2FA / TOTP Secret & QR Generator

CMP Consulting Services · runs entirely in your browser

Generate a random Base32 secret and a scannable QR code for time-based one-time passwords (TOTP, RFC 6238). Enter the issuer and account, and scan the QR with Microsoft Authenticator or any compatible app.

Nothing here leaves this computer. The secret is generated on your own PC by your browser — using its built-in cryptographic random number generator — not on the web server. The server only ever sends you this page; it never sees, receives, or produces a secret. Nothing you generate or type here is recorded, logged, stored, or transmitted anywhere: no server, no database, no analytics, no third parties. The page makes no network calls at all after it loads, and every value disappears when you close the tab. Verify it yourself: disconnect from the network and the tool still works.

1. Secret

A random Base32 key, or paste your own.

32 characters is the RFC 6238 recommended strength and works with every authenticator app. Choose a different length only if your identity provider requires it.

2. Account details

Both are required. They are embedded in the QR code and become the name of the entry in the authenticator app.

The bold top line of the entry. Name the system this code unlocks — the company, application, or portal (e.g. CMP VPN, Microsoft 365) — so the user can tell at a glance which login it belongs to.

Issuer is required.

The smaller second line. Use the username or email address this secret belongs to, so someone with several accounts on the same service can tell them apart.

Account is required.

Use a unique Issuer + Account pair. Authenticator apps identify an entry by these two values together. If they exactly match an entry already on the user's device, scanning this QR can overwrite that entry — and the old secret is unrecoverable, locking them out of whatever it protected. If the person already has a code for this service, vary the issuer or account (e.g. CMP VPN (new)) before they scan.

3. QR code

Scan with your authenticator app.

Enter an Issuer and an Account to generate the QR code.

How it will look on the phone

Will display as below in TOTP key holders like Microsoft Authenticator, Google Authenticator, Keeper, Authy, 1Password, and Duo.

Your Issuer
— — —
30s

This is the live code for the secret above — computed in your browser and refreshing every 30 seconds, exactly matching what the authenticator app will show once scanned. Use it to confirm the enrollment worked.

How to use it

  1. Open your authenticator app and choose Add / Scan QR.
  2. Scan the code above (or type the secret manually).
  3. Store the secret securely in your identity provider / backend to verify the 6-digit codes.

Get Microsoft Authenticator

Point the phone's camera at the code below to open the store listing. The QR is drawn on this computer, so it works with no internet connection.

App Store

Scan with the iPhone or iPad Camera app, then tap the banner that appears to open the App Store.

Open this listing in a browser