Generate time-based one-time passwords
RFC 6238 TOTP. Use the same secret as your authenticator app. Codes are generated client-side — nothing is sent to any server.