Turn a two-factor secret into the six-digit code a site is asking for. Calculated in your browser and never stored.
The text version of the QR code your site showed when you set up two-factor authentication. Spaces are ignored.
••• •••
Paste a key to see your code
Codes are calculated in your browser from the key and your clock. Nothing is sent anywhere and nothing is saved between visits — keep your phone app as the everyday method, since a separate device is what makes two-factor authentication work.
Two-factor codes are calculated from a secret key and the current time, which is why they change every thirty seconds and why they work without an internet connection.
When a site sets up two-factor authentication it shows a QR code, with a link revealing the key as text for people who cannot scan it. That string is what you need.
The current code appears immediately, along with a countdown showing how long it remains valid.
Copy the code into the site that asked for it. A new one is generated automatically every thirty seconds.
A stopgap rather than a replacement for an app on your phone.
Get into an account when your phone is flat, lost or somewhere else.
Check that a newly configured two-factor secret produces working codes.
Generate codes against a test account without configuring a phone app for it.
Let whoever holds the key produce a code when the account is not tied to one person.
Verify a key still works while moving between authenticator applications.
See how a secret and a clock combine to produce the codes you type every day.
Two-factor authentication works because the second factor lives somewhere separate. Keep that in mind.
How TOTP codes work and when to use this instead of an app.
An app that generates a short code, changing every 30 seconds, as a second step when you log in. Because the code comes from a secret held on your device rather than a text message, it cannot be intercepted by SIM swapping.
Other things you can do here without signing up.