Fill it, or right-click it in.
Click Fill in the popup, or right-click any code field and choose Insert 2FA code.
Free & open-source 2FA for Chrome
Totpy keeps your two-factor codes in Chrome, encrypted end to end. Fill them with a click, sync them without trusting anyone, and leave your phone in your pocket.
How it works
The six-digit dance, every single sign-in. Usually with your phone somewhere else.
Open it and the account for the site you’re on is waiting at the top.
Fill types the code straight into the page. That’s the whole workflow.
End-to-end encrypted sync
Your vault is encrypted on your device before it leaves. Chrome sync and Google Drive keep your computers in step, and only ever hold the column on the right.
↑ Real ciphertext, encrypted in your browser moments ago with a throwaway key. Totpy has no servers, so this is all anyone else ever stores.
Works the moment you install it in a signed-in Chrome profile.
Unlimited accounts in a hidden app folder, with version history.
New accounts, edits, deletions and password changes merge on their own.
Features
Everything an authenticator should do, plus the things you only notice once you’ve had them.
Click Fill in the popup, or right-click any code field and choose Insert 2FA code.
The right account is suggested before you search.
No phone camera. Just the QR code on the page.
Import a whole Google Authenticator export in one go.
A recovery code resets a forgotten password.
An encrypted copy every day, kept for 7 days.
Warns you before a site rejects a code.
No limits, no tiers, no ads, no “Pro”. MIT licensed, forever.
Security
Open source, so you don’t have to take our word for any of it. Here is exactly how your codes are protected.
What Totpy never asks of you
Just your codes.
FAQ
Yes. Every feature is free with no account limits, and the code is MIT licensed. There is no paid tier, and nothing to upgrade to.
Click “Forgot password?”, enter your recovery code and choose a new password. If you lose both, nobody can decrypt your codes, including us. Keep the backup codes websites give you when you turn on 2FA.
No. Totpy has no servers. Codes are generated on your device, and sync providers only store an encrypted file that only your password or recovery code can open.
Totpy encrypts your codes and locks itself, but it shares a device with your passwords. For your most important accounts, a hardware security key is stronger still. Our security design explains the trade-offs openly.
In Google Authenticator choose Transfer accounts → Export accounts, take a photo of the QR code, then click + → Upload QR in Totpy. All accounts come across at once.
Totpy is built and tested for Google Chrome. Other Chromium browsers should work, but Google Drive sync needs Chrome. Firefox is on the roadmap.
Yes. Codes are computed on your device. Only sync and the occasional clock check need a connection.
Yes. It’s a public demo secret that protects nothing. It exists so you can check that Totpy’s codes match your own authenticator.
Free, open source and yours to keep. Install it in under a minute.
Chrome Web Store listing coming soon