Authenticator X

Two-factor codes that stay on your device.

Jump to the privacy policy →

Authenticator X generates the six-digit codes you need to sign in to GitHub, Google, your bank, and anything else that supports an authenticator app. It runs entirely in your browser. There is no account and no server.

It cannot read the websites you visit

Most extensions that fill something in for you ask to read and change your data on every site you visit. This one does not ask for that, and could not use it if it were granted.

It declares no host permissions and installs no content scripts. Scanning a QR code or filling in a code uses Chrome's activeTab permission, which Chrome grants for a single tab, only when you open the extension on it, and only until that tab navigates somewhere else.

You do not have to take that on trust. Chrome lists every permission an extension asks for, on the install prompt and on its entry in chrome://extensions. If this one ever asks to read your data on all websites, something has changed that should not have.

What it does

Your accounts are encrypted with AES-256-GCM before anything is written to disk. The key never leaves your device.

Privacy Policy

Last updated: 11 September 2026

Authenticator X does not collect, transmit or sell any of your data. There is no server. Everything the extension stores stays in your own browser profile on your own computer.

What the extension stores

All of this lives in Chrome's local extension storage. None of it is sent anywhere.

What the extension can see

Nothing seen this way is stored or transmitted. The screenshot is decoded in memory and discarded.

What the extension does not do

Data you export yourself

The backup and export features write files to wherever you choose. An encrypted backup is protected by the password you set for it. A plain-text otpauth:// export is not encrypted and contains your secrets in readable form — delete it as soon as you have finished using it.

Deleting your data

Settings → Security → Delete this vault removes the encrypted vault and its encryption key from the device. Removing the extension from Chrome also removes its storage. Neither is recoverable, and neither needs a request to us, because we never had a copy.

Future versions

A later version will offer an optional account so your vault can sync between your devices. That is opt-in, it does not exist in this version, and this policy will be updated before it ships.

Contact

brickitall.hi@gmail.com