Generate RFC 6238 6-digit one-time passwords from Base32 secret keys with live 30s countdown.
Execution runs 100% locally inside the browser sandbox using HTML5 Canvas, Web Cryptography Subtle API, and Web Workers. Zero egress.
Zero network latency. Operates completely offline with zero dependencies on third-party backend servers or cloud services.
Built according to official RFC specifications, cryptographic test vectors, and enterprise-grade data transformation standards.
Type or paste your 16+ character 2FA secret key.
View the active 6-digit token computed from your local system clock.
Click to copy the 6-digit code before the 30-second window expires.
Yes, HMAC-SHA1 calculations run entirely in local browser RAM using Web Crypto Subtle API with zero network egress.
Yes, standard Base32 secret keys used by Google Authenticator, 1Password, and Authy are 100% compatible.
Zero-egress companion tools in the Security & Network suite
Measure cryptographic randomness, Shannon entropy (0-8 bits/byte), Chi-square test, and byte distributions.
Brute-force all 256 single-byte XOR keys with automated English frequency & chi-squared scoring.
Audit CSP, HSTS, X-Frame-Options, and security headers with OWASP grading (A+ to F).
Compare memory hardness, GPU ASIC resistance, and security parameters across KDF standards.