A clean, private authenticator. No cloud lock-in, no third-party servers. Your secrets stay encrypted on your own deployment.
Open source · AES-256 encrypted · Self-hosted
GitHub
user@example.com
482 761
Codes refresh every 30 seconds
Built for privacy, designed for daily use. Five seconds to a code, then back to work.
Every TOTP secret is encrypted with AES-256 before it touches the database. Your app key, your data.
Scan setup QR codes with your camera, or paste a Base32 secret. Either way, you're done in seconds.
The Chrome/Firefox extension puts your codes one click away on any login page, authenticated by a personal API token.
Organize accounts into color-coded categories and find any code instantly with search.
Export all accounts as a single AES-encrypted blob. Restore it on any instance with the same key.
Deleted accounts sit in the archive for a week before permanent removal, so one mis-tap never locks you out.
Set up in under a minute. No subscription, no tracking, no compromise.
Create your account