Security & Privacy

AUTHENTICATORTOOL

Security & Privacy

Understand what runs locally, what gets stored, and what the limitations are.

How these tools work

The public generator calculates time-based one-time passwords in your browser. The QR reader parses supported TOTP setup data locally where browser capabilities allow it. Neither tool needs your third-party account password.

Protect your authenticator secret

A TOTP secret is sensitive. Anyone who gets it may be able to generate verification codes for the associated account. Do not share secrets, setup QR codes, or unencrypted backup files.

Vault encryption

The vault derives an encryption key in your browser from a separate vault password and encrypts vault entries before sending them for storage. The server stores ciphertext and a non-secret salt. The deployed website's JavaScript still has to handle decrypted data while the vault is unlocked, so a compromised site or device can expose it. This is not a substitute for an independent security audit.

Data and limitations

Use HTTPS. Avoid shared devices. Keep secure backups. The QR image decoder depends on browser support for the built-in Barcode Detector API; pasting a supported otpauth://totp/ URI is an alternative. Do not store secrets for accounts you do not own or have permission to administer.

Security contact

Before public launch, add a monitored security contact address and publish a reviewed privacy policy and terms of use.

Scroll to Top