Authentication · Desktop app

2FA Authenticator App

A desktop two-factor authentication app for Time-based One-Time Passwords (TOTP), built in Python with CustomTkinter. Your secrets are encrypted with a key that only your PIN or password can unlock, then stored in the operating system's keyring.

Screenshots

The accounts shown are example.com demo accounts, and the secret key and recovery codes are made-up examples. Click a screenshot to open it full size. Use the arrows, or select the gallery and press ← →.

How it works

  1. Choose a PIN or password on first launch: a password of 8+ characters (recommended) or a numeric PIN of 6+ digits.
  2. Encrypt each token with AES-256-GCM using a random data key. That data key is itself encrypted with a key derived from your PIN or password using scrypt (N=217, r=8, p=1, the OWASP recommendation).
  3. Store the encrypted tokens and encrypted data key in the OS credential manager under random IDs, so the entries don't reveal which services you use.
  4. Unlock to see live codes. Locking, manually or after inactivity, discards the decryption key and decrypted tokens.
  5. Release builds are made by GitHub Actions, which runs the tests first and publishes a SHA-256 hash and a build attestation with each Windows download.

Security decisions