Private by design · ready in minutes

Your 2FA codes.
In reach, not exposed.

CloudOTP brings your authenticator codes to Chrome, fills verification fields with one click, encrypts every secret before sync, and makes moving from your current app painless.

Client-side encryption Local code generation No tracking
CloudOTPalex@example.com•••
Codes refresh automatically18s
AES-256encrypted before sync

Bring your accounts from

Google AuthenticatorAegis2FASBitwardenAny otpauth:// app
Simple on purpose

From setup to your next code in three small steps.

No manual database work. No decoding exports by hand. CloudOTP guides the parts that matter.

01

Sign in once

Use Google to create your private sync space across Chrome profiles.

02

Choose a quick PIN

Use six digits to keep the extension UI locked after Google sign-in.

03

Add or import

Paste one setup key, scan a QR, or move your existing accounts in a batch.

Switch without the weekend project

Your current authenticator is welcome here.

CloudOTP recognizes common exports automatically. Preview what was found, skip duplicates, and import only supported TOTP entries.

  • Google Authenticator transfer QR
  • Aegis and 2FAS backups
  • Bitwarden JSON or CSV
  • Standard URIs and generic exports
Read import questions
A vault, not a viewing window

Cloud sync should not mean cloud-readable secrets.

Your six-digit vault PIN stays with you. It derives an encryption key in the extension; only encrypted secret data is synced.

••Your vault PINNever uploaded
Key derivationPBKDF2-SHA-256
Encrypted vaultAES-256-GCM
01

Codes generate locally

TOTP calculations happen inside Chrome using the browser’s cryptography APIs.

02

The vault key stays in memory

Close the extension and the derived encryption key is discarded.

03

Your records are isolated

Firebase authentication and Firestore rules scope every vault to its owner.

04

Imports stay on-device

Export parsing and QR decoding happen locally before secrets are encrypted.

Questions, answered

Know what you are trusting.

Security tools should be understandable. Here are the important details up front.

Can CloudOTP read my 2FA secrets?+

TOTP secrets are encrypted with AES-256-GCM in the extension before upload. The PIN is not stored. If you enable device unlock, a vault key copy stays in local extension storage and is used after platform verification. The six-digit PIN is a convenience lock, not strong protection against offline guessing. Account labels remain visible to the sync database.

Which apps can I import from?+

Google Authenticator, decrypted Aegis exports, 2FAS backups, Bitwarden JSON/CSV, standard otpauth URIs, and generic CSV/JSON.

What if I forget my vault PIN?+

It cannot currently be recovered. Keep recovery codes and your old authenticator until you have verified every account and your recovery plan.

Does CloudOTP replace security keys?+

No. Hardware passkeys and security keys are stronger against phishing. Use them whenever a service supports them; CloudOTP is for services that still require TOTP.

Can I self-host the sync service?+

Yes. The project includes a guided setup script, Firebase configuration, Firestore security rules, tests, and static hosting files.

A better home for your codes

Set up once. Reach your 2FA codes without breaking focus.

Free to use. Built for Chrome. Your secrets stay encrypted.

Chrome Web Store — coming soon Publishing yourself? Follow the setup instructions in the repository README.