Repository navigation
CloudAuth v1.0.0
Browser extension authenticator with end-to-end encrypted sync. Codes are
generated locally and the vault is encrypted before it leaves the browser, so
the server only ever stores ciphertext.
Install
Chrome — download cloudauth-chrome-v1.0.0.zip, unzip it, then go to
chrome://extensions, turn on Developer mode, and click Load unpacked on
the unzipped folder.
Firefox — download cloudauth-firefox-v1.0.0.zip and unzip it. Go to
about:debugging#/runtime/this-firefox and click Load Temporary Add-on,
then pick manifest.json from the folder.
You also need the backend running. See the README for setup, or DEPLOY.md to
host it. By default the extension points at http://localhost:4000 — change
config.js and the manifest's host_permissions to use a deployed server.
What's in it
- TOTP (RFC 6238), HOTP (RFC 4226) and Steam Guard codes
- Add accounts by scanning a QR off the page, from an image, by pasting an
otpauth://link, or by bulk import from Google Authenticator - AES-256-GCM vault, PBKDF2-SHA256 at 600k iterations, synced to your own server
- Works offline from a cached copy
- Encrypted backup export and restore
- Autofill codes into the page, search, tags, pinning, drag to reorder
- Popup or side panel, light and dark themes
- Auto-lock, and "sign out all devices" for instant token revocation
Notes
The two builds share the same code and differ only in the manifest: Chrome uses
side_panel, Firefox uses sidebar_action.
Neither build is signed. Chrome will flag it as a developer-mode extension, and
Firefox will drop it on restart — that is expected for an unpacked install and
needs a store listing to change.