แฮช/การเข้ารหัส
TOTP Generator/Verifier
รหัสผ่านครั้งเดียวตามเวลา (TOTP, RFC 6238) — สร้างรหัสปัจจุบันจาก secret และตรวจสอบรหัสที่ป้อนโดยยอมรับความคลาดเคลื่อนของเวลา
------
TOTP (Time-based One-Time Password, RFC 6238) is a two-factor authentication algorithm that generates a one-time code from a secret and the current time. It's exactly what runs under the hood in Google Authenticator, Authy, and similar apps.
How to use it
- Generate: paste a secret key (usually Base32, the same one encoded in a 2FA setup QR code) and the tool shows the current 6-digit code along with the time left before it changes.
- Verify: enter a secret and a code from an authenticator app to check whether they match.
- Verification tolerates a small amount of clock drift — it accepts a code from a neighboring time step, not just the current one.
Common uses
- Debugging your own 2FA implementation on the backend — checking that the server generates and accepts codes correctly.
- Manually generating a code for an account when you don't have your phone with the authenticator app handy.
- Figuring out why an app's code is being rejected by the server (usually the cause is a clock out of sync).
Things to keep in mind
A TOTP code is only valid for a short window (usually 30 seconds) — that time limit is the main protection, not the secret alone.
Code accuracy depends directly on the device's clock being synced; a noticeable clock drift is the most common cause of rejected 2FA codes.
บทความเกี่ยวกับเครื่องมือนี้: TOTP: รหัสใช้ครั้งเดียวในแอปยืนยันตัวตนทำงานอย่างไร
คำถามที่พบบ่อย
ทำไมโค้ดที่สร้างขึ้นถึงหมดอายุเร็วมาก?
โค้ด TOTP อิงตามเวลา — ค่าเริ่มต้นจะหมุนเวียนทุก 30 วินาที คำนวณจากเวลา Unix ปัจจุบันและความลับที่ใช้ร่วมกัน หน้าต่างสั้น ๆ นี้จำกัดว่าโค้ดที่รั่วไหลจะยังใช้ได้นานแค่ไหน
จะเกิดอะไรขึ้นถ้านาฬิกาของอุปกรณ์ฉันไม่ตรงกัน?
TOTP อาศัยการที่ทั้งสองฝ่ายเห็นตรงกันเรื่องเวลาปัจจุบันโดยประมาณ แอปยืนยันตัวตนและเซิร์ฟเวอร์ส่วนใหญ่ยอมรับความคลาดเคลื่อนของนาฬิกาเล็กน้อย (ปกติหนึ่งช่วงเวลา) แต่ความคลาดเคลื่อนที่มากกว่านั้นจะทำให้โค้ดที่ถูกต้องถูกปฏิเสธ
คีย์ลับของฉันถูกส่งไปที่ไหนหรือไม่เมื่อสร้างโค้ดที่นี่?
ไม่ โค้ด TOTP ถูกคำนวณทั้งหมดในเบราว์เซอร์ของคุณ คีย์ลับจะไม่ออกจากอุปกรณ์ของคุณเลย
TOTP ป้องกันฟิชชิงได้หรือไม่?
ไม่ครบถ้วน หากเหยื่อกรอกรหัสผ่านและรหัส TOTP ปัจจุบันลงในเว็บไซต์ปลอมแปลง ผู้โจมตีสามารถนำค่าทั้งสองไปใช้บนเว็บไซต์จริงได้ทันทีในขณะที่รหัสยังใช้งานได้อยู่ มีเพียงกุญแจฮาร์ดแวร์ตามมาตรฐาน FIDO2/WebAuthn เท่านั้นที่ป้องกันการโจมตีแบบเรียลไทม์เช่นนี้ได้
เหตุใดเซิร์ฟเวอร์จึงยอมรับช่วงเวลาก่อนหน้าด้วย ไม่ใช่แค่ช่วงเวลาปัจจุบัน?
เพื่อชดเชยความล่าช้าของเครือข่ายเล็กน้อยระหว่างการสร้างรหัสบนโทรศัพท์กับช่วงเวลาที่เซิร์ฟเวอร์ได้รับและตรวจสอบ หากไม่มีระยะผ่อนปรนนี้ รหัสที่ถูกต้องบางครั้งอาจถูกปฏิเสธเพียงเพราะความล่าช้าปกติไม่กี่วินาที