Uses
- Developers testing two-factor login in their own apps.
- Creating a secret and QR code for a new 2FA setup.
- Checking that a server’s clock and an authenticator agree.
Never paste the 2FA secret of a real account into a website you do not trust — anyone with the secret can generate your codes. Here, codes are calculated only in your browser.
Frequently asked questions
Why does my code not match?
Check the device clock (it must be accurate to within ~30 seconds) and the digits, period and algorithm settings.
Which apps support the QR code?
Google Authenticator, Microsoft Authenticator, Authy, 1Password, Bitwarden and others.
Is the secret stored?
No.

