Runs in your browser
Codes are calculated locally with the Web Crypto API. The site’s code does not send your secret key anywhere.
Your 2FA code is calculated locally in your browser with the Web Crypto API. Use this tool only on a device you trust and keep your own copy of the secret key – it is not saved here. How the site handles your key.
When you turn on two-factor authentication for an account, choose “Authenticator app”. The service shows a QR code and a text setup key – your 2FA secret key.
Paste the key or an otpauth:// link into the field above, or press “Scan QR” and show the QR code to your camera.
A 6-digit code appears and refreshes every 30 seconds. Copy it, type it into the website, and you are verified.
Codes are calculated locally with the Web Crypto API. The site’s code does not send your secret key anywhere.
Point your camera at a QR code or paste an otpauth:// link – the key is extracted automatically.
Uses the same open TOTP standard (RFC 6238) as authenticator apps: 6 digits, refreshed every 30 seconds, so the codes match.
One tap puts the code on your clipboard. The refresh button shows the next code instantly.
There is nothing to sign up for. Open the page, get your code and close the tab.
Works in a modern desktop or mobile browser, which is useful on a new device or when your phone is not at hand.
2FA Auth is built to keep things minimal. The site has no login or user accounts, and no database of authenticator data. Your secret key and codes exist only in the open page: reload or close it and they are gone. The only thing the site stores in your browser is your language choice.
Some third-party resources do load – fonts from Google Fonts, a QR-decoding library from a CDN when you scan, and Google AdSense if ads are switched on – and your hosting provider may keep standard server logs. We list all of this in the security and privacy overview and the privacy policy.
The menu names differ, but the path is almost always the same:
Want screenshots-free detail and troubleshooting? Read the full guide to using a 2FA authenticator.
A 2FA code is a one-time 6-digit password that changes every 30 seconds. It is calculated from a Base32 secret key that a service gives you when you enable two-factor authentication. See what a 2FA key is for the details.
Codes are calculated in your browser, and the site's code does not transmit your key. Still, an online tool can never be as isolated as a dedicated app on a locked phone, so use it only on a device you trust, never on a shared computer. Read the security and privacy details.
The algorithm is the same (TOTP), so the codes match. There is nothing to install here, but the page does not keep your key between visits, so you are responsible for storing it.
Check the key and your device clock: a drift of more than 30 seconds produces wrong codes. Make sure the key was copied completely and that you enter the current code before it expires. The troubleshooting steps cover more cases.
No. The site has no accounts or login. You paste a key or scan a QR code, get your code and close the tab. Because nothing is saved for you, keep your secret key somewhere safe, such as a password manager.
A 2FA authenticator is an app or tool that generates the one-time verification codes used in two-factor authentication. Instead of waiting for a text message you read a fresh code from the authenticator and type it in after your password. 2FA Auth does this in your browser. More in what is 2FA.
Both produce the same TOTP codes. An app stores your keys on your phone. An online authenticator runs in a browser tab: nothing to install and handy on a computer or a new device, but it does not save your keys, and a web page is more exposed to browser extensions and shared computers. Many people use an app for daily sign-ins and an online tool for quick checks or recovery.
Standard 6-digit, 30-second TOTP codes using SHA-1, which is what most websites and authenticator apps use. If a service uses other settings, such as 8 digits or SHA-256, the tool tells you it is not supported. See what is TOTP.
No. Hardware security keys (FIDO2/WebAuthn, usually USB or NFC) are a different method. 2FA Auth generates time-based codes from a secret key. The 2FA key explainer shows how the two differ.
Two-factor authentication explained, with the main types compared.
Secret setup key, security key or backup code – what each one is.
How a secret and the clock become a 6-digit code.
Step-by-step guide with troubleshooting.
Which accounts it works with, what it supports and how to fix rejected codes.