Secret (Base32) or otpauth:// link
— — —
–
This generates time-based one-time passwords (TOTP, RFC 6238) with the Web Crypto HMAC, the same standard Google Authenticator and others use. It is a checker, not a vault — nothing is saved, so the secret is gone when you leave the page. Never paste a secret you don't own or on a device you don't trust. Everything runs on your device.