authenticator.sh 2FA icon

authenticator.sh 2FA

An open-source authenticator that makes your 2FA codes inside Chrome, with no host permissions.

Add to Chrome Open source · Chrome Web Store · Source on GitHub

Why it's a strong pick

authenticator.sh 2FA asks for no host permissions, so it cannot read the pages you visit. It is open source under the MIT license and uses Manifest V3, Chrome's current extension format. The README says it is free to install. Its latest GitHub release is from 24 September 2026.

What it does

It makes time-based one-time codes (TOTP) for your accounts, so you do not need a phone app. Add an account, then copy the code when a site asks for it. The repo describes it as an open-source authenticator with "no servers, no analytics, no host permissions".

Key features

  • TOTP codes. Supports SHA-1, SHA-256 and SHA-512, with 6 to 10 digits.
  • QR code import. Add an account from its QR code.
  • Password-protected vault. The README names AES-256-GCM and PBKDF2-HMAC-SHA256 with 600,000 iterations.
  • Optional passkey unlock. Uses WebAuthn where your device supports it.
  • Backups. Optional password-protected backups, plus seven rolling automatic copies kept in your browser.
  • 20 interface languages.

Who it's for

It suits people who want 2FA codes in the browser without an account or a server. It also suits people who like open-source code they can read. The project is young: all its repo activity is from 2026, so its update pace over time is not yet proven.

What permissions does authenticator.sh 2FA ask for?

Its manifest lists storage, activeTab, contextMenus, scripting and sidePanel. It lists no host permissions and no content scripts. That means it does not ask to read every site you visit. The list comes from the source manifest for version 1.13.3 on GitHub.

Where does it keep my accounts?

The README says data sits in Chrome's local storage, in optional Chrome sync storage (your Google account), and in browser backups. In its words: "We receive none of your data on any path." That is the developer's own statement. We could not read the developer's privacy policy when we checked; read it before installing.

Is it safe to use without a password?

Not for sync. The README says that with password protection off, accounts sit in Chrome's sync storage in the clear, so Chrome copies them to Google. Set a password before you add any account. The README also says the vault cannot protect you from malware running as you while it is unlocked, or from a keylogger.

Does it work with passkeys?

Optionally. You can unlock the vault with a passkey through WebAuthn. The README says this depends on your platform supporting the PRF extension, so it may not work on every device. Keep your password as a fallback, and keep a backup of your accounts somewhere safe.

FAQ

Is it open source? Yes, under the MIT license.

Does it cost anything? The README says it is free to install.

Does it replace a password manager? No. It makes 2FA codes. For passwords, see Bitwarden or KeePassXC-Browser.

Good to know

Turn on the password first, then add accounts. This is the key safety step. Make a password-protected backup and store it away from your browser. Remember that codes in the same browser as your passwords weaken the point of a second factor. Many people keep the two apart.

Other password managers to compare

authenticator.sh 2FA is one of 10 picks in our Password Managers guide:

  • Bitwarden: An open-source password manager from Bitwarden Inc. The free plan covers unlimited passwords and devices.
  • 1Password: A password manager from AgileBits Inc. (1Password). It has a free trial but no free plan.
  • NordPass: A password manager from Nord Security. The free plan covers one active device; Premium adds more.
  • Proton Pass: An open-source, end-to-end encrypted password manager from the Proton Mail team. It has a free plan.
  • RoboForm: A password manager from Siber Systems, Inc. The free plan is for one device with no sync.
  • Keeper: A zero-knowledge password manager from Keeper Security. The extension needs a paid plan or the free trial.
  • KeePassXC-Browser: Fill in logins from the KeePassXC desktop app (needs KeePassXC installed and running).
  • Passbolt: Open-source password manager for teams. The extension needs a Passbolt server, self-hosted or managed.
  • Psono: Autofill and team sharing for a Psono vault. Needs a Psono server, hosted or self-hosted. Open source.

This is a third-party extension, not built or maintained by Xplorekit. We link to the official Chrome Web Store listing — install and permissions are entirely between you and the extension's own publisher.