TOTP, secrets, and codes
TOTP calculates a one-time password from a shared secret and the current time. The service and authenticator use agreed parameters to calculate the code, without sending a new SMS each time.
A Base32 secret is the long-lived sequence of letters and digits used to calculate codes. A six-digit code is a short-lived result. Recovery codes, passwords, and SMS codes are not TOTP secrets.
Set up an authenticator on Facebook or another service
- Open the service’s official account security settings and choose two-factor authentication with an authenticator. Menu names can change.
- Follow its instructions to scan a QR code or enter the setup secret, and save any recovery codes it provides.
- Confirm setup with a generated code. Use that account’s matching authenticator for future sign-ins.
Troubleshoot a rejected code
- Confirm that the complete secret belongs to the account you are signing in to.
- Wait for the next period and enter a fresh code rather than one close to expiry.
- Check the algorithm, digit count, and period. This tool supports SHA-1, six digits, and 30 seconds.
- Check the generator’s clock. This tool generates codes on the server, which should keep its system clock synchronized.
- If the secret is unavailable, use the service’s official recovery options. Repeated guesses cannot recover a secret.
Store secrets and recovery options carefully
A secret can keep generating valid codes, so protect it like a password. Do not publicly share its screenshot, QR code, or a URL containing it. Read the data-processing explanation before using an online generator.
This tool sends the secret to its server for calculation and does not restore it from browser storage after a reload. See the privacy page for analytics and third-party requests.