Generate the current RFC 6238 time-based one-time password from a base32 secret, and show how many seconds it has left.
TOTP Generator is one page doing one thing. No account, no settings to sync, no history building up somewhere.
No server sees this. That is a consequence of how the tool is built rather than a policy someone wrote down, which is the version worth trusting.
You will find it under Developer tools, alongside 11 other tools for the same sort of job.
Runs in this tab, so nothing you type is uploaded.
secret: GEZDGNBVGY3TQOJQGEZDGNBVGY3TQOJQ timestampSeconds: 59
Code: 287082 Seconds remaining: 1 Period start: 30 Period end: 60
Yes. It is JavaScript running in this tab, so once the page has loaded it needs nothing further from the network. Put the machine in flight mode and it carries on. Nothing you do here is sent anywhere, because there is nowhere for it to go.
No. Reload the page and it starts from nothing. There is no account, no saved state and no cookie holding your last session. That is a deliberate trade: it cannot lose your data because it never keeps any.
Timing comes from performance.now(), the high resolution clock the browser provides, rather than from setInterval, which drifts by a few milliseconds every tick and compounds over minutes. What can still shift things is the browser throttling a tab in the background, so leave it visible if the timing matters.
Where a sound makes sense, it is generated with the Web Audio API rather than loaded as a file, so there is nothing to download and nothing to block. Browsers refuse to start audio until you have interacted with the page, which is why the first press is what switches it on.
Yes. The controls are sized for touch and the layout collapses to one column on a narrow screen. Bear in mind that a phone locking its screen will suspend the page, and timing stops with it.