2FA Code Generator

Generate TOTP two-factor codes from a Base32 secret — right in your browser.

Loza CRM·Updated: September 29, 2026

Quick answer

Paste your Base32 secret key to instantly get the current 6-digit TOTP code — it refreshes every 30 seconds. The tool runs entirely in your browser: the key is never uploaded or stored.

The key never leaves your browser — generation is fully local (RFC 6238).

How to use

  1. Paste the Base32 secret key — the text string shown next to the QR code when you set up 2FA
  2. The tool displays the current 6-digit TOTP code immediately
  3. The code refreshes every 30 seconds — copy the active value when you need it
  4. To switch accounts, just paste a different secret

Why you need it

TOTP (Time-based One-Time Password) is the standard behind Google Authenticator, Authy and similar apps: a 6-digit code derived from a shared secret and the current time, valid for a 30-second window. The algorithm is defined in RFC 6238, so any compliant generator produces identical codes for the same secret and timestamp.

Media buyers and affiliate teams often need a code without reaching for a phone: shared ad accounts, test profiles, backup access when a device is lost or the authenticator is tied to one person’s handset. This tool solves that — paste the Base32 secret and the current code appears instantly, synced with any other authenticator using the same key.

Everything runs client-side in your browser. The secret is never sent to a server, logged, or persisted — you can verify this in the Network tab. That makes the tool safe for working and test accounts, though you should still treat 2FA secrets as sensitive: anyone holding the key can generate valid codes.

Loza CRM computes these metrics for your campaigns automatically — try it free.

Open Loza CRM

FAQ

Is it safe to enter a 2FA secret in an online tool?
In this tool — yes: generation is 100% local, the key never leaves your browser. Still, treat secrets like passwords: only use them for work or test accounts you control.
Will the code match Google Authenticator?
Yes. TOTP is standardized (RFC 6238): the same secret and synced time produce the same code in every generator.
Where do I find the secret key?
When enabling 2FA, the service shows a QR code plus a text string — that string is the Base32 secret (letters A–Z and digits 2–7).
Why does the code get rejected?
Most often it’s clock drift on your device or a copy error — extra spaces or wrong characters break the key. The tool ignores spaces and case, but the secret itself must be valid Base32.
Does it work for Facebook or Google ad accounts?
Yes — any service that uses standard TOTP. Many affiliates use this for shared ad accounts where a single authenticator device is a bottleneck.

Other tools