A TOTP code (RFC 6238) is an HOTP code (RFC 4226) whose counter is the clock: T is the number of whole periods, normally 30 seconds, since 1970. HOTP takes the HMAC of T written as eight big-endian bytes — HMAC-SHA-1 unless the set-up says SHA-256 or SHA-512 — then uses the low four bits of the last byte as an offset, reads four bytes from there, clears the top bit and keeps the last six to eight decimal digits, leading zeros included. Nothing else goes in, which is why a phone with no signal shows the same code as the server. The codes here are checked against RFC 6238 Appendix B for all three algorithms and RFC 4226 Appendix D. One trap in that appendix: its text says every mode uses the 20-byte seed "12345678901234567890", but the table was generated with a 32-byte seed for SHA-256 and a 64-byte one for SHA-512.
The secret is Base32 (RFC 4648): the letters A to Z and the digits 2 to 7, with no 0, 1, 8 or 9 because they are too easily confused with O, I, L and B. Lower case, spaces between groups and trailing = padding are all accepted; any other character is refused with its position and, for a digit, the letter it probably was. An otpauth://totp/Issuer:account?secret=…&issuer=… URI, the text inside an authenticator QR code, follows Google’s Key Uri Format, whose defaults are SHA1, 6 digits and 30 seconds. When a URI is pasted its own settings are used. Google’s page states that Google Authenticator ignores the algorithm and period parameters, and the digits parameter on Android, so the tool warns whenever a setting differs from the defaults. The URI it builds names the issuer twice, as the format recommends, and omits defaults. No QR code is drawn, because that would need a library this page does not load; most apps also accept the secret typed in as a setup key.
Servers usually accept a code from one step either side of their own, because RFC 6238 recommends allowing at most one step of network delay; a device clock that is further out produces codes for the wrong step, and the checker says which step a code matched. The secret is the whole of the security: anyone who has it can produce every future code, which is why services show it once and hand out recovery codes for when the device is lost. Everything here runs in your browser and nothing is sent anywhere, but this is a testing tool — do not keep real account secrets in a browser tab.