TEMPMAIL CLOUD

TOTP Secret Key Explained: What Must Stay Private?

The TOTP secret is shared seed material used with time to generate codes; anyone who copies it can generate the same codes until the setup is replaced.

TOTP Secret Key Explained: What Must Stay Private — an original TempMail Cloud visual explaining TOTP secret key explained

Written and reviewed by the team operating TempMail Cloud. Product claims are checked against our live service and our editorial standards.

A TOTP secret key is the shared seed used by an authenticator and the account provider to calculate rotating codes. It is not your ordinary account password or the six-digit value you type at login. Someone with the seed may generate future codes until the provider replaces that enrollment.

What changes, and what stays the same?

ValueChanges automatically?Where it belongs
Account passwordUsually only when changedA protected password manager or another appropriate credential system
TOTP setup keyUsually remains the same for that enrollmentThe configured authenticator and any deliberately protected backup
Current TOTP codeChanges with the configured time stepThe legitimate verification screen for the current attempt
Recovery codeFollows the provider's own lifecycleA protected recovery location, separate from public notes

The generator and verifier must agree on the secret and configuration. RFC 6238 describes a default 30-second step and supports more than one hash algorithm; a page displaying six changing digits alone does not prove compatibility. TOTP specification.

A label is not a cryptographic identity

Imagine that two test entries are both labeled "Staging." Renaming one to "Staging admin" helps you choose the right entry, but does not change its secret or the account that will accept its code. If a code fails, check the actual account and enrollment rather than repeatedly changing labels.

Use descriptive labels without storing secrets inside them. Never send the setup key to a website's support team merely because a current code was rejected.

Understand storage before making a backup

A password manager that holds a password and TOTP seed concentrates access in one system. Separate devices and protected backup designs have different tradeoffs. Assess who can open the vault, how recovery works and what happens if a device is stolen; physical separation is not the only fact that determines authentication strength.

In TempMail Cloud, calculation is local to the browser, while optional Save Key stores a guest key in browser storage or syncs a signed-in key to the account service. Sharing is separate. The tool is not a way to reconstruct a lost seed from your email address. Read generator safety before using it.

If the seed may have leaked

Use the account provider's official process to replace the authenticator. Keep a valid recovery path available, confirm the new enrollment and review other sessions or recovery methods according to that provider's instructions. Deleting a screenshot, saved entry or chat message cannot revoke an already copied secret.

For a lost phone without evidence of exposure, start with a previously configured recovery method instead of guessing a replacement seed. Our TOTP troubleshooting guide separates clock errors, wrong entries and lost access. The QR security guide covers setup images.