Frequently asked questions

Everything you need to know about using a privacy-first TOTP authenticator in Chrome — including 2FA autofill, data storage, and how Pro compares to the free tier.

What is Secure 2FA Authenticator?
A Chrome extension that generates time-based one-time passwords (TOTP) for two-factor authentication. It runs entirely in your browser — no account required. Optional Google sign-in links Pro to your account for multi-device restore. Pro adds automatic OTP autofill on login pages so you stop copying codes from your phone.
Does it autofill 2FA codes on login pages?
Yes, with Pro. When you reach a verification step, the extension detects OTP input fields and fills the matching 6-digit code when the username or email on the page matches a saved account. The free tier generates and copies codes from the toolbar popup.
Is my TOTP data stored in the cloud?
No. TOTP secrets are stored only in chrome.storage.local on your device. Nothing is uploaded to our servers. License validation sends only your license key — never your secrets. See our privacy policy for details.
Does it work with GitHub, Google, AWS, and banking sites?
Yes. Any site that uses standard TOTP (RFC 6238) works — GitHub, Google, AWS, Microsoft, Stripe, Discord, and most banks. Add accounts via QR setup codes the same way you would with Google Authenticator or any other TOTP app.
How is this different from Google Authenticator or Authy?
Phone apps require switching devices and manually typing codes. Secure 2FA Authenticator runs in Chrome and can autofill OTP fields on login pages (Pro). Unlike cloud-synced authenticators, your secrets never leave your device. There is no subscription — Pro is a one-time $10 purchase for lifetime access.
Is Pro a subscription?
No. Pro is a one-time payment of $10 for a lifetime license. The free tier includes unlimited accounts, code generation, and QR import via file upload.
How do I add accounts?
Click the extension icon → Migration Hub to upload a setup QR, import a Google Authenticator export QR, or add an account manually. With Pro, you can also right-click any QR code on a page or scan the page for QR codes to import instantly.
Can I import from Google Authenticator?
Yes — free. In Google Authenticator: menu → Transfer accounts → Export accounts → screenshot the export QR. In the extension Migration Hub, drop the image in the Google Authenticator section. If you have many accounts, Google may show multiple export QRs — upload each one. Large exports may split across several QRs.
Can I organize accounts by client or org?
Yes. Edit any account (✎) to set a client folder (e.g. “Acme Corp”), an optional label (e.g. “Prod” or “Sandbox”), and pin frequently used logins to the top. Use the folder filter to focus on one client at a time. Collapse folder groups to reduce clutter.
Does it work for Salesforce consultants with multiple orgs?
Yes. Register TOTP in each Salesforce org (One-Time Password Authenticator), import the setup QR, and assign a client folder plus label. With Pro, when you log in and reach the verification step, the extension autofills the code that matches the username or email shown on the page — useful when you switch between many client logins daily.
Does the extension track me or use analytics?
The extension does not sell your data. The marketing website may show third-party ads (Google AdSense) — see the privacy policy. The extension may send anonymous usage events to Google Analytics (e.g. Pro tab opened, upgrade nudge shown) — never your TOTP secrets, emails, or browsing history. Pro license validation sends only your license key and a random install ID. See our privacy policy.

Ready to stop copying codes from your phone?

Add to Chrome — Free