Using and troubleshooting TOTP 2FA

Learn how TOTP two-factor authentication works on Facebook and other services, how Base32 secrets differ from codes, and how to troubleshoot time, algorithm, and recovery issues.

TOTP, secrets, and codes

TOTP calculates a one-time password from a shared secret and the current time. The service and authenticator use agreed parameters to calculate the code, without sending a new SMS each time.

A Base32 secret is the long-lived sequence of letters and digits used to calculate codes. A six-digit code is a short-lived result. Recovery codes, passwords, and SMS codes are not TOTP secrets.

Set up an authenticator on Facebook or another service

  1. Open the service’s official account security settings and choose two-factor authentication with an authenticator. Menu names can change.
  2. Follow its instructions to scan a QR code or enter the setup secret, and save any recovery codes it provides.
  3. Confirm setup with a generated code. Use that account’s matching authenticator for future sign-ins.

Troubleshoot a rejected code

  1. Confirm that the complete secret belongs to the account you are signing in to.
  2. Wait for the next period and enter a fresh code rather than one close to expiry.
  3. Check the algorithm, digit count, and period. This tool supports SHA-1, six digits, and 30 seconds.
  4. Check the generator’s clock. This tool generates codes on the server, which should keep its system clock synchronized.
  5. If the secret is unavailable, use the service’s official recovery options. Repeated guesses cannot recover a secret.

Store secrets and recovery options carefully

A secret can keep generating valid codes, so protect it like a password. Do not publicly share its screenshot, QR code, or a URL containing it. Read the data-processing explanation before using an online generator.

This tool sends the secret to its server for calculation and does not restore it from browser storage after a reload. See the privacy page for analytics and third-party requests.