OTPilot Authenticator by Hank
Generate 2FA codes in a master-password-encrypted vault, with host-matched autofill, encrypted cloud backup, and security tips.
Extension Metadata
Screenshots
About this extension
OTPilot Authenticator generates two-factor authentication (2FA) codes right in your
browser, so you don't need to reach for your phone to sign in.
WHAT'S NEW IN THIS VERSION
• Encryption now runs on the browser's native Web Crypto — the vault is sealed with
AES-GCM authenticated encryption (Argon2id-derived key, a fresh random IV per
record). Tampered data or a wrong password fails loudly instead of silently
decrypting into a wrong code.
• Domain binding added — a code is only ever typed into the exact host the account
was saved for.
• Cloud upload stays fully disabled until a master password is set, so an
unencrypted vault can never be uploaded.
• Lighter on the pages you visit — QR scanning runs in the extension's own
background worker, so only a few dozen KB is injected into your tabs.
• Rebuilt QR engine — scanning moved to an actively maintained decoder for more
reliable recognition, and the QR generator was upgraded to its latest version.
KEY FEATURES
• Standard 2FA codes — time-based (TOTP) and counter-based (HOTP) one-time passwords,
compatible with Google, GitHub, AWS, and any service that supports authenticator apps.
• Encrypted vault — protect your accounts with a master password. Secrets are encrypted
with Argon2id key derivation and AES-GCM, and the vault auto-locks after a set idle time.
• Host-matched autofill — fill the current code into the matching site's login field with
one shortcut. Codes are only injected when the page's host matches the saved account.
• Encrypted cloud backup (optional) — back up your encrypted vault to your own Dropbox.
Backups stay encrypted; only you can decrypt them with your master password.
• Easy import — scan a QR code, enter a key manually, or import from Google Authenticator.
• Security Advisor — surfaces practical tips to keep your 2FA setup safe.
PRIVACY
Your 2FA secrets never leave your device unencrypted. OTPilot does not run analytics and
does not send your data to its developer. Cloud backup is opt-in and goes only to your own
cloud account.
Open source (MIT) — based on the Authenticator extension
(github.com/Authenticator-Extension/Authenticator).
Source: https://github.com/Hank076/Authenticator
browser, so you don't need to reach for your phone to sign in.
WHAT'S NEW IN THIS VERSION
• Encryption now runs on the browser's native Web Crypto — the vault is sealed with
AES-GCM authenticated encryption (Argon2id-derived key, a fresh random IV per
record). Tampered data or a wrong password fails loudly instead of silently
decrypting into a wrong code.
• Domain binding added — a code is only ever typed into the exact host the account
was saved for.
• Cloud upload stays fully disabled until a master password is set, so an
unencrypted vault can never be uploaded.
• Lighter on the pages you visit — QR scanning runs in the extension's own
background worker, so only a few dozen KB is injected into your tabs.
• Rebuilt QR engine — scanning moved to an actively maintained decoder for more
reliable recognition, and the QR generator was upgraded to its latest version.
KEY FEATURES
• Standard 2FA codes — time-based (TOTP) and counter-based (HOTP) one-time passwords,
compatible with Google, GitHub, AWS, and any service that supports authenticator apps.
• Encrypted vault — protect your accounts with a master password. Secrets are encrypted
with Argon2id key derivation and AES-GCM, and the vault auto-locks after a set idle time.
• Host-matched autofill — fill the current code into the matching site's login field with
one shortcut. Codes are only injected when the page's host matches the saved account.
• Encrypted cloud backup (optional) — back up your encrypted vault to your own Dropbox.
Backups stay encrypted; only you can decrypt them with your master password.
• Easy import — scan a QR code, enter a key manually, or import from Google Authenticator.
• Security Advisor — surfaces practical tips to keep your 2FA setup safe.
PRIVACY
Your 2FA secrets never leave your device unencrypted. OTPilot does not run analytics and
does not send your data to its developer. Cloud backup is opt-in and goes only to your own
cloud account.
Open source (MIT) — based on the Authenticator extension
(github.com/Authenticator-Extension/Authenticator).
Source: https://github.com/Hank076/Authenticator
Rated 0 by 0 reviewers
Permissions and data
Optional permissions:
- Input data to the clipboard
- Access your data for sites in the dropboxapi.com domain
- Access your data for www.google.com
Data collection:
- The developer says this extension doesn't require data collection.
Optional data collection, according to the developer:
- Authentication information
More information
- Add-on Links
- Version
- 8.0.5
- Size
- 4.28 MB
- Last updated
- 6 days ago (Jul 28, 2026)
- Related Categories
- License
- MIT License
- Version History
- Add to collection