Home/Tools/2FA Code Generator

2FA Code Generator

Paste a 2FA secret key, get the live 6-digit code, and share access with a private link. Runs entirely in your browser.

Shared access loaded from your link. Codes below are live.

Your 2FA details?Everything is computed in this browser tab using the Web Crypto API. The key is never uploaded, never logged and never saved.

Advanced settings

Share access?The link produces the same codes on anyone's device. The secret travels after the # in the URL, a part browsers never send to a web server, so it stays off logs and referrers.

The link carries the secret itself and cannot be revoked.?Share carefullyAnyone holding the link can generate codes forever. Send it through a private channel only, never a public page, ticket or group chat. To cut access, turn 2FA off and on again at the service so a fresh secret is issued.
2F No service yet
------ --
?Codes come from your device clock. If one is rejected, set your system time to sync automatically. Check Advanced settings if the service uses 8 digits or a 60-second refresh.
Before you share a link
  • The link contains the secret key itself, so anyone holding it can generate codes forever.
  • It cannot be revoked. To cut access, turn 2FA off and on again at the service so a fresh secret is issued.
  • Send it through a private channel. Never paste it into a public page, ticket or group chat.
  • The secret sits after the # in the URL, which browsers never transmit to a web server.

How to use it

Three steps, no account, nothing leaves your browser.

1

Copy your secret key

When a service shows a 2FA QR code, choose "enter code manually". The string it reveals is your secret key.

2

Paste it here

Add the service name so you can tell codes apart. The live code appears immediately and refreshes on its own.

3

Share if you need to

Create a link and send it privately to a colleague. They get the codes without ever getting your password.

Questions about 2FA codes

Is my secret key sent anywhere?
No. The code is computed in your browser with the built-in Web Crypto API. The key is never uploaded, never logged, and is not saved between visits unless you create a share link and keep that link yourself.
How does the share link work?
The key and labels are packed into the part of the URL after the #. Browsers never transmit that portion to a web server, so the secret stays on the two devices that hold the link. Opening it loads the same tool with the code already running.
Can I take the link back once I have sent it?
No. A share link cannot be revoked, because it contains the secret itself rather than a permission you can switch off. To cut access, turn 2FA off and on again at the service, which issues a fresh secret and makes every old link useless.
My code is being rejected. What is wrong?
Almost always the device clock. TOTP codes are derived from the current time, so a device that is more than about 30 seconds out will produce codes the server refuses. Set your clock to sync automatically and try again. Also check whether the service uses 8 digits or a 60-second refresh, both of which are in Advanced settings.
Does this replace my authenticator app?
It can, but it is best treated as a convenience and a sharing tool rather than your only copy. Keep the secret or the service's recovery codes somewhere safe, exactly as you would with an app.

Related tools

More utilities landing shortly.