TOTP Token Generator is a browser authenticator built around one rule: your secrets never leave this device in readable form. Add a token, and it is encrypted with AES-256-GCM using a key derived from a master password only you know. The vault lives in local IndexedDB, the codes come from WebCrypto, and there is no account, no sync, and no server-side copy to breach.
On first visit you choose the password that protects the vault. It is stretched with a deliberately slow key-derivation function, and the resulting key never leaves memory. If you forget it, the vault stays locked for good — there is no reset link, because a reset path would also be an attack path.
Scan an otpauth QR code, paste otpauth:// links in bulk, or type a Base32 secret by hand. Every token is encrypted before it touches storage, so the raw secret is never written to disk in readable form.
Codes rotate on the standard RFC 6238 time step. Click a card to copy the current digits, and watch the ring before a step boundary. Because the maths runs on your device, the same code appears whether you are online or offline.
The whole vault is sealed with AES-256-GCM. Only the salt and iteration count are readable, which is exactly what you would need to unlock it — and nothing more.
RFC 6238 time-based codes with SHA-1, SHA-256 or SHA-512, 6 or 8 digits, and 30 or 60 second periods — verified against the RFC's own test vectors so the codes match what every other authenticator expects.
Scan otpauth QR codes with the camera. Frames are decoded on a local canvas and are never uploaded anywhere, so a picture of your screen never leaves the device.
Organise tokens with tags, pin the ones you use most, and filter down to a single service as the vault grows from a handful of logins to dozens.
Export an encrypted backup that only your master password can open, or copy plain otpauth:// links to move into another authenticator. Nothing about the vault is a lock-in.
Once the page is loaded, generating codes needs no network at all — useful on a plane, in a basement, or on a network you do not trust.
TOTP Token Generator has no server component. Nothing is uploaded, so no database of secrets exists to leak — the only copy of your vault is the encrypted record sitting in your browser's storage. That single design choice removes whole classes of risk: no token server to breach, no sync account to phish, and no plaintext secret in transit.
AES-GCM-256 · PBKDF2-HMAC-SHA-256