RFC 6238 Time-based One-Time Password. Compatible with Google Authenticator, Authy, 1Password.
Same secret your authenticator app shows when you reveal the key. Spaces ignored.
Time-based One-Time Password — the 6-digit codes from authenticator apps. The server stores a shared secret per user. Both sides compute HMAC-SHA1(secret, current_time / 30) and take 6 digits from the result. As long as the clocks are roughly in sync, the codes match.
=) is optional.Everything runs in your browser via SubtleCrypto. The secret is never sent anywhere.