TOTP Token Generator is a two-factor authenticator that runs entirely in your browser: encrypted locally, generated locally, and accountable about both.
Two-factor codes are the last line of defence on almost every account you own, and yet the tools that hold them usually ask you to trust a company with the keys. Cloud sync is convenient right up to the point where someone else's breach becomes your breach.
TOTP Token Generator takes the opposite position. There is no account, no sync service and no server-side copy of your vault. Your secrets are encrypted on your device with a password only you know, and the codes are computed by your own browser. If we disappeared tomorrow, your vault would keep working exactly as it does today.
AES-256-GCM seals the entire vault using a key derived from your master password, so the bytes sitting in your browser are unreadable without it.
No uploads, no accounts, no telemetry about which services you use. The only secrets in existence are the ciphertext on your device.
Forget the master password and the vault is gone for good. We would rather say that plainly than offer a recovery flow that quietly weakens the encryption.
RFC 6238 codes via the WebCrypto API, with SHA-1/256/512, 6 or 8 digits and 30 or 60 second periods — checked against the RFC's own test vectors.
When you set a master password, TOTP Token Generator stretches it with PBKDF2-HMAC-SHA-256 over 600,000 iterations and a random salt, producing an AES-GCM-256 key that is marked non-extractable. From that point on, every write to storage is a fresh encryption of the whole vault, and the key lives only in memory — locking the vault, closing the tab or reloading simply forgets it.
Codes are then generated locally on the standard TOTP time step. The camera scanner decodes QR frames on a local canvas, the import/export tools work on the encrypted vault or on otpauth links you explicitly ask for, and the page's only network traffic is its own assets, fonts and analytics.