Most authenticator apps use TOTP: a short code generated from a shared secret and the current time.

The OTP Generator tool gives me a safe place to test the idea before I put it into a script, server, or production workflow.

The simple mental model

Most authenticator apps use TOTP: a short code generated from a shared secret and the current time.

I try to reduce the tool to one question: what input do I have, what output do I expect, and what would make the result unsafe or misleading?

Step 1: Create or paste a test secret

Create or paste a test secret.

Start with a small example first. A small example is easier to inspect than a real production-sized case.

Step 2: Confirm the digit length and period, usually 6 digits every 30 seconds

Confirm the digit length and period, usually 6 digits every 30 seconds.

Step 3: Generate the current code

Generate the current code.

Step 4: Verify it using the same secret and time settings

Verify it using the same secret and time settings.

Step 5: If verification fails, check clock drift first

If verification fails, check clock drift first.

Step 6: Store recovery codes when enabling 2FA on real accounts

Store recovery codes when enabling 2FA on real accounts.

Step 7: Never share the OTP secret QR publicly

Never share the OTP secret QR publicly.

My checklist

Before I trust the result, I check:

  • Create or paste a test secret.
  • Confirm the digit length and period, usually 6 digits every 30 seconds.
  • Generate the current code.
  • Verify it using the same secret and time settings.
  • If verification fails, check clock drift first.
  • Store recovery codes when enabling 2FA on real accounts.
  • Never share the OTP secret QR publicly.

The tool saves time, but the important part is still understanding the input and reviewing the output before using it somewhere important.

Comments

Comments are welcome — please read the comment policy first. Powered by giscus and GitHub Discussions.