Secret Key to 2FA Code: Generate TOTP Codes Online for Any Account

A 2FA secret key is the text a service shows you when you set up an authenticator app. 2FA Auth turns that key – or the QR code that contains it – into the same 6-digit TOTP code your phone app would show, right in your browser. This page explains how to convert a secret key to a code, which accounts it works with (and three popular ones it cannot work with), and what to do when a code is rejected.

Last updated: October 8, 2026

How to get a 2FA code from a secret key online

  1. Find the secret key. In the account’s security settings, choose authenticator-app two-factor authentication. When the QR code appears, look for a link such as “can’t scan the QR code” or “enter the key manually” to reveal the key. The wording differs from service to service.
  2. Enter it in 2FA Auth. Open the online 2FA authenticator and paste the key. If you only have the QR code, press “Scan QR” or paste the otpauth:// link instead. Spaces, dashes and lowercase letters are fine.
  3. Read the code. A 6-digit code appears with a 30-second countdown and refreshes by itself. Type the current code into the service to finish setup or to sign in.
  4. Keep the key safe. Store the secret key and the service’s backup codes offline. This site does not keep your key and cannot restore it.

That is all “converting a secret key to a TOTP code” means: the key and the current time go through the standard TOTP calculation (RFC 6238), and the result is the code any other authenticator would show for the same key. What is TOTP explains the calculation, and what is a 2FA key explains the key.

Which accounts work with a secret key 2FA code generator?

Every service that offers authenticator-app 2FA uses the same standard TOTP codes, so one generator fits all of them. Popular examples:

Type of accountExamples
Social and communityFacebook, Instagram, Discord, X (Twitter), LinkedIn, Reddit, Twitch
Crypto exchangesBinance, Coinbase, Kraken, Bybit, OKX, KuCoin
Big tech, payments and shoppingGoogle, Microsoft, Amazon, PayPal, Shopify
Developer and cloudGitHub, Cloudflare, DigitalOcean
GamesEpic Games

So the same tool can act as a Facebook 2FA code generator, an Instagram or Discord authenticator code generator, a GitHub TOTP generator or a Binance 2FA code generator. The generator does not know which site a key belongs to, and it does not need to.

Availability, wording and regional rules change, so confirm in the service’s own security settings that authenticator-app 2FA is offered for your account. All names above belong to their respective owners; 2FA Auth is not affiliated with them.

Popular accounts it cannot work with

Generate 2FA codes without a phone or an authenticator app

If you already have the secret key, you do not need your phone. A code can be calculated on a PC, laptop or desktop, in the browser, with nothing to install and no browser extension. That helps when your phone is broken or out of reach, and when you want to check that a key works before you finish setting up an account.

Two limits matter. The key is shown only when 2FA is set up, so if you did not save it, this tool cannot recover it – use the service’s backup codes or account recovery instead. And an online tool lives in a web page, which is more exposed than a locked phone, so read the security and privacy page and use a device you trust.

Testing a key. Generate a code here and compare it with the code from another authenticator that holds the same key; the two should match every 30 seconds. Developers can use the same approach to compare their own TOTP implementation with standard RFC 6238 output (SHA-1, 6 digits, 30 seconds). 2FA Auth is a generator, not a validator, and it does not contact your server.

A browser-based, client-side TOTP generator

2FA Auth is a web based authenticator: the code is calculated locally with the Web Crypto API (HMAC-SHA-1), following RFC 6238. It should work in current versions of Chrome, Edge, Firefox and Safari on a PC, laptop, tablet or phone. There is no account, no sign-up and no extension to install.

