Skip to content

CloudAuth v1.0.0

Choose a tag to compare

@adhyys07 adhyys07 released this 09 Aug 08:58
· 4 commits to main since this release

Browser extension authenticator with end-to-end encrypted sync. Codes are
generated locally and the vault is encrypted before it leaves the browser, so
the server only ever stores ciphertext.

Install

Chrome — download cloudauth-chrome-v1.0.0.zip, unzip it, then go to
chrome://extensions, turn on Developer mode, and click Load unpacked on
the unzipped folder.

Firefox — download cloudauth-firefox-v1.0.0.zip and unzip it. Go to
about:debugging#/runtime/this-firefox and click Load Temporary Add-on,
then pick manifest.json from the folder.

You also need the backend running. See the README for setup, or DEPLOY.md to
host it. By default the extension points at http://localhost:4000 — change
config.js and the manifest's host_permissions to use a deployed server.

What's in it

  • TOTP (RFC 6238), HOTP (RFC 4226) and Steam Guard codes
  • Add accounts by scanning a QR off the page, from an image, by pasting an
    otpauth:// link, or by bulk import from Google Authenticator
  • AES-256-GCM vault, PBKDF2-SHA256 at 600k iterations, synced to your own server
  • Works offline from a cached copy
  • Encrypted backup export and restore
  • Autofill codes into the page, search, tags, pinning, drag to reorder
  • Popup or side panel, light and dark themes
  • Auto-lock, and "sign out all devices" for instant token revocation

Notes

The two builds share the same code and differ only in the manifest: Chrome uses
side_panel, Firefox uses sidebar_action.

Neither build is signed. Chrome will flag it as a developer-mode extension, and
Firefox will drop it on restart — that is expected for an unpacked install and
needs a store listing to change.