Blog

2FA Generator

Instant TOTP codes for Instagram, Facebook, TikTok, and any standard authenticator secret. It never leaves this tab.

A TOTP 2FA code is six digits derived from your secret and the current 30-second window. Use it as an Instagram or Facebook 2FA generator, or paste any Google Authenticator / Authy key. The secret stays in JavaScript on this device — Accstall never receives it.

Privacy

Nothing leaves your browser

Your 2FA secret stays in this browser tab. It is not sent to Accstall, stored, or shared with analytics.

Spaces and dashes are ignored. otpauth URIs that ask for 8 digits, SHA256, or a period other than 30 seconds are rejected.

This is not a valid Base32 secret yet. It should only contain the letters A–Z and the digits 2–7.

This otpauth URI asks for a format this tool does not generate (6-digit SHA1 / 30 seconds only). Showing a code anyway would be the wrong code.

Could not reach the server clock. Codes use your device time instead.

A secret in the page URL was removed. Never share 2FA secrets in a link.

Current code
——— ———
Next

About to expire — if the login fails, wait for the next code.

Bought an account with 2FA? Log in to generate codes for the secrets we delivered.

How it works

  1. Paste a Base32 secret or an otpauth:// URI.
  2. We normalize spaces, dashes, and padding, then reject anything that is not A–Z and 2–7.
  3. A 6-digit code and the next code appear, with a 30-second countdown from server time.

FAQ

No. The secret is processed only in your browser. Accstall does not upload it, log it, or send it to analytics.

Yes. Instagram, Facebook, TikTok, and any other site that uses standard 6-digit TOTP work here. Paste the Base32 secret or otpauth URI from the account — the page is not Instagram-specific, so the same generator covers every platform Accstall sells.

Any standard TOTP app: Google Authenticator, Authy, and the same secrets Accstall delivers with 2FA accounts. The tool produces 6-digit SHA-1 codes every 30 seconds.

Yes, if it asks for 6 digits, 30 seconds, and SHA1. URIs that request 8 digits, SHA256, or another period are rejected so we never show a plausible but wrong code.

The page asks our server for the time and offsets the countdown. If that request fails, codes still generate from your device clock and a warning appears.

Sign in and open the dashboard 2FA generator. Purchased secrets stay on your order — this public page is for pasting a secret you already have.