Where the secret comes from
When a website offers an authenticator app for 2FA, it shows a QR code and usually a can't scan it? fallback with the secret spelled out, a Base32 string like JBSW Y3DP EHPK 3PXP. That string is what this tool takes. The QR code itself just wraps an otpauth:// link carrying the same secret plus the settings, so if you have that link from a backup or a password manager export, paste it whole and nothing needs configuring by hand.
To enroll a phone from an otpauth link you already have, turn the link back into a scannable image with the QR Code Generator.
How the codes are computed
TOTP is standardized in RFC 6238: the Unix time is divided into 30 second steps, the step number is signed with the secret using HMAC, and a few digits of the result become the code. Both sides compute the same code because they share the secret and the clock. This implementation passes the official RFC test vectors for SHA-1, SHA-256 and SHA-512.
The dimmed neighbours exist because clocks drift. Most services accept the previous code for a short while after a rotation, so a code typed just too late usually still works. The time offset setting in the tool shifts the clock on purpose, useful when checking how a server handles drift.
A debugging tool, not an authenticator
The tool computes exactly what an authenticator app would, which makes it handy for testing a TOTP integration, checking a stored secret before deleting it, or generating a code when your phone is not at hand. It is not a replacement for an authenticator app, so keep your 2FA secrets enrolled in one, or in a password manager that generates codes.