What 2FA Auth supports – and what it does not

FeatureStatus
Base32 secret key (letters A–Z and digits 2–7)Supported
otpauth:// link or QR codeSupported (camera scan or paste)
Google Authenticator “export accounts” QR codeSupported for the first account only
TOTP with SHA-1, 6 digits, 30 seconds (the RFC 6238 defaults)Supported
SHA-256 or SHA-512, 8 digits, other time periodsNot supported – if a link or QR code asks for them, the tool says so instead of showing a wrong code
HOTP (counter-based) codesNot supported
Steam Guard codesNot supported
Several or saved accountsNot supported – one key at a time, nothing is stored
Checking a code against a serviceNot supported

Why is my 2FA code not working? Fix an invalid or rejected code

  1. Check your device clock. TOTP codes depend on the time, so a clock that is a minute or two off causes rejected codes. Turn on automatic date and time, then try again.
  2. Type the code before it expires. A code lasts about 30 seconds. If the countdown is nearly over, wait for the next code.
  3. Check the key. A Base32 key uses only the letters A–Z and the digits 2–7, so a 0, 1, 8 or 9 means a typing or copy error. Paste the key instead of retyping it, and make sure you copied all of it.
  4. Use the key from the latest setup. If you set up 2FA again, the service issues a new key and the old one stops working.
  5. Check the service’s settings. Some services use SHA-256, 8 digits or another time period, which 2FA Auth does not support.
  6. Check that the service uses authenticator codes at all. WhatsApp, Apple Account and Steam do not (see above).

Still stuck? Use the service’s backup codes or account recovery – a generator cannot bypass 2FA. The step-by-step guide covers more troubleshooting.

2FA Auth, authenticator apps and other online tools

Authenticator apps such as Google Authenticator, Microsoft Authenticator, Authy, FreeOTP, Aegis and 2FAS keep your keys on your phone, and features like app lock, backup and sync depend on the app, so check each app’s own documentation. For daily sign-ins an app is usually the safer choice. An online generator like 2FA Auth is handy when you are at a computer, need a quick code, or want to check a key without installing anything. The TOTP codes are the same, and many people use both.

Other online tools exist, for example 2fa.live, 2fa-live.com, 2facter.com and authenticator.cc. We do not review them here. Whichever one you use, compare what each site says about how it handles your key, whether it loads ads or third-party scripts, and whether its code is open to inspection – before you paste a secret.

Frequently asked questions

How to generate OTP from a Base32 secret?

Paste the Base32 secret into 2FA Auth. It decodes the key and runs the standard TOTP calculation (HMAC-SHA-1, 6 digits, 30 seconds) in your browser, and the result is the one-time password your authenticator app would show for the same key.

What is a TOTP secret key?

It is the shared secret that you and the service both store. Together with the current time it produces your 6-digit codes. Anyone who has the key can generate your codes, so treat it like a password. See what is a 2FA key.

What is a Base32 2FA secret?

Base32 is a way of writing the secret using only the letters A–Z and the digits 2–7, which makes it easy to read and type. Services usually show it in groups of four characters, for example when you choose to enter the key manually instead of scanning a QR code.

Is a 2FA secret key the same as the QR code?

They carry the same secret. The QR code contains an otpauth:// link with the Base32 secret key plus settings such as issuer, digits and period. The text key is the manual alternative to scanning.

What information is in a TOTP QR code?

An otpauth:// link: the type (totp), a label such as the account name, the secret, the issuer, and optional settings such as algorithm, digits and period. Treat a QR code like a key and do not upload it to sites you do not trust.

How to get the secret from a TOTP QR code?

You do not need to read it yourself: press “Scan QR” in 2FA Auth and the camera image is decoded in your browser. To see the key as text, use the “can’t scan the QR code” or manual-entry option in the service’s 2FA setup, if it offers one.

How to set up 2FA with a secret key instead of scanning a QR code?

In the service’s 2FA setup, choose the authenticator-app method, pick the manual-entry option, copy the key, enter it in your authenticator (or in 2FA Auth), and confirm with the first 6-digit code. The names differ between services, but the QR code and the key hold the same secret.

How to generate TOTP without a phone or authenticator app?

Paste the secret key into 2FA Auth in any browser. The code is calculated on your computer, so you do not need the phone that holds your authenticator app. You do still need the key itself, which the service shows only when you set up 2FA.

How to generate 2FA codes on a computer in Chrome, Firefox or Edge?

