RFC 6238 TOTP 2FA Token Generator & Clock Drift Validator
Test Two-Factor Authentication (2FA) OTP tokens in your browser. Inspect Base32 secret keys, simulate 30-second time-step windows, test HMAC-SHA1/SHA256 algorithms, and validate client-server clock drift tolerance.Documentation & FAQs ↓
Clock Drift Verification Window
RFC 6238 authenticators tolerate ±1 step (±30s) clock synchronization skew between server and client.
Authenticator URI & App Pairing
Standard Key URI format supported by Google Authenticator, 1Password, Bitwarden, Authy, and Apple Passwords.
otpauth://totp/AnshuTechy:user%40anshutechy.com?secret=JBSWY3DPEHPK3PXP&issuer=AnshuTechy&algorithm=SHA1&digits=6&period=30
100% Client-Side. Secret never leaves your browser sandbox.
Step-by-Step Instructions
4 Steps to CompletionEnter your Base32 secret key (e.g., JBSWY3DPEHPK3PXP) or generate a cryptographically random test seed.
Select token parameters: 6 or 8 digits, 30-second time step, and HMAC-SHA1 (standard) or HMAC-SHA256.
Watch the live token count down in real-time with an interactive circular progress gauge.
Simulate client clock drift (-60s to +60s) to verify verification window tolerance in your backend.
Practical Use Cases & Real-World Scenarios
RFC 6238 Engine
Complies strictly with RFC 6238 (TOTP) and RFC 4226 (HOTP) using browser Web Crypto API HMAC primitives.
Base32 Key Decoder & Sanitizer
Parses standard Base32 secret keys (with or without spaces/padding) and displays raw hex byte structures.
Clock Drift Window Tolerance
Validates tokens across ±1 and ±2 time steps (±30s to ±60s) to diagnose smartphone clock desynchronization errors.
Algorithm & Digit Configuration
Supports 6-digit and 8-digit codes, 30s and 60s step intervals, and HMAC-SHA1, SHA256, and SHA512 hashing.
Frequently Asked Questions
How does RFC 6238 TOTP generate a 6-digit 2FA code?↓
Why do Google Authenticator codes fail if phone time is wrong by 1 minute?↓
What is the standard clock drift tolerance window on production servers?↓
Are Base32 secret keys case-sensitive?↓
Why do most authenticator apps still use HMAC-SHA1 instead of SHA256?↓
10 Best Authenticator Apps for Android and iPhone in 2026
Dive deeper into the foundational technical concepts behind this tool on our editorial blog. Includes comprehensive hardware benchmarks, case studies, and best practices.
Found this tool helpful? Share it with colleagues & friends:
100% free, private in-browser utility with zero server uploads.
