TOTP URI Generator
Generate an otpauth TOTP URI from an issuer, account and secret for setting up two-factor authentication in authenticator apps.
Last reviewed by the Radiatus Cloud team
Generate an otpauth TOTP URI for authenticator app two-factor setup.
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
Generate a TOTP setup URI
When you set up two-factor authentication with an app like Google Authenticator or Authy, the app usually reads a QR code that encodes an otpauth URI. This generator builds that URI from the pieces it contains: the issuer name of your service, the user account, the shared Base32 secret, the number of digits in the code, and the time period. Encoding this URI as a QR code lets an authenticator app add the account and begin generating time-based one-time passwords.
The URI follows the widely supported otpauth standard for time-based one-time passwords, or TOTP.
How TOTP enrolment works
Time-based one-time passwords are generated from a secret shared between the server and the authenticator app, combined with the current time, so both sides compute the same six-digit code that changes every thirty seconds. The otpauth URI is how that secret and its parameters are handed to the app during setup. The secret must be kept confidential, since anyone with it can generate valid codes.
This tool creates the URI only; turn it into a scannable QR code with a QR generator, and keep the secret secure. The default SHA1 algorithm and thirty-second period are the standard values most apps expect. All generation happens locally in your browser.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
What is an otpauth URI?
It is the standard string, usually encoded in a QR code, that an authenticator app reads to set up a two-factor account with its secret and parameters.
What is the secret?
It is the Base32-encoded shared key the server and app both use, combined with the time, to compute matching one-time codes.
How do I turn the URI into a QR code?
Paste it into a QR code generator. The resulting QR can be scanned by an authenticator app to add the account.
What are the standard settings?
Six digits, a thirty-second period and the SHA1 algorithm are the defaults almost all authenticator apps expect for TOTP.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Enter the issuer, account and Base32 secret to build the otpauth URI.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.