Skip to content

Two Fa Code Tester API

POST https://api.findutils.com/api/tools/two-fa-code-tester/execute

Compute the current TOTP code (RFC 6238) for a base32 secret and return the code, the seconds remaining in the window, and — when a code is supplied — whether it matches. Defaults match Google Authenticator: 6 digits, 30-second period, HMAC-SHA1. Pass "time" (unix seconds) to evaluate a specific moment.

Request body

application/json
  • secret

    string required

    The base32 TOTP secret (e.g. JBSWY3DPEHPK3PXP). Spaces, dashes, and padding are ignored.

  • code

    string optional

    Optional code to verify against the computed one.

  • digits

    integer optional

    Number of digits. Default: 6. Default 6.

  • period

    integer optional

    Time step in seconds. Default: 30. Default 30.

  • time

    integer optional

    Unix timestamp (seconds) to compute the code for. Default: now.

  • algorithm

    string optional

    HMAC hash. Default: SHA-1. One of SHA-1 · SHA-256 · SHA-512. Default "SHA-1".

Example arguments

Verified
{
  "secret": "JBSWY3DPEHPK3PXP"
}