2FA QR code decoder
See what's inside a two-factor setup QR code or a Google Authenticator export: the service, the setup key, its settings and the current code. Everything happens in your browser.
Drop a QR code image here, paste a screenshot, or
Decoded in this browser tab. Nothing is uploaded.
Before you use it
A setup key is as sensitive as a password. Anyone who has it can generate your codes. Only decode QR codes for your own accounts, and don't do it on a shared or work computer you don't trust. This page sends nothing anywhere: once it has loaded, you can switch off your connection and it keeps working.
What it reads
Standard setup links look like this:
otpauth://totp/Example:alice@example.com?secret=JBSWY3DPEHPK3PXP&issuer=Example
This is the format most websites put in their 2FA QR codes. It's often called the "Key URI format". The decoder shows each part:
| Part | Meaning | If it's missing |
|---|---|---|
totp or hotp |
Time-based or counter-based codes | Required |
Label (Example:alice@…) |
Service and account name shown in your app | Empty |
secret |
The setup key, in base32 | Required |
issuer |
The service name | Taken from the label |
algorithm |
SHA1, SHA256 or SHA512 | SHA1 |
digits |
Code length | 6 |
period |
Seconds each code lasts | 30 |
Google Authenticator exports (otpauth-migration://offline?data=…) are what Google Authenticator shows when you choose Transfer accounts > Export accounts. One QR code can hold several accounts, and a large export is split over several QR codes. The decoder lists every account in the QR code and says which part of the export it is, for example 2 of 3.
When it's useful
- Checking which accounts and settings an export QR code contains before you import it somewhere.
- Seeing whether a service uses non-standard settings, such as 8 digits or a 60-second interval, when its codes don't match.
- Checking that a code from your authenticator app matches the code calculated here. If they differ, your device's clock or the stored key is the likely cause. See 2FA code not working?
The Novaz line on each result says whether Authenticator App - Novaz can add that account. The app supports time-based codes with SHA-1, SHA-256 or SHA-512, 6 to 8 digits, and intervals of 1 to 300 seconds.