Frequently asked questions
Everything you need to know about using a privacy-first TOTP authenticator in Chrome — including 2FA autofill, data storage, and how Pro compares to the free tier.
What is Secure 2FA Authenticator?
A Chrome extension that generates time-based one-time passwords (TOTP) for two-factor
authentication. It runs entirely in your browser — no account required. Optional Google sign-in
links Pro to your account for multi-device restore.
Pro adds automatic OTP autofill on login pages so you stop copying codes from your phone.
Does it autofill 2FA codes on login pages?
Yes, with Pro. When you reach a verification step, the extension detects
OTP input fields and fills the matching 6-digit code when the username or email on the page
matches a saved account. The free tier generates and copies codes from the toolbar popup.
Is my TOTP data stored in the cloud?
No. TOTP secrets are stored only in
chrome.storage.local on your device.
Nothing is uploaded to our servers. License validation sends only your license key — never
your secrets. See our privacy policy for details.
Does it work with GitHub, Google, AWS, and banking sites?
Yes. Any site that uses standard TOTP (RFC 6238) works — GitHub, Google, AWS, Microsoft,
Stripe, Discord, and most banks. Add accounts via QR setup codes the same way you would
with Google Authenticator or any other TOTP app.
How is this different from Google Authenticator or Authy?
Phone apps require switching devices and manually typing codes. Secure 2FA Authenticator runs in Chrome
and can autofill OTP fields on login pages (Pro). Unlike cloud-synced
authenticators, your secrets never leave your device. There is no subscription — Pro is a
one-time $10 purchase for lifetime access.
Is Pro a subscription?
No. Pro is a one-time payment of $10 for a lifetime license. The free tier includes
unlimited accounts, code generation, and QR import via file upload.
How do I add accounts?
Click the extension icon → Migration Hub to upload a setup QR, import a Google Authenticator
export QR, or add an account manually. With Pro, you can also right-click any QR code on a
page or scan the page for QR codes to import instantly.
Can I import from Google Authenticator?
Yes — free. In Google Authenticator: menu → Transfer accounts → Export accounts → screenshot
the export QR. In the extension Migration Hub, drop the image in the Google Authenticator
section. If you have many accounts, Google may show multiple export QRs — upload each one.
Large exports may split across several QRs.
Can I organize accounts by client or org?
Yes. Edit any account (✎) to set a client folder (e.g. “Acme Corp”),
an optional label (e.g. “Prod” or “Sandbox”), and pin
frequently used logins to the top. Use the folder filter to focus on one client at a time.
Collapse folder groups to reduce clutter.
Does it work for Salesforce consultants with multiple orgs?
Yes. Register TOTP in each Salesforce org (One-Time Password Authenticator), import the setup
QR, and assign a client folder plus label. With Pro, when you log in and reach the verification
step, the extension autofills the code that matches the username or email shown on the page —
useful when you switch between many client logins daily.
Does the extension track me or use analytics?
The extension does not sell your data. The marketing website may show third-party ads
(Google AdSense) — see the privacy policy.
The extension may send anonymous usage events to
Google Analytics (e.g. Pro tab opened, upgrade nudge shown) — never your TOTP secrets,
emails, or browsing history. Pro license validation sends only your license key and a
random install ID. See our
privacy policy.
Ready to stop copying codes from your phone?
Add to Chrome — Free