Authenticator
Get the current two-factor code from your setup key. Codes refresh automatically and your key stays on this device.
Loading authenticator…
Privacy & draft storage
Tool input and output stay in your browser. Neither is uploaded or saved by the toolkit.
- Copy writes only the current code to your device’s clipboard.
- Switching tools or returning home keeps drafts in this tab’s memory. Passwords and setup keys are hidden when you return.
- Reloading or leaving the toolkit clears drafts. Nothing is saved to browser storage.
Clearing a tool does not erase a copy already on your clipboard or a file you saved. A dot beside a tool marks an edited draft.
How to use
AuthenticatorEnter a Base32 setup key or a TOTP otpauth link, or open a local QR image.
Match the account's algorithm, digit count and period. Link settings take precedence.
Read the current code or choose Copy. Codes refresh using your device clock.
Supported one-time codes
This tool generates time-based codes using TOTP (RFC 6238) (opens in a new tab) and Web Crypto HMAC.
- Defaults: SHA-1, six digits and 30 seconds.
- Other options: SHA-256, SHA-512, eight digits and supported refresh periods.
Counter-based HOTP links are not supported.
Temporary use, without a vault
Your setup key and generated codes stay in this tab’s memory. They are never uploaded or saved by the tool.
- Switching tools or returning home retains and hides the key.
- Clearing, reloading or leaving the toolkit removes it.
Keep a durable authenticator and recovery method. A setup key can generate future codes, so treat it as a secret.
QR images and clock accuracy
PNG, JPEG and WebP images are decoded locally, up to 10 MB and 25 megapixels.
Set your device clock automatically. An incorrect clock can produce codes the service rejects.
The example key is a public test fixture from RFC 6238, not a real account.