page refreshes quietly so you do not need to submit again.

RFC 6238

How to generate a 2FA code

  1. Get the full Base32 secret from the two-factor settings of your own account. A secret differs from an SMS code or recovery code.
  2. Enter the secret above and select Generate code. This tool uses SHA-1 TOTP with six digits and a 30-second period.
  3. Copy the current code into the matching service before it expires. Codes refresh automatically while the page remains open.

Facebook 2FA and other TOTP accounts

Facebook accounts configured for authenticator-based verification, and other services with matching TOTP parameters, can use their account-specific secret. This tool cannot retrieve a secret, reset an account, or generate SMS codes.

The secret is sent to this website’s server to calculate a code. Calculation is not performed entirely in your browser. The application does not write secrets to browser storage or server files.

Frequently asked questions

Why is my code rejected?

Check that the complete secret belongs to the account and that the service uses SHA-1, six digits, and a 30-second period. Try a freshly generated code. Clock differences between the generator and the verifying service can also cause rejection.

Can I generate codes without the secret?

No. You need the original TOTP secret. If it is unavailable, use the service’s official recovery codes, a signed-in device, or its account recovery process.

How does a recovery code differ from a TOTP code?

TOTP codes change over time, usually every 30 seconds. Recovery codes are issued separately by the service for account recovery and cannot be entered as Base32 secrets.