Two Fa Code Tester API
https://api.findutils.com/api/tools/two-fa-code-tester/execute Compute the current TOTP code (RFC 6238) for a base32 secret and return the code, the seconds remaining in the window, and — when a code is supplied — whether it matches. Defaults match Google Authenticator: 6 digits, 30-second period, HMAC-SHA1. Pass "time" (unix seconds) to evaluate a specific moment.
Request body
application/json-
secret
string required
The base32 TOTP secret (e.g. JBSWY3DPEHPK3PXP). Spaces, dashes, and padding are ignored.
-
code
string optional
Optional code to verify against the computed one.
-
digits
integer optional
Number of digits. Default: 6. Default
6. -
period
integer optional
Time step in seconds. Default: 30. Default
30. -
time
integer optional
Unix timestamp (seconds) to compute the code for. Default: now.
-
algorithm
string optional
HMAC hash. Default: SHA-1. One of
SHA-1 · SHA-256 · SHA-512. Default"SHA-1".
Example arguments
Verified{
"secret": "JBSWY3DPEHPK3PXP"
} More Security tools
- Base32 Encode Encode UTF-8 text to RFC 4648 base32 (uppercase, "=" padding).
- Csp Generate Build a Content-Security-Policy header from a preset (strict, typical, google-analytics) and/or your own directives, and get the header…
- Data Sanitizer Sanitize untrusted text and return the cleaned output, a list of changes made, and a risk level.
- Dnpm Configurator Returns the five files of a hardened Docker-based npm wrapper (the ./dnpm bash script, .dnpm/Dockerfile, docker-compose.node.yml…
- Email Header Analyzer Return a structured analysis of raw email headers: sender, recipient, subject, date, message id, the Received hop chain with per-hop…
- Hash Comparison Tool Hash text with MD5, SHA-1, SHA-256, SHA-384, or SHA-512 and compare the hex digest with an expected hash.