Build a small tool in this working folder that calculates the code an authenticator app shows, from a secret that it takes from a protected setting.
Prove the calculation against the test values published with the open standard for these codes, before any real secret is involved.
Use only those test values and a made-up secret. Never ask me for a real secret, never print or store one, and write nothing outside this folder.
Show me how I check it: all published test values match, and the test turns red when you break the calculation on purpose in a copy.