Open 2fauth.online in a current browser on Windows, macOS or Linux, paste the key and read the code. There is no extension to install and nothing to download, and the same page works on a phone.

Can I use a browser as an authenticator?

Yes. TOTP only needs the key, the clock and a hash function, and modern browsers include one through the Web Crypto API. The trade-off is exposure: a web page is more open to malware and extensions than a locked phone, so read the security page.

Can I use 2FA without an authenticator app?

Often yes. Many services also offer text-message or email codes, hardware security keys or passkeys, and the authenticator-app codes themselves can come from any tool that implements TOTP, including a browser-based one. Text messages are generally considered the weakest of these options.

How long is a TOTP code valid, and why does it change?

Usually 30 seconds. The code is calculated from the secret key and the current 30-second time step, so it changes whenever the step changes. Some services also accept the previous or next code to allow for small clock differences. See what is TOTP for the full picture.

Why do authenticator codes expire every 30 seconds?

A short life limits how long a stolen or intercepted code is useful. Thirty seconds is the default time step in the TOTP standard (RFC 6238); a few services use a different period.

What happens when a TOTP code expires?

Nothing breaks. The next code is calculated automatically and the old one stops working, although some services still accept the previous code for a short time.

Why are TOTP codes 6 digits?

Six digits is the common default: short enough to type quickly, and combined with the short validity and the limits services put on wrong attempts. Some services use eight digits, which 2FA Auth does not support.

Does TOTP need an internet connection?

Calculating a code needs only the key and your device clock, which is why authenticator apps keep working without a signal. 2FA Auth is a web page, so it has to load first; after that, calculating a code does not contact a server. Browsers without built-in QR detection load a small helper library the first time you scan a QR code.

What is the difference between OTP, TOTP and HOTP?

OTP is the general term for a one-time password. TOTP is time-based and HOTP is counter-based. 2FA Auth generates TOTP codes only; the TOTP vs HOTP comparison explains the difference.

What is the difference between 2FA and TOTP?

2FA is the idea of proving who you are with two different things. TOTP is one way to do the second step, using a time-based code. Others include text messages, hardware security keys and passkeys. What is 2FA compares them.

What is the difference between TOTP and an authenticator app?

TOTP is the algorithm. An authenticator app is software that stores keys and runs it for you. A browser-based tool such as 2FA Auth can run the same algorithm, so the codes match.

Is it safe to enter a 2FA secret key online?

The calculation happens in your browser and this site’s code does not transmit your key. Still, anyone who obtains a secret key can generate your codes, and a web page is more exposed than a locked phone to malware, browser extensions and shared screens. Use a device you trust, avoid public computers, check that the address is 2fauth.online and keep recovery options for important accounts. Details are on the security and privacy page.

Can I recover a lost TOTP secret key?

No. The service shows the key only when you set up 2FA, and 2FA Auth does not store it. Use the service’s backup codes or account recovery, and when you set 2FA up again, save the new key somewhere safe and offline.

Why is my 2FA secret key not working?

Usually the key was mistyped or is from an older setup, the device clock is off, or the service uses settings 2FA Auth does not support. Work through the fix list above.

Can I use it for several accounts or for client accounts?

2FA Auth works with one key at a time and does not save accounts, so it is not an account manager. For many accounts, such as agency or business accounts, use a tool designed to store and share keys securely and decide carefully who holds each key. For a single quick code, paste the key here.

How do I get a Facebook, Instagram, Discord or Google 2FA code online?

Choose the authenticator-app option in the account’s security settings, reveal the setup key, and paste it into 2FA Auth to get the same 6-digit code. The same steps apply to X, LinkedIn, GitHub, Microsoft and most other accounts in the list above.

How do I generate a TOTP code for a crypto exchange account?

Pick the authenticator-app option (often labelled “Google Authenticator”) in the exchange’s security settings, copy the setup key and paste it here. Exchange accounts hold money, so keep the key and backup codes offline, use a device you trust, and turn on stronger options such as hardware security keys or passkeys where they are offered. Wording and rules differ by exchange and region.