QR Code Scanner / Decoder
Upload a QR code image and decode exactly what it contains — including 2FA otpauth:// secrets
Drag & drop a QR code image, or click to upload
About this tool
The ToolNinja QR Code Scanner decodes any QR code image — upload a screenshot, a photo, or a saved image file, and it extracts exactly what's encoded inside, running entirely client-side via canvas pixel data and the jsQR decoding library. It specifically recognizes otpauth:// QR codes — the format every 2FA setup screen encodes — and when it detects one, breaks out the issuer, account label, and algorithm/digits/period settings, with a direct link to open the decoded secret in the TOTP Generator. This is the natural complement to a situation that comes up more than people expect: you have a 2FA QR code (a screenshot, a backup photo) but no working authenticator app in front of you, and need to know what's actually inside it before you lose access to it entirely. Everything runs 100% in your browser — the image is decoded locally and never uploaded anywhere.
When to use it
- →Extracting a 2FA secret from a QR code screenshot when you don't have an authenticator app handy
- →Checking what a QR code actually points to before scanning it with your phone
- →Debugging a QR code your own application generated, to confirm it encodes what you expect
- →Reading a QR code from an old screenshot or backup when the original source is gone
Tips
- ◆Works from a screenshot or photo, not just a cleanly-generated QR image — jsQR is reasonably tolerant of camera photos as long as the code is in focus and not too small.
- ◆An otpauth:// QR code is detected automatically and gets a direct 'Open in TOTP Generator' link so you don't have to copy the secret by hand.
- ◆If decoding fails on a photo, try cropping tighter around just the QR code itself — a lot of surrounding background can throw off detection.
Frequently asked questions
Is my QR code image uploaded anywhere?
No. The image is decoded entirely in your browser — it's drawn to an off-screen canvas, read as raw pixel data, and passed to the jsQR library locally. No network request is made with the image at any point.
Can this scan a QR code using my camera, not just an uploaded image?
Not currently — this tool works from an uploaded image file. For a live camera scan, most phone camera apps and dedicated QR scanner apps already decode QR codes natively without needing a separate tool.
Why does it specifically call out otpauth:// QR codes?
Because that's one of the most common reasons someone needs to decode a QR code rather than just scan it normally — recovering a 2FA secret from an old screenshot when the original authenticator app entry is gone. Any other QR code (a URL, plain text, a WiFi config) decodes the same way, just without the extra otpauth-specific breakdown.