TOTP Token Generator logoTOTP Token Generator
Zero-Knowledge Offline Vault

TOTP Token Generator — encrypted codes, generated on your device

TOTP Token Generator is a browser authenticator built around one rule: your secrets never leave this device in readable form. Add a token, and it is encrypted with AES-256-GCM using a key derived from a master password only you know. The vault lives in local IndexedDB, the codes come from WebCrypto, and there is no account, no sync, and no server-side copy to breach.

How TOTP Token Generator works

1Step 1

Set a master password

On first visit you choose the password that protects the vault. It is stretched with a deliberately slow key-derivation function, and the resulting key never leaves memory. If you forget it, the vault stays locked for good — there is no reset link, because a reset path would also be an attack path.

2Step 2

Add your tokens

Scan an otpauth QR code, paste otpauth:// links in bulk, or type a Base32 secret by hand. Every token is encrypted before it touches storage, so the raw secret is never written to disk in readable form.

3Step 3

Copy a code when you need one

Codes rotate on the standard RFC 6238 time step. Click a card to copy the current digits, and watch the ring before a step boundary. Because the maths runs on your device, the same code appears whether you are online or offline.

What is in the vault

Encrypted at rest

The whole vault is sealed with AES-256-GCM. Only the salt and iteration count are readable, which is exactly what you would need to unlock it — and nothing more.

Standards-first TOTP

RFC 6238 time-based codes with SHA-1, SHA-256 or SHA-512, 6 or 8 digits, and 30 or 60 second periods — verified against the RFC's own test vectors so the codes match what every other authenticator expects.

Local QR scanning

Scan otpauth QR codes with the camera. Frames are decoded on a local canvas and are never uploaded anywhere, so a picture of your screen never leaves the device.

Tags, favorites and search

Organise tokens with tags, pin the ones you use most, and filter down to a single service as the vault grows from a handful of logins to dozens.

Portable in both directions

Export an encrypted backup that only your master password can open, or copy plain otpauth:// links to move into another authenticator. Nothing about the vault is a lock-in.

Works offline

Once the page is loaded, generating codes needs no network at all — useful on a plane, in a basement, or on a network you do not trust.

The security model, stated plainly

TOTP Token Generator has no server component. Nothing is uploaded, so no database of secrets exists to leak — the only copy of your vault is the encrypted record sitting in your browser's storage. That single design choice removes whole classes of risk: no token server to breach, no sync account to phish, and no plaintext secret in transit.

Cipher
AES-GCM-256
Authenticated encryption; tampering with the ciphertext makes decryption fail rather than returning wrong data.
Key derivation
PBKDF2-HMAC-SHA-256
600,000 iterations with a random per-vault salt, raising the cost of guessing your master password.
Key lifetime
Memory only
The derived key is non-extractable and is discarded when the vault locks, the tab closes, or you reload.

AES-GCM-256 · PBKDF2-HMAC-SHA-256

Frequently asked questions

What is a TOTP token generator?+
A TOTP token generator is a tool that turns a shared secret into a short, time-based one-time password using the RFC 6238 algorithm. Every thirty seconds it derives a fresh six- or eight-digit code from that secret and the current time, which you type in as the second factor when you sign in. TOTP Token Generator performs that calculation in your browser instead of on a phone app or a server.
Which services work with this TOTP token generator?+
Any service that supports standard TOTP two-factor authentication will accept the codes, which covers most major platforms: GitHub, Google, Microsoft, AWS, Dropbox, Cloudflare and thousands more. As long as the service shows an otpauth:// QR code or a Base32 secret during setup, you can add it here and the generated codes stay interchangeable with those from any other authenticator.
Is a browser-based TOTP token generator safe?+
A browser-based TOTP token generator can be as safe as a native app, provided the secrets are encrypted and never leave the device — which is how this one is built. The honest trade-off is attack surface: a web page is more exposed to malicious extensions and injected scripts than a dedicated app. Keep your browser clean and extensions minimal, and the encryption at rest makes the vault far harder to lift than an unencrypted app database.
How does TOTP Token Generator compare with Google Authenticator or Authy?+
All three generate the same standards-based TOTP codes, so the codes are interchangeable. The differences are where the secrets live and who can reach them. Google Authenticator and Authy keep secrets on the phone or in a vendor cloud; TOTP Token Generator keeps an AES-256-GCM encrypted vault in your own browser storage and never transmits it. That means no vendor account and no cloud copy — but also no automatic cross-device sync, which you replace with an encrypted backup you control.
Can I use TOTP Token Generator on more than one device?+
Yes, but by design there is no automatic sync. Each device keeps its own encrypted vault, and you move tokens between them with an encrypted backup: export on one device, import on the other, and unlock with the same master password. Because the backup is ciphertext, you can move it through cloud storage or email without exposing your secrets — though exporting plain otpauth:// links is best kept off the network entirely.
What happens if I forget my master password?+
The vault becomes unreadable, permanently. The key is derived from your password and never stored anywhere, so neither we nor anyone else can reset it. This is the trade-off that makes the vault safe: if a recovery path existed, it would also be an attack path.
Do you store or transmit my secrets?+
No. There is no API, no database and no account. Codes are computed locally with the WebCrypto API, and the encrypted vault is written to your browser's IndexedDB. The only network requests the page makes are for its own assets, fonts and analytics.
Is this as safe as a native authenticator app?+
It uses the same standards and the same cryptographic primitives, and it adds encryption at rest that most native apps do not have. The honest caveat is attack surface: a browser page is more exposed to malicious extensions and injected scripts than a dedicated app, so keep your browser clean and extensions minimal.
How do I move my tokens to another authenticator?+
Use Import/Export to copy plain otpauth:// links, which most authenticator apps can import. Remember that those links contain your unencrypted secrets, so treat the clipboard carefully and clear it afterwards.
Why do the codes sometimes fail on a fresh device?+
TOTP depends on your clock. TOTP Token Generator shows the measured offset against the server clock at the bottom of the page — if it is off by more than a few seconds, synchronise your system time.
Does it work offline, and can I install it?+
Yes to both. The page is a PWA, so it can be installed and opened without a network. Code generation never needs a round trip.