2FA Secret Keys: What They Are and Where to Find Them
A 2FA secret key is the long-term credential behind the changing codes in an authenticator app. If a website asks you to scan a QR code or enter a setup key manually, that secret is what connects your authenticator to the account.
Also available in 简体中文

A 2FA secret key is the long-term credential behind the changing verification codes in an authenticator app. It is not the 6-digit code you type when signing in.
When you enable authenticator-based two-factor authentication, the service creates a secret and gives it to your authenticator. Both sides then know the same secret.
A TOTP authenticator combines that secret with the current time to calculate a verification code. The service performs the same calculation when you sign in and checks whether the code matches.
That relationship is the key thing to understand:
Secret key + current time → current TOTP code
If you already have a Base32 secret, paste it into the 2FA Code Generator to get the current code.
What a 2FA secret key actually does
The secret is the stable part of a normal TOTP setup. The verification code is the temporary part.
For example, your secret might look like this:
JBSWY3DPEHPK3PXP
Your authenticator might currently generate:
281944
A short time later, it might show:
607183
The Base32 secret stays the same. The short code changes as the TOTP time window changes.
This is why an authenticator does not need a website to send it a new code every 30 seconds. Once the authenticator has the correct secret and time settings, it can calculate the current code locally.
The TOTP standard is defined in RFC 6238.
Secret Key, Setup Key and 2FA Secret
Different services use different names for the same kind of credential. During setup, you may see labels such as:
- Secret Key
- Setup Key
- 2FA Secret
- Authenticator Key
- Manual Entry Key
- TOTP Secret
In a standard TOTP setup, these usually refer to the secret your authenticator needs to generate verification codes.
The exact wording matters less than where you see it. If a service displays a QR code and then offers an option such as Can’t scan it?, Enter manually, or Show setup key, the value behind that option is usually the credential you need.
Do not confuse it with your account password or one of your recovery codes.
What a 2FA secret key looks like
Many TOTP setup keys appear as a string of uppercase letters and numbers:
JBSWY3DPEHPK3PXP
Some services add spaces to make the string easier to read:
JBSW Y3DP EHPK 3PXP
This is commonly a Base32-encoded secret. Base32 is an encoding format used to represent binary data as text. You do not normally need to decode it yourself.
The important part is that authenticator apps and compatible TOTP tools can read that Base32 value and use it as the shared secret. Google Authenticator’s documented provisioning format also represents its secret parameter as Base32.
Where to find a 2FA secret key
You normally receive the secret while setting up authenticator-based 2FA for an account. The exact menus vary, but the path often looks roughly like this:
Account Settings → Security → Two-Factor Authentication → Authenticator App
Once setup starts, the service may display a QR code. Look around that screen for options such as:
- Can’t scan the QR code?
- Enter manually
- Manual setup
- Setup key
- Show secret
Opening one of these options may reveal the text version of the credential contained in the setup information.
One important detail: the service may not continue showing the original secret after enrollment is complete. If 2FA is already active and you can no longer find the setup key, you may need to reconfigure the authenticator before the service provides a new one.
Do not reset working 2FA until you know you still have a valid way back into the account.
How the QR code relates to the secret key
The QR code and the secret key are closely related, but they are not exactly the same thing.
A QR code is a convenient way to transfer the authentication setup into an app without making you type the secret manually. For TOTP accounts, the QR code often represents an otpauth:// URI.
A simplified example looks like this:
otpauth://totp/Example:alice@example.com?secret=JBSWY3DPEHPK3PXP&issuer=Example
Inside it, the secret is:
JBSWY3DPEHPK3PXP
The URI can also contain the account name, issuer, authentication type, number of digits, algorithm and TOTP period.
So when you scan an authenticator QR code, the app is not receiving a completely different credential. It is reading the provisioning information needed to create the authenticator entry, including the secret.
What an otpauth:// URI contains
The otpauth:// format is commonly used to provision authenticator apps. Take this example:
otpauth://totp/Example:user@example.com?secret=JBSWY3DPEHPK3PXP&issuer=Example
There are several useful pieces inside it.
totp
This tells the authenticator that the account uses time-based one-time passwords.
Example:user@example.com
This helps identify the service and account inside the authenticator.
secret=…
This contains the shared secret used to generate the codes.
issuer=Example
This tells the authenticator which service issued the credential.
The format can also contain optional settings such as the algorithm, digit count and time period. Google documents this format in its Authenticator Key URI specification.
If a TOTP tool supports otpauth:// input, you do not necessarily need to extract the Base32 secret by hand.
The secret key is not the 6-digit code
This is one of the easiest parts of 2FA to mix up.
Suppose the setup secret is:
JBSWY3DPEHPK3PXP
The authenticator uses it to generate temporary values such as 281944 and later 607183. These values serve different purposes.
| Value | What it is | How long it lasts |
|---|---|---|
JBSWY3DPEHPK3PXP | 2FA secret | Normally stays with the enrollment |
281944 | TOTP code | Short-lived |
607183 | Next TOTP code | Short-lived |
Knowing a current 6-digit code does not automatically reveal the underlying secret. Possessing the secret is much more sensitive because a compatible TOTP implementation can use it to calculate future codes.
A recovery code is something different
Recovery codes are not TOTP secret keys. They exist for a different reason.
A 2FA secret allows an authenticator to continue generating dynamic codes. A recovery code gives you an alternative way to recover or access an account when the normal second factor is unavailable.
A recovery code may look like a random string, but that does not make it a TOTP secret.
If a service gives you a list of backup or recovery codes, do not paste one of them into a TOTP generator expecting it to create 6-digit authentication codes.
Why the secret needs to stay private
Anyone who obtains the correct TOTP secret may be able to generate the same authentication codes as your authenticator. That means the secret should be treated as a credential.
Avoid:
- posting it in screenshots
- sending it through public chats
- saving it in public notes
- committing it to source code
- sharing the authenticator QR code
- pasting it into tools you do not trust
The QR code deserves the same care because it may contain the secret itself.
A useful rule is simple: treat the setup QR code and the text secret as credentials. They are not harmless setup instructions.
What to do if you only have the QR code
If you are still on the original 2FA setup screen, first look for a manual setup option. Many services provide the Base32 secret separately for users who cannot scan the QR code. That is usually easier than trying to extract the secret from an image.
If you only need to configure an authenticator, simply scanning the QR code is normally enough.
Be more careful with old screenshots. If the account has been reconfigured since the screenshot was created, the secret stored in that old QR code may no longer match the credential currently registered with the service.
What to do if the secret is no longer visible
Some services only reveal the secret during initial enrollment. Authenticator apps also differ in how much credential information they let you view or export later.
Before changing an existing setup, check whether you still have a working recovery method, such as:
- the existing authenticator
- another enrolled authentication method
- recovery codes
- the service’s account-recovery process
If the original secret is no longer available, the safest route may be to follow the service’s official process for resetting and enrolling the authenticator again.
A new enrollment normally means a new secret. Do not assume an old secret will continue working after 2FA has been reset.
Generating a TOTP code from a 2FA secret
Once you already have the Base32 secret, generating the current TOTP code is straightforward. For the full login sequence — account, password, then the short code — read How to Use a 2FA Secret Key: Generate a Code and Sign In.
Open the 2FA Code Generator and paste the secret into the input field. The tool also supports otpauth:// input, so you can use a supported provisioning URI without manually extracting the secret first.
The resulting code changes with the current TOTP time window.
If you already have the correct secret but the generated code is still being rejected, the problem is usually no longer about finding the key. The next things to check are:
- device time
- whether the current code is about to expire
- whether the service was reconfigured with another secret
- whether the account actually uses standard TOTP
- whether its TOTP settings match the ones in the provisioning data
For that situation, read 2FA Code Not Working: Common Causes and Fixes.