Keyrook Authenticator

Your two-factor codes, one click away.

A browser extension for the six-digit codes that GitHub, Google, your bank and everything else ask for. They are encrypted on your own computer, kept in step across your browsers if you want, and the extension cannot read the websites you visit.

Free, with no ads. Open source under GPL-3.0.

Sample accounts. The codes are real, made in this page the way the extension makes them.

Built to be trusted, not just used

An authenticator holds the second half of every login you protect. So it is built to know as little as possible, and to show its work.

Encrypted on your computer

Your accounts are sealed with AES-256-GCM under a key only you hold. Nothing readable is ever written to disk.

No access to websites

It asks for no permission to read or change the sites you visit. Scanning a QR code or filling in a code works only on the tab you open it on, at the moment you open it.

Open source

The extension and its encryption are published under GPL-3.0. Read it, build it yourself, and compare your build with the one the store ships.

Nothing phones home

No analytics, no ads, no tracking. Service logos are built in, so no website ever learns which accounts you keep.

Everything you need to sign in

Works with any site that offers an authenticator app — the standard six-digit codes.

  • Scan the QR code straight from the page you are setting up
  • Or point your camera at a code shown on your phone
  • Fill a code into the page with one click
  • Sync your browsers — optional, free, end-to-end encrypted
  • Move everything over from Google Authenticator
  • Move to any other app, whenever you like, in a few scans
  • Groups, search, auto-lock and encrypted backups
  • Get one code from a key, without saving anything

No extension at hand?

Paste a setup key into the code page and get the current code. It is worked out in that page, never sent anywhere and never kept — and the page's own security policy, enforced by your browser, is what makes that so.

Questions, problems, security reports

Write to brickitall.hi@gmail.com, or open an issue on GitHub. What the extension stores, and where, is in the privacy policy.