HOTP Generator
Generate RFC 4226 counter-based one-time passwords — TOTP's time-independent sibling
Enter or generate a Base32 secret key to compute an HOTP code
About this tool
The ToolNinja HOTP Generator computes RFC 4226 HMAC-based one-time passwords — the counter-based algorithm that TOTP itself is built on top of. Where TOTP derives its counter from the current time divided into fixed intervals, HOTP uses an explicit counter value that only advances when a code is actually used, making it the right choice for hardware tokens (like early YubiKeys) and offline-generated code lists where there's no reliable shared clock between client and server. Enter a Base32 secret and a counter value, and it computes the exact same HMAC-SHA1/256/512-based code a real HOTP authenticator would produce for that counter. It also builds and parses otpauth://hotp/ URLs — the same URL format TOTP uses, just with a counter parameter instead of a period. Everything runs 100% in your browser via the Web Crypto API — your secret never leaves your machine.
When to use it
- →Testing an HOTP-based authentication integration without physical hardware tokens
- →Understanding the difference between HOTP and TOTP by computing both for the same secret
- →Debugging a counter-desync issue between a client and server HOTP implementation
- →Generating a specific HOTP code for a known counter value during development
Tips
- ◆Unlike TOTP, an HOTP code never expires on its own — it stays valid until used, which is exactly why counter synchronization between client and server matters so much more than it does for TOTP.
- ◆Most real HOTP servers accept a small window of future counter values (not just the next one) to tolerate a user pressing the button on their token multiple times without using earlier codes.
- ◆If you're building something new, TOTP is usually the better default — it doesn't require either side to persist and synchronize a counter, since time serves that role automatically.
Frequently asked questions
What's the actual difference between HOTP and TOTP?
Both compute an HMAC over a moving counter and truncate it into a short numeric code — the algorithms are nearly identical. TOTP (RFC 6238) derives the counter from the current time divided by a fixed period (usually 30 seconds), so it changes automatically without either side tracking state. HOTP (RFC 4226) uses an explicit counter that only increments when a code is generated and accepted, requiring the server to track and advance it.
Why would anyone use HOTP instead of TOTP today?
Mainly for hardware tokens without a reliable internal clock, or systems where a shared, synchronized time source between client and server can't be guaranteed. Most modern 2FA (Google Authenticator, Authy, most authenticator apps) uses TOTP specifically because it avoids the counter-synchronization problem entirely.
Is my secret key safe when using this tool?
Yes — HOTP computation runs entirely in your browser via the Web Crypto API. Your secret key and counter value never leave your device; there's no network request involved at any point.