Skip to content

NO TRUST

Trust nothing – Verify everything

TOTP Tester

Authenticator lab

TOTP Tester

Generate, inspect, and verify TOTP codes locally. Secrets stay in this browser tab.

Web Crypto No server secrets
Default settingsSHA-256, 6-digit codes, 30-second lifetime
AlgorithmsSHA-1, SHA-256, SHA-512
VerificationCurrent code +/- 1 refresh window
PrivacyBrowser only

Secret and Profile

Current Code

——
Waiting

Enter a secret or generate one.

Verify Code

No code checked yet.
Authenticator setup URI Optional otpauth string for local QR workflows

Use this with a local QR generator if needed. The Suite intentionally does not call third-party QR services.

Use TOTP Carefully

TOTP codes are useful for testing flows, but the seed secret is the part that needs real protection.

Secret vs code

Your code expires. Your secret doesn’t. Protect the secret, and the codes will take care of themselves.

Clock drift

Before blaming the secret, make sure your clock is correct. Time is part of how TOTP works.

QR setup

A QR code is just another way to share your secret. Local is best. Random websites are not.

Best Practice

Test here. Protect everywhere. Only use real MFA secrets on devices and browsers you trust.

Local only Web Crypto No server secrets Nothing stored