CSP Builder
Build and risk-score Content-Security-Policy headers visually.
OpenGenerate and verify TOTP codes with otpauth URIs - entirely in your browser. - runs entirely in your browser. Free, fast and private.
Use an existing authenticator secret or generate a sample.
Codes refresh on the period with clock-skew tolerance.
Copy the URI for authenticator apps.
Confirm MFA flows without leaving the browser.
You are wiring MFA and need to see the six-digit code for a known secret without locking a phone yet. TOTP Studio generates and verifies time-based one-time passwords and can work with otpauth URIs entirely in the browser.
Use it while implementing authenticator flows, recovering a lab account, or confirming that server and client share the same secret, period, and digit length. Clock skew is the usual failure: if codes fail, check device time sync before rotating secrets.
Pitfall: pasting production MFA secrets into any tool on a shared laptop. Prefer fixtures and staging secrets. QR Code Generator can render an otpauth URI for enrollment demos when appropriate.
Codes are derived with local HMAC-based TOTP logic in the page. The shared secret is not uploaded to OneDevToolkit to mint digits.
Related: QR Code Generator
Processes data instantly with no server round-trips.
Your data never leaves your browser. Nothing is uploaded.
Works in any modern browser. Nothing to download or install.
No limits, no sign-up, no credit card required.
Works on desktop, tablet and mobile devices.
Beautiful in both themes. Your preference is saved.
Keyboard shortcut
Generate expected TOTP values while building verify endpoints.
Confirm a base32 secret matches what your IdP enrolled.
Work from otpauth URIs during local enrollment tests.
Answers for this tool. For site-wide help, open the FAQ hub.
Generators and hashers run locally. Still, never paste production secrets into any site if your security policy forbids it.
Results live in page memory until you leave or clear. Favourites/history do not save password fields unless you explicitly store them in Vault.
When applicable, tools rely on Web Crypto or well-known libraries. Read on-page notes for exact algorithms (SHA-256, bcrypt-style notes, etc.).
After load, crypto helpers typically work offline. Confirm network independence for your threat model.
Browser CSPRNG (crypto.getRandomValues) powers secure generators when the tool states so.
Treat generated secrets like passwords - share only through approved password managers, never chat apps.
OneDevToolkit aids technical workflows; it is not a certification product. See Compliance for processing model language.
Always check you are on your real OneDevToolkit domain before entering sensitive material.
Contact us via Contact with responsible-disclosure details - do not include live production secrets